Softphones Require Strong Endpoint Protection

Opinion
Oct 27, 20093 mins

Strong endpoint protection for mobile workers protects both VOIP and data communications

What happens when the phone becomes the computer and vice versa? We’re finding that 70% of organizations are using softphones for Voice over IP (VOIP) for at least some (on average, 22%) of their employees. And these are not just toys. Among organizations using softphones, a little more than a third are using softphones in lieu of a desktop phone. Just over half are using them primarily as an adjunct to a desktop phone. And the number one role (44%) for softphone use is mobile workers.

This all points to the need for strong endpoint security and authentication. The good news is strong endpoint protection for mobile workers protects both VOIP and data communications.

Keep in mind that by “softphone”, we’re not talking about Skype or Google Voice. The softphone is a piece of software that provides desktop phone functionality running on Windows or Mac. Softphones require a common signaling protocol and codec to connect to the corporate VOIP PBX. Today, most softphones use session initiation protocol (SIP) as the signaling protocol. And, when the host device is outside the corporate firewall the connection to the PBX is over the Internet. This is why endpoint protection is so important.

As a baseline the endpoint device needs to have basic security functions operating, include anti-virus and anti-malware. Essentially, any device connecting to the corporate network – voice or data – needs to meet the basic corporate security protection profile. Given that most softphones are on laptops for mobile workers, that’s likely to be the case.

The one area that gets tricky is the personal firewall. Most personal firewalls are configurable to allow or deny VOIP/SIP connections. Obviously, softphones require VOIP/SIP connections, but you’ll also want to know that the personal firewall protects against VOIP/SIP vulnerability exploits. The best protection from external exploit via the network is to encrypt the communications.

The other issue that is unique to the mobile worker is the requirement for strong authentication. How do you know it’s really Joe connecting to the corporate PBX? When Joe is using the softphone in the office there are other mechanisms – building security, LAN connection, social factors – that authenticate Joe. When Joe is on the road we need multi-factor authentication (something you know, something you have and/or something you are) to validate that someone else or something else (malware) is not impersonating Joe.

The good news is a corporate VPN meets both the requirement for encryption and authentication. This guarantees the confidentiality of the softphone communications through encryption and the integrity of the connection via multi-factor authentication.