Gear, education programs seek to speed adoption, keep VoIP networks out of trouble.
Vendors are rolling out gear dedicated to VoIP security and at the same time mounting an IP network security-awareness campaign as an additional way to keep attacks from crashing VoIP networks.
SecureLogix, BorderWare and NFR Security last week announced appliances that filter VoIP traffic to find and drop malicious traffic that is indicative of attempts to hijack phone calls, crash IP PBXs and flood voice mail systems with junk messages.
While there is no evidence to show an increase in assaults against VoIP, advocates of tightened security say that it is just a matter of time before attackers craft exploits specifically to cripple voice.
“We want to provide enough information to deter threats and help customers plan to deploy VoIP securely,” says David Endler, chairman of the VoIP Security Alliance, a group formed to spread the word that general network security is key to VoIP security. He’s also the director of Digital Vaccine , one of the TippingPoint’s security products. “It only takes one high-profile attack to slow the adoption of VoIP,” Endler says.
The Tribute Company newspaper and television conglomerate plans to install a SecureLogix Enterprise Telephony Management System , with its new Version 5 software that supports VoIP protection. “We want to get it installed and learn about [VoIP security] from the outset,” says Bill Rasmussen, manager of telephone services for the company.
The Tribune Company, which has used VoIP for some of its employees for two and a half years, wants to avoid attacks that affect availability and quality. The Blaster worm hit the company’s network, and while it didn’t directly infect VoIP machines, its disruption of the network turned message lights on and off on the IP phones.
The SecureLogix software he is buying acts as a voice application firewall and seeks denial-of-service (DoS) attacks launched via Session Initiation Protocol (SIP ) signaling and malformed packets. It looks for traffic patterns that indicate unauthorized use and voice mail spamming.
BorderWare is introducing its own appliance designed to block VoIP attacks. The company is releasing an appliance that screens SIP, the call setup protocol that VoIP gear uses most. Called SIPassure , the company describes it as a SIP firewall that looks for a range of attacks such as attempts to discover legitimate IP phone addresses via directory harvesting; clogging voice mail systems with voice spam sent as audio files; voice phishing, in which voice mails urge users to return calls and leave personal financial information; and DoS attacks against voice servers.
SIPassure also can detect attempts to redirect calls to another phone, hijack ongoing calls and turn on other phones so they act as a receiver of the conversations.
The equipment does this by examining call setup requests at the application layer. If it finds traffic that violates security policies set on the box, it can reject the connection. SIPassure will be available this summer.
NFR has announced an appliance called Sentivist that also sorts through SIP traffic and looks for malformed packets or traffic patterns that fall outside the norm and cuts off sessions that seem suspicious. Sentivist, which also screens instant-messaging traffic, starts at $20,000.
VoIP security starts with the network
The National Institute of Standards and Technology recently issued a report called “Security Considerations for Voice Over IP Systems” that details network security considerations users must act on to protect their voice networks.
Users must consider voice an application running on an IP network and protect it as they would protect any other application, says Brian Cincera, vice president of security solutions for Greenwich Technology Partners.
This is the strategy of Bank of America, which is rolling out VoIP and a security and authentication infrastructure at the same time. “Our security initiative is a separate project from our [VoIP] rollout, but it will have to work on multiple fronts with our VoIP infrastructure,” says Craig Hinkley, the bank’s senior vice president of network architecture and strategic design.
He recommends encrypting voice traffic. “It’s unlikely a man in the middle could intercept and inject new words in a conversation, but with a sniffer could tap a call and post a word file of it online,” he says. Encrypting the call blocks this possibility, he says.
Cincera recommends that VoIP handsets authenticate to the network to prevent IP address spoofing of legitimate phones to gain access to legitimate VoIP gear.
Management traffic to VoIP servers should run separately from VoIP signaling and call traffic to prevent network users from hacking the servers themselves, Cincera says.
Properly implemented VoIP is safe, Cincera says. “Is there an inherent security flaw in VoIP? The answer is no,” he says.
Network World Senior Editor Phil Hochmuth contributed to this story.




