* Potential for DDoS attacks tops list of concerns over VoIP security
endif; ?>The Webtorials 2004 VoIP State of the Market Report was released last week, and as we previously reported, security took over as the top concern. But while simply stating that “security” is a problem, it’s very useful to look a bit more deeply at exactly what the security concerns are.
In particular, the primary concern is about the security of infrastructure and the resiliency of PBXs. In fact, almost twice as many respondents saw “infrastructure security” as a major concern than saw “conversation” as a major concern. Regarding infrastructure security, two-thirds of respondents worried most that the server might be the target of a distributed denial-of-service (DDoS) attack.
This concern was mirrored in a recent e-mail message we received from Greg Brewster at the School of Computer Science, Telecommunications and Information Systems at DePaul University in Chicago. He wrote:
“I’m not terrifically concerned about anyone intercepting my VoIP conversations, and encrypting VoIP is probably a piece of cake if I want to do it. My main security concern with VoIP is denial of service. Anyone with access to the same IP network as my VoIP phone may decide to try to knock it out of service with a barrage of worms, viruses, spurious traffic, or whatever. I would guess that it’s probably trivial to completely disable a VoIP phone by sending it malformed signaling messages or simply overwhelming it with junk. I haven’t seen any of the vendors seriously address this problem yet. This is not something we had to worry about with the PBX.”
This is a serious problem. DDoS attacks are and will continue to be a fact of life. The best hope we see is that since DDoS attacks are equally a problem for data networks, the solutions that are being offered by vendors in the security area will apply to VoIP as well.




