IP Voice Trunking – Corporate Risk?

Opinion
Feb 26, 20083 mins

We’ve all heard about the claims of voice trunking over the Internet, be it SIP, H.323, IAX, or a proprietary trunking protocol. It provides for very low origination/termination costs to home users, SMBs, and large corporations. Personally, I utilize quite a few SIP trunks to different providers connected to my Asterisk servers. There’s no cost-effective substitute that could even come close to providing PSTN termination at such low costs. Yes, we’re all aware of the issues with IP-based voice transport, such as QoS concerns (latency, bandwidth availability, packet loss), as well as cross-carrier outages between providers’ IP-to-PRI channel banks, etc. But, I don’t think that the security concerns of IP trunking are as well communicated as they should be. I’m not emphasizing the many home-based customers of services such as Vonage and Packet8. In the fine print of their agreements, there is undoubtedly a liability release stating that IP telephony is not 100% foolproof and secure. However, it’s the enterprise implementations of IP-trunking that really concern me. When we make a call from our analog home POTS line to a large company, we immediately give up control over where that call is transported, and the forms of security that may or may not be there to protect against eavesdropping and collecting sensitive information. The principle of the weakest link unfortunately applies to voice transport. You can take preventative means to secure the intra-CO infrastructure of the PSTN, but the last loop within an organization can be the most fatal. Imagine a company that utilizes SIP trunking between offices to handle call transport between them. Calls from inbound PRIs may be forwarded across these IP trunks in order to route calls properly, depending on the nature of the call. This is natural, but can we be assured that every company has implemented strong VPNs or other encryption to protect the RTP that may or may not contain spoken credit card numbers, health information, etc? Any company can easily, cheaply, and quickly utilize IP-trunking to streamline their telecom bottom-line. What regulation or oversight makes sure that these transports are even moderately secure? Just as regular non-voice data transport is vulnerable to spoofing or man-in-the-middle attacks, how can we be assured that this type of lapse in security isn’t occurring on such a telecom network? Ultimately, it comes down to individual responsibility to protect sensitive information. Obviously, this requires research, architecture, and proper implementation to do it right “the first time.” With the promise of convergence and VoIP becoming easy to deploy at such lucrative costs, at what cost will we forget about security? I understand, anybody can walk up to the NID attached to my house and plant a tap easily. But, it’s much easier to sniff unencrypted RTP from anywhere in the world.