Major VoIP exploit predicted

But not in the next year.

The threats against VoIP are numerous and seem to be growing, but in 2008 the technology probably won't suffer crippling attacks, analysts have said.

The potential danger is very real. VoIP is susceptible to the many exploits that networks generally are heir to - denial of service, buffer overflows and more. VoIP PBXs are servers on corporate networks and are only as secure as the networks themselves.

In addition, there are many voice-specific attacks and threats. These have been chronicled by researchers and vendors intending to alert users and suggest ways to guard against them.

For instance, two protocols widely used in VoIP - H.323 and Inter Asterisk eXchange - have been shown to be vulnerable to sniffing during authentication, which can reveal passwords that later can be used to compromise the voice network.

Implementations of Session Initiation Protocol (SIP), an alternative VoIP protocol, can leave VoIP networks open to unauthorised transport of data.

In addition, tools that can help find vulnerable deployments have been published online by a VoIPSA, an industry group dedicated to securing VoIP. The VoIPSA tools are intended to help businesses test and secure their networks, but these and other online tools can be used to probe for weaknesses as well.

Still, there have been few exploits so far and none that have been widespread or crippling to businesses. "We are not hearing about attacks. We don't think they are happening," says Lawrence Orans, an analyst with Gartner.

Part of the reason may be that the largest VoIP vendors use proprietary protocols, such as Cisco's Skinny, Nortel's Unistim and Avaya's variant of H.323, Orans says. That makes them difficult to obtain and study for potential security cracks. "These systems are not readily available to the bad guys," he says.

SIP, which is gaining popularity, is a mixed bag, Orans says, because it is readily available to those who might want to exploit it. "I would say that SIP is a good-news, bad-news story. It's easy to get your hands on, and that includes the bad guys. The good news is there are more options to protect SIP," he says. These options include firewalls and intrusion-prevention systems that support SIP.

Another reason for the lack of broad exploits is that there isn't enough ROI for attackers' development time. Attackers' motivation may improve, however, as VoIP increases in popularity, something it is doing relentlessly.

Hybrid PBX systems - which handle both VoIP and TDM voice - account for 64 percent of all PBX lines sold, according to a December 2007 Infonetics report. Pure IP systems account for another 18 percent.


Comment

What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.

Characters remaining: 500

Add your commentComments

David Caughtry Computerlinks | Published: 12:01 GMT, 21 December 2007

A VoIP network is susceptible to the usual attacks that plague all data networks. It goes without saying that a resilient security offering must support the undeniable benefits that VoIP brings. IP telephony vendors such as Swyx and security vendors are already facing this challenge and providing specific support for VoIP. For example, security vendor Check Point already provides support for VoIP protocols where the Swyx solution sits behind the router and the firewall on a separate server. The channel must also face this challenge in order to ensure that the end customer feels their communication infrastructure is secure and well protected. One vendor alone cannot provide all this, but the channel can. In fact, the collaboration between data, security and voice presents a compelling business proposition for the channel. Voice and data resellers must adapt to the changes, taking the opportunity to extend their knowledge base and realise new revenue possibilities

Related Security news

Anglia Water signs managed security service contract with SU53

Contract includes upgrade of SAP Governance, Risk Management and Compliance (GRC) solutions

PandaLabs: Hackers create 57,000 malicious pages per week

64 percent of the fake websites are designed to look like legitimate bank websites

Norton releases 2011 version of security software

Norton also announces new application - Norton Power Eraser

Security vendor demonstrates insider attack on VMware ESX

VMware can prevent attacks demonstrated by BeyondTrust



Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

IT Manager's guide to buying an anti-spam solution

With these ten critical questions as your guide, you can cut through the marketing hype and zero in on the key features and benefits that should guide your decision.

Download Whitepaper

Unleashing cloud performance

While cloud services aim to eliminate cost and complexity from the world of enterprise IT, the unintended consequences of these services may do exactly the opposite if not carefully planned for.

Download Whitepaper

Online PC backup

This paper looks at the need for laptop and desktop data protection and, based upon recent IDC research, the key requirements firms should consider in evaluating enterprise-level online PC backup solutions.

Download Whitepaper

Protecting your business, customers, and the bottom line

Download this whitepaper to find out more about how you can protect your business from malware.

Download Whitepaper

Techworld UK - Technology - Business

Oracle Video

Enabling agile and intelligent businesses

 Changing markets, competitive pressures and evolving customer needs are placing increasing pressure on IT to deliver greater flexibility and speed. Explore truly flexible SOA foundations with this Oracle video.

Watch
AMD LGF

AMD Opteron™ Resource Centre

Set the foundations for higher speed processing, low energy consumption whilst delivering flexibility and value to your organisation.

Learn More

Win an iPad

How do you view and share technology related content and information? Tell us in our 2010 Media Usage Survey and you could win an iPad.

Complete the survey here

Site Map

IDG Network

* *