Home > Unified Communications Tips > Unified Communications Tech Tip > How to think about VoIP security
Unified Communications Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

UNIFIED COMMUNICATIONS TECH TIP

How to think about VoIP security


Gary Audin
03.12.2007
Rating: -4.75- (out of 5)


VoIP news and advice channel
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Voice over IP (VoIP) brings converged networks security challenges that never existed for the data network or traditional telephony. In this VoIP security series, industry expert Gary Audin reveals these IP telephony threats, the added costs of securing VoIP, and how your organization can keep VoIP secure.

Security requires constant vigilance. The security job is never finished. Security is all about the protection of resources -- data, devices, networks, applications and people. While access to these resources is the goal of the user, securing access to these resources means the administrator of the resources wants to limit, even prevent, that access. These two goals are at odds: The most secure environment is one that prevents any access, which is contrary to the business needs of an enterprise.

Enterprises already have many security problems with their data network infrastructure, servers, desktops and software. Adding voice over IP (VoIP) and IP telephony (IPT) to the mix only compounds the security problems. VoIP and IPT will have all of the security problems that the data organization has, plus new threats and vulnerabilities.

What's new about VoIP security?

There are several security issues with VoIP networks:

VoIP security vs. voice quality

It may not be apparent, but security tools and solutions will conflict with voice quality. The more barriers there are in the network and endpoints for security purposes, the more interference there will be with voice quality.

One of the first issues is the firewall. The firewall can block calls because it cannot process the signaling or dynamically allocate the UDP ports for the calls to pass through it. Firewalls may not read the QoS markers in the voice packet, thereby degrading the packet delivery service. Other issues include:

The security vs. voice quality conflict will be hard to resolve. The voice manager, obviously, does not want poor-quality calls. If the calls


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Unified Communications Tech Tip
The significance of Avaya's Aura
UC buyers should look for SaaS-based UC offerings in 2009
Using the iPhone in the enterprise?
Social networking and discussion forums for the enterprise
Streaming Cisco's IP Communicator to an HP thin client
Demystifying unified communications deployment strategies
Presence management and security
Presence: SIMPLE versus XMPP
Four factors driving videoconferencing
Consider IBM Lotus SameTime for UC, not just Microsoft OCS

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


are poor, then why have calls travel over the data network in the first place? The security manager does not want to open the network and endpoints to security exposures that will not only compromise the voice services but weaken the data functions as well. This will require a great deal of negotiation and compromise. Security is important, but not at the cost of an unacceptable voice service.

Finding vulnerabilities

There are two sites that demonstrate the software security threats to the data functions. These lists now include VoIP/IPT vulnerabilities. Both lists are funded by the federal Homeland Security Administration. The first is hosted at Mitre. This site has a dictionary of standardized names and descriptions for Common Vulnerabilities and Exposures (CVE). The second site hosts the National Vulnerability Database at the federal National Institute of Standards and Technology (NIST). The NIST site has about 21 additional security vulnerabilities listed every day. I searched on both sites in early February 2007 and found the number of VoIP/IPT vulnerabilities listed in the following table.

[TABLE]

The two sites overlap but do not have exactly the same lists. The published vulnerabilities have patches available from the vendors. The sites are not as up-to-date as individual vendors' lists, so check with your vendor as well as these two sites. The NIST site also evaluates the severity of the security problem. A severity rating of 1 is the lowest and 10 is the highest. Most of the vulnerabilities are rated between 3 and 8. I strongly recommend accessing these sites in order to learn of the types of vulnerabilities that are occurring in VoIP/IPT.

Cost to the enterprise

Tangible and measurable monetary costs -- which can accrue to an enterprise when security problems occur -- will include the following:

Case studies published in the article The Cost of Network Downtime show that one hour of downtime can cost an enterprise up to $96,632. What if the network and voice service need to be shut down for one hour to resolve a security problem? Costs that are hard to calculate include loss of the future business caused by bad publicity about the security breach, as well as the loss of market share to competitors.

VoIP security: Where do you start?

Assume an attack will occur and probably be successful. You will always have a limited budget, so you will have to prioritize the allocation of the budget. Start looking at the core components: storage, applications, servers and network. Locate the most valuable and sensitive resources. Evaluate the security risks to these resources. You need to protect these resources first. Work outward to less valuable, less sensitive resources. The suggested order of protection is the call server first, then the trunk gateway, next the media gateway, then the softphones, and finally the IP phones.

The discussion of security issues for VoIP/IPT will continue in several more tips. These tips will cover:

About the author:
Gary Audin has more than 40 years of computer, communications and security experience. He has planned, designed, specified, implemented and operated data, LAN and telephone networks. These have included local area, national and international networks, as well as VoIP and IP convergent networks, in the U.S., Canada, Europe, Australia and Asia.

Rate this Tip
To rate tips, you must be a member of SearchUnifiedCommunications.com.
Register now to start rating these tips. Log in if you are already a member.




DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Communications Solutions for Business: Collaboration, Cell Phone Access, and IP Telephony
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts