Fending Off VoIP Attacks

Updated: April 30, 2009

Your business is probably switching or has switched to VoIP to take advantage of the technology's many cost, efficiency and productivity benefits. But you also got something else in the bargain — the need to protect your organization's telephone system from outside attacks.

Security is the part of VoIP that most businesses don't like to think about. Many companies still don't fully understand the need for protecting a phone system. But since VoIP shares many technologies with computer-focused data networks, the need to safeguard Internet telephony deployments is very real.

VoIP vendors and service providers don't like to publicize the fact, but IP telephony is vulnerable to virtually all of the attacks that plague regular data networks, including viruses, worms, Trojan horses, DoS (denial of service) assaults and hijacking. VoIP is also vulnerable to things like toll fraud, phishing , voice spam and eavesdropping . Dealing with VoIP threats requires a three-tiered approach that targets threats on the infrastructure, software and user levels. Here are the details:

Network Considerations
VoIP vendors and service providers tout the cost savings that can be made by placing VoIP onto existing data networks. Yet close proximity to other data services can expose a VoIP system to multiple threats. This is particularly true if the VoIP system is exposed to the public Internet.

To safeguard your VoIP system, make sure that ironclad authentication and encryption tools are in place. A VPN (virtual private network) will enable trusted users to securely connect to your VoIP system from untrusted networks. Internally, a VPN will effectively separate the VoIP network from the underlying data network, sparing your phone system from any attacks that may afflict the rest of the network.

If a hosted IP PBX service is used, you should ask the provider what technologies are utilized on its end to keep VoIP threats from attacking the devices used within your organization. Compare the security policies of several VoIP service providers to find the vendor that offers the best security protection.

Security Considerations
Security technologies designed to safeguard traditional networks often don't incorporate "VoIP awareness." VoIP includes a number of specialized protocols that standard network security gear just isn't equipped to handle. Dedicated VoIP networks and converged networks should be equipped with IPSs (intrusion prevention systems) and firewalls that can look deeply into traffic to detect threats that are aimed specifically at VoIP devices. Also, make sure that intelligent IPS technology is placed between VoIP gateways as well as close to the call manager, a prime attack point that contains all critical user data.

User Considerations
In many ways, users are any VoIP network's weakest spot. Users do all sorts of things that open the door to potential attackers, such as using unauthorized hosted IP telephony technologies like Google Talk and Skype . While these services are relatively safe in a stand-alone consumer environment, they can introduce significant risks into an enterprise VoIP system as they search for ways to reach the public Internet though firewalls and other security barriers.

Installing VoIP-aware IPS technology and firewalls at key access locations will help pave the way for the creation of a uniform user-security policy. Organizations may decide to either block user-installed voice technologies entirely or to confine their use in such a way that they can be accommodated in a safe and authorized manner.

Featured Research
  • [Infographic] 8 Common Pain Points UC Eliminates

    Every company has moments of frustration, it is when these moments become extended periods of inefficiency, or pain points, where we start to see loss in productivity and employee morale. What truly sets a successful business apart from those of its competitors, is how they take these pain points and use them as opportunities to improve upon procedures and systems to eliminate pain points and move beyond what was the status quo. more

  • Go VoIP and Go Green

    You may be looking to switch to VoIP because of the cost benefits that it will bring your company, but did you know that it is also FAR BETTER than traditional phone systems for the environment as well? With environmental impact being at the forefront of both consumer and business minds, it is essential that business decisions are made now based on economic AND ecological impact. more

  • eGuide: Comparing UC Vendors

    Changing your company’s business communications solution is an investment in time and money that will touch everyone in your organization. A successful unified communications (UC) deployment should streamline everyone’s work flow, simplify IT operations and deliver a lowered total cost of operations. Your company deserves nothing less. more

  • Getting More from Your VoIP System

    Too many businesses fall into the trap of setting up their VoIP as a "plug and play" and getting to work. However, we have found that this thinking only leads to businesses failing to get the most out of their VoIP experience. We have put together an in-depth guide that will walk you through 15 easy steps to get more out of your system. more

  • Making Your Phone System Work

    Deciding what to do about a legacy phone system can be difficult. The advantages of modern systems like VoIP are well-documented, but the switch can still be resource intensive. Updating your old system is usually the better decision, but circumstances often make this impossible. Fortunately, there are other ways to improve and tweak an existing system to enjoy better performance. more