Fending Off VoIP Attacks

Updated: April 30, 2009

Your business is probably switching or has switched to VoIP to take advantage of the technology's many cost, efficiency and productivity benefits. But you also got something else in the bargain — the need to protect your organization's telephone system from outside attacks.

Security is the part of VoIP that most businesses don't like to think about. Many companies still don't fully understand the need for protecting a phone system. But since VoIP shares many technologies with computer-focused data networks, the need to safeguard Internet telephony deployments is very real.

VoIP vendors and service providers don't like to publicize the fact, but IP telephony is vulnerable to virtually all of the attacks that plague regular data networks, including viruses, worms, Trojan horses, DoS (denial of service) assaults and hijacking. VoIP is also vulnerable to things like toll fraud, phishing , voice spam and eavesdropping . Dealing with VoIP threats requires a three-tiered approach that targets threats on the infrastructure, software and user levels. Here are the details:

Network Considerations
VoIP vendors and service providers tout the cost savings that can be made by placing VoIP onto existing data networks. Yet close proximity to other data services can expose a VoIP system to multiple threats. This is particularly true if the VoIP system is exposed to the public Internet.

To safeguard your VoIP system, make sure that ironclad authentication and encryption tools are in place. A VPN (virtual private network) will enable trusted users to securely connect to your VoIP system from untrusted networks. Internally, a VPN will effectively separate the VoIP network from the underlying data network, sparing your phone system from any attacks that may afflict the rest of the network.

If a hosted IP PBX service is used, you should ask the provider what technologies are utilized on its end to keep VoIP threats from attacking the devices used within your organization. Compare the security policies of several VoIP service providers to find the vendor that offers the best security protection.

Security Considerations
Security technologies designed to safeguard traditional networks often don't incorporate "VoIP awareness." VoIP includes a number of specialized protocols that standard network security gear just isn't equipped to handle. Dedicated VoIP networks and converged networks should be equipped with IPSs (intrusion prevention systems) and firewalls that can look deeply into traffic to detect threats that are aimed specifically at VoIP devices. Also, make sure that intelligent IPS technology is placed between VoIP gateways as well as close to the call manager, a prime attack point that contains all critical user data.

User Considerations
In many ways, users are any VoIP network's weakest spot. Users do all sorts of things that open the door to potential attackers, such as using unauthorized hosted IP telephony technologies like Google Talk and Skype . While these services are relatively safe in a stand-alone consumer environment, they can introduce significant risks into an enterprise VoIP system as they search for ways to reach the public Internet though firewalls and other security barriers.

Installing VoIP-aware IPS technology and firewalls at key access locations will help pave the way for the creation of a uniform user-security policy. Organizations may decide to either block user-installed voice technologies entirely or to confine their use in such a way that they can be accommodated in a safe and authorized manner.

Featured Research
  • Why Your Educational Institution Needs to Implement VoIP

    VoIP makes a lot of sense for educational institutions—and it’s not just because of the substantial cost savings. Other benefits include increased efficiency and integration options. Emergency responsiveness can even be improved. more

  • Is Your Phone System Meeting the Needs of Your Workforce?

    When was the last time you evaluated the performance of your current business phone system? For most people, the answer is too long ago. Phone systems are one of the most overlooked tools in business, even though they’re also one of the most important in terms of employee productivity. more

  • Why are Companies Still Using PBX?

    For years, all kinds of businesses depended on Private Branch Exchange (PBX) phone systems to help facilitate direct, line-to-line communication. Over the course of the past decade, however, Voice over Internet Protocol (VoIP) technology quickly became the go-to resource for brands. more

  • Top 15 Reasons You Should Upgrade to VoIP

    While more businesses make the switch to VoIP every single day, there are also many that choose to stay with the system they are used to.The rationale is almost always the same. You don’t want to shake things up when what you are already using is working. more

  • [Infographic] 16 Mistakes to Avoid When Buying a Phone System

    Choosing a phone system for your business isn’t as easy as it looks. Most people learn this the hard way. You choose a new system, and everything seems fine. Until it isn’t. In hindsight the problems always seem obvious, yet countless businesses fall into the same traps every year. more