| | | RssFeeds
 
Get Free Newsletter Search   Search Search
         

Follow Us:

 
 
NC Print 
February 2010
Editorial
Four factors to consider before firing up that DLP solution
By Invitation

»The Analyst Angle

»ProductivIT

»Technology & Risks

How to plug the loopholes in two-factor authentication
Google Wave: An experimental ride
Managing Document Mammoths

» Jigar Shah

» Vidhii Partners

How The Koobface Worm Gang Makes Money
Zoeb Adenwala
On the Record

»Andrew M Dutton

»Jim Wagstaff  

Printer vendors don ‘consultant’ hat to push MPS
Case Study

»FT Rides Web 2.0 Wave Securely

»Eko’s Mobile Platform Accelerates Financial Inclusion

»Open Source Infrastructure Management tool helps JSL reduce downtime

5 points to make when your CEO cries cloud
How to be a guinea pig and not get slaughtered
Cisco launches enterprise social network solution
Top 10 security challenges for 2010
In the News
 EDGE 2009

Read More About the Best IT Implementations in the Country

 
       Read more >> 

Archive
 

Technology and Risks


 Is it Safe to Voice, VoIP That is?

 By Avinash Kadam / MIEL E-SECURITY

Avinash KadamIn 1875, Alexander Graham Bell set up the first telephone connection. He stretched a wire to the adjoining room and uttered the famous sentence, “Mr Watson, come here. I want to see you." Telecommunications has come a long way, since then.


Telephone circuits have expanded to circumnavigate the earth many times over. Everyone is just a call away. With the advent of the Internet, even the exorbitant charges thus far levied by telephone companies cease to be a problem. Calls can now be made at a nominal cost, if not for free.


Just like telephone companies, the Internet can digitize and compress voice and send it as data anywhere in the world. This theory was further transformed into many techniques like ATAs (analog telephone adapters), or IP phones or simple computer-to-computer communication. The basic idea is the same: convert normal analog voice to digital signal, put it in the data portion of an IP packet—Voice over Internet Protocol (VoIP)—and send it across through the Internet at a fraction of the cost of a telephone call.



Since the cost aspect seemed too good to be true, we started worrying about security. From our years of experience, we knew that the Internet is an insecure medium to send data over. So, is it safe for voice?
What can go wrong with VoIP? 


The most serious fear is a Denial of Service (DoS) attack. What if the network is flooded with spurious traffic and all VoIP phones go dead? Fortunately, we have not yet faced such an attack. One reason could be the relative low density of VoIP phones. In addition, despite the lure of merging data and voice networks, we are not yet ready to bid adieu to PSTN (public switched telephone network)—tried, tested and proven for more than 100 years.


In recent times, several new acronyms have cropped up to describe security threats for VoIP. We now dread SPIT (spam over internet telephony). Similar to the ubiquitous phishing e-mails (spam) that threaten to suspend our credit cards if we do not give our password, PIN and social security number, there are vishing attacks through voice calls. These calls can intimidate unsuspecting users to call a given number and confirm their account credentials.


Also, there is the ever-present threat of viruses, worms and Trojans that can infect our IP phones and other telecommunication devices too. VoIP calls can also be spoofed, eavesdropped, hijacked or intercepted by MITM (man-in-the-middle) attackers. Then, there is the worry about toll frauds.
All these are very tangible risks. We have faced these on our data networks and on voice networks. There is no doubt that we might face all these on our VoIP communications. So, it seems that the attack surface has just increased manifold for voice communication using IP.


Is there a way to negate risks?
VoIP is bound to overtake traditional telephone communication. The cost savings are enormous. We will just have to learn to cope with all the threats. Enough security technologies are being developed for data traffic on the Internet. In order to counter the treat, VoIP will see heavy usage of cryptography. It is likely that new VoIP-aware firewalls, IDS, and IPS will be deployed in the near future. Already, Turing tests are being employed to check if the VoIP caller is human or machine.


The ideal solution would be to educate ourselves, so that we do not to fall prey to any vishing attack. We should also learn to scan our IP phones for viruses before we make a call. At the end of the day, the price we pay for securing ourselves will still be much smaller compared to the savings we will make.

Print this Page   E-mail this Page
RATE THIS ARTICLE
 Worse   Better 
Comment:*
First Name:*
Last Name:*
Company:
City:*
E-mail:*
Verification Code:*

Type the characters you see in the picture above.
 
  Reset

Comments >>

1/27/2010 6:31:52 AM
 
Good read and thought provoking
 
 - RAVIKUMAR RAMACHANDRAN,MIEL e-Security Pvt .Ltd,Mumbai
1

Disclaimer >>

 

 

 Global CIO

Global CIO: The Top 10 CIO Issues For 2010

For CIOs, 2010 will require new emphases on customers, revenue, external information, and a passion for rapid change           
           Read More >> 

 

 Editor's Blog

What’s your storage strategy?

        

Read more >>  

 

 CIO Profile

Satish Pendse Muralikrishna K

VP and Head, Computers & Communication Division, Infosys Technologies

 Read more >>  

 

 International News

Facebook Hit By Clickjacking Attack

Social network targeted by emerging brand of attack that's hard to kill

 Read more >>

 

        

 Work Smart

Archive your mail      


Read more >>  

 

ADVERTISEMENTS >>
 
Powered By: ssCMS 2.2.0.0