Home > Ask the Unified Communications Experts > UC Security Questions & Answers > Will implementing VoIP increase our company's vulnerability to hackers and denial-of-service attacks?
Ask The Unified Communications Expert: Questions & Answers
EMAIL THIS

Will implementing VoIP increase our company's vulnerability to hackers and denial-of-service attacks?

Andrew Graydon EXPERT RESPONSE FROM: Andrew Graydon

Pose a Question
Other Unified Communications Categories
Meet all Unified Communications Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 04 October 2005
Will implementing VoIP increase our company's vulnerability to hackers and denial-of-service attacks?

>
EXPERT RESPONSE
Currently there is a lot of commentary and information available about the security of VoIP systems which is, to be blunt, pure scaremongering. Typically, in an implemented VoIP installation of an IP PBX, with IP hard phones on the desk and a connection from the IP PBX to the PSTN provider using a PRI or similar trunk, there are no external security concerns. This type of installation, which accounts for the majority of enterprise and SMB implementation, is considered a 'campus' system and is as secure externally as any current digital or analog PBX installation. There is, however, one small security issue with this type of installation.

There is a concern regarding the internal possibility of 'man-in-the-middle' type of attacks, such as eavesdropping, interception, caller-ID fraud, etc. While this may sound fraught with danger, since all of the VoIP communications are internal, it will only cause an issue if the internal network is compromised by a trusted user, either onsite or through a secure remote connection.

VoIP installations do, however, become more of a security concern when the IP traffic containing the voice data is passed over the open Internet. This opens up the possibilities of all 'man-in-the-middle' attacks originating from every external IP address on the network (i.e. anyone), with the possibility of DoS attacks being directed against the open ports on your perimeter necessary for the VoIP traffic to communicate with the recipient.

Before you decide not to implement an open VoIP system though, it is important to remember that HTTP and SMTP suffer from the same issues. In the case of SMTP, you use a secondary system after your firewall to guard against attacks such as viruses, spyware, spam, DoS attacks, and other threats to your mail system. VoIP systems can be secured in a similar fashion with perimeter security devices giving you the protection to deploy IP PBX with the same piece of mind as you utilize your e-mail.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
UC Security
Why is VoIP authentication essential?
Traffic logging and VoIP encryption
Criminal abuse of VoIP
Alternative to keeping data and VoIP traffic on separate VLANs
Do session border controllers (SBCs) improve security at the level of VoIP traffic?
Can VoIP and firewalls work together for the greater security good?

VoIP Security
Security concerns for enterprise Skype
SIP tutorial
Unified communications security risks and countermeasures
Can outsiders access my VoIP line and gather confidential data?
Top VoIP Chapter Downloads of 2007
Best practices for instant messaging security
Top rated VoIP security tips of 2007
Voice over IPv6: Architectures for Next Generation VoIP Networks
VoIP vulnerability threatens data
How to Cheat at VoIP Security

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
vishing  (SearchUnifiedCommunications.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Voice and Data Communications Tips
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts