Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity
    • Networking

    New VOIP Exploits Coming Soon

    Written by

    Michael Myser
    Published December 1, 2004
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Before long, VOIP systems will be filled with spam, open to hackers and taken down by worms. But security, infrastructure and VOIP vendors say its important to get ahead of the curve, and they encouraged enterprises to consider security first when implementing VOIP systems in a panel Wednesday at Ziff Davis Medias online Virtual Tradeshow on security.

      “Weve already seen instances where good-size enterprises had their VOIP infrastructures taken down by a worm,” said Chris Thatcher, national practice leader at Dimension Data Holdings, a global IT services firm based in Reston, Va.

      “Theres been a lack of security in the design and development of VOIP [voice over IP] systems, and buyers arent taking security concerns into consideration,” Thatcher said.

      Enterprises instead have focused almost exclusively on price, features and performance, often leaving new VOIP systems open to threats.

      According to panelist Andrew Graydon, vice president of technology at security firm BorderWare Technologies Inc., those risks include the common security breaches that enterprises deal with today, including DDoS (distributed denial-of-service) attacks, malicious code, spoofing and phishing.

      But enterprises also need to look out for unique-to-VOIP threats such as eavesdropping and “VBombing,” where hundreds or thousands of voice mails can be quickly left on a single VOIP console.

      Graydon said vendors are loath to admit that these weaknesses exist, let alone that theyve already been exploited.

      “Its such a new market, no one wants to scare the consumer,” he said. “But I can already go onto hacking Web sites and find script for attacks [on VOIP systems].”

      /zimages/2/28571.gifClick here for a Q&A about VOIP and SIP security.

      Graydon said a bulk of those attacks can be accomplished at the application layer, which for most major vendors is based on SIP (Session Initiation Protocol). Firewalls and VPNs can adequately handle transport-layer security for VOIP, but he compared SIP with SMTP and HTTP for Web and e-mail applications, which were largely ignored until security issues arose.

      “All of the vulnerabilities that exist for e-mail also exist for VOIP,” Graydon told eWEEK.com prior to the panel. “Lets not make the same mistakes.” He said Ontario-based BorderWare is working with major VOIP vendors and telcos to install the companys SIPAssure firewall appliance.

      Dimensions Thatcher also spoke about the increased number of holes and layers that must be protected in a VOIP infrastructure.

      “By mixing voice and data, and sharing a common infrastructure, there are more ways for attackers to get in,” he said. “You cant rely on any one security control as a silver bullet.”

      And when can enterprises expect attacks?

      “Itll be sooner rather than later,” Thatcher said. “As the VOIP market grows, hackers and spammers will focus on it more and more.”

      The panel discussion is archived at www.securityshow.eseminarslive.com and can be accessed for free.

      Editors Note: The Ziff Davis Media Security Virtual Tradeshow is run by eSeminars, a division of Ziff Davis Media, parent company of eWEEK.com.

      /zimages/2/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

      Michael Myser
      Michael Myser

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×