Telephony LIVE

Know a service provider that is DEFINING INNOVATION?

Nominate a service provider today for the Telephony Innovation Awards, to be held at Telephony LIVE: The 2008 Telecom Summit!

Learn more or Nominate!

         Subscribe in NewsGator Online   Subscribe in Bloglines

Sipera sounds VoIP security alarm

more on the topic

More Related Articles

The proliferation of voice over IP and softphones—as well as smartphones, which combine Wi-Fi access with cellular technology—poses a significant security risk for enterprise data networks, a leading security software company is saying today. Sipera Systems, which specializes in VoIP security, said research by its Viper Labs shows it is possible for hackers to take control and delete or steal data from a laptop running an enterprise VoIP softphone.

The company is demonstrating the dangers of VoIP-based attacks on corporate networks today at the Black Hat USA 2007 Conference. Sipera operates both a group that looks for exploits and other vulnerabilities and a separate organization that designs security software, said Krishna Kurapati, founder and chief technology officer.

“We have found that smartphones, where you can download the client and do VoIP on the phone, are more vulnerable to hacking because they have limited memory and limited capacity,” Kurapati said. The company tested numerous brands of phones and software clients, he added. “In some cases, you could cause a [denial-of-service] attack or exploit that phone and make it into a bot and then use that phone to send spam.”

VoIP softphones and smartphones that run VoIP clients are more vulnerable to hacking because “they are having for the first time to support an open protocol such as [session initiation protocol],” Kurapati said. “This is a very porous protocol that can be easily hacked into because, for example, a SIP message, which is used for call set-up or initiation, can be sent to the phone directly. In this scenario, every phone acts as a server since it is always available to receive calls. Anybody can send a request to that phone. That is both good and bad. When they send that message, it can be for many purposes; it could be DoS; it could be toll fraud.”

And the hacking isn’t limited to the VoIP service itself, he added, but can use VoIP as a way of getting at data stored on a laptop.

“We can send a SIP message to a softphone running on a laptop, and it takes control of that laptop,” he said. “It can copy certain files or delete them.”

Traditional firewalls can’t stop these threats, Kurapati added, and neither can traditional authentication security processes. Sipera believes most enterprise IT managers aren’t aware of the dangers.

What the industry needs, and what Sipera is working to provide, he said, is technology developed for real-time communications that takes a comprehensive look at incoming traffic to protect suspicious content or anomalies. Sipera is regularly publishing VoIP vulnerabilities that it has detected on its Web site, and the numbers are in the thousands, the company said.

Get Updates Via Email

related resources

popular articles

Want to use this article? Click here for options!
© 2008 Penton Media Inc.

White Papers

WHITE PAPER

Network Evolution to SIP-based Networks: Migration Strategies for Success

This paper explores the benefits of optical control plane functionality for service providers. You’ll learn the benefits of Ciena's CoreDirector, the first intelligent optical switch. DOWNLOAD NOW

Podcasts

PODCAST

A NXTcomm08 Podcast: George Dobrowski, Broadband Forum

George Dobrowski, chairman and president of the Broadband Forum, speaks with Associate News Editor Sarah Reedy about the broadband industry and its relevant themes at NXTComm08. LISTEN

Blogs

BLOG

What happened at NXTcomm08

Recuperating from the big show, here are some reflections on some of the more prominent themes amid activity at the show... READ

E-Books

E-BOOK

READ E-BOOK: MANAGING THE CUSTOMER EXPERIENCE

This e-book explains how to keep your customers happy, reduce churn and strengthen profits. Sponsored by CA’s Wily Technology Division. READ NOW!

Events

FEATURED EVENT

NXTcomm08: News from the show as only Telephony can deliver!

The editors of Telephony have all the news from NXTcomm08, including keynote recaps, podcasts, video interviews and much more! Visit nxtcommnews.com.

TV

TV

Interview with Jim Hansen of Embarq at NXTcomm08

Tune in to Telephony TV to watch an interview with Embarq's Jim Hansen at NXTcomm08. WATCH IT NOW.

  • Telephony Content
  • Telephony Content

current issue

Current Issue

June 30, 2008

Telecom's top execs had lots to say at NXTcomm08 -- our editors covered every word. Read Now

Telephony Innovation Awards

The second annual Telephony Innovation Awards recognize service providers who have developed unique or first-to-market offerings that either utilize technology or address customers’ needs in a new way. Nominate a service provider for this distinctive award!
Learn more or
Nominate

NXTcomm08 Show Daily News

Get up-to-the-minute news from NXTcomm08 -- before, during and after the show! Hear interview podcasts, announcements, commentary and more. Visit www.nxtcommnews.com!

more news

Global >>

MORE

Ethernet >>

MORE

Independent >>

MORE

IPTV >>

MORE

IMS >>

MORE

WiMax >>

MORE

VOIP >>

MORE

FTTX >>

MORE

Access >>

MORE

Broadband >>

MORE

Wireless >>

MORE

Software >>

MORE

Podcasts >>

MORE

Get Updates Via Email

Browse Issues

  • June 30, 2008
  • Jun 16, 2008
  • May 19, 2008
  • May 5, 2008
  • Apr 28, 2008
  • Apr 14, 2008
  • Mar 31, 2008