Exclusive New Research from the Telecom Leader

Survey stats * market share * real world deployments * and more

Now with two ways to buy…

      Subscribe in NewsGator Online   Subscribe in Bloglines   
   Comments

Sipera sounds VoIP security alarm

more on the topic

More Related Articles

The proliferation of voice over IP and softphones—as well as smartphones, which combine Wi-Fi access with cellular technology—poses a significant security risk for enterprise data networks, a leading security software company is saying today. Sipera Systems, which specializes in VoIP security, said research by its Viper Labs shows it is possible for hackers to take control and delete or steal data from a laptop running an enterprise VoIP softphone.

The company is demonstrating the dangers of VoIP-based attacks on corporate networks today at the Black Hat USA 2007 Conference. Sipera operates both a group that looks for exploits and other vulnerabilities and a separate organization that designs security software, said Krishna Kurapati, founder and chief technology officer.

“We have found that smartphones, where you can download the client and do VoIP on the phone, are more vulnerable to hacking because they have limited memory and limited capacity,” Kurapati said. The company tested numerous brands of phones and software clients, he added. “In some cases, you could cause a [denial-of-service] attack or exploit that phone and make it into a bot and then use that phone to send spam.”

VoIP softphones and smartphones that run VoIP clients are more vulnerable to hacking because “they are having for the first time to support an open protocol such as [session initiation protocol],” Kurapati said. “This is a very porous protocol that can be easily hacked into because, for example, a SIP message, which is used for call set-up or initiation, can be sent to the phone directly. In this scenario, every phone acts as a server since it is always available to receive calls. Anybody can send a request to that phone. That is both good and bad. When they send that message, it can be for many purposes; it could be DoS; it could be toll fraud.”

And the hacking isn’t limited to the VoIP service itself, he added, but can use VoIP as a way of getting at data stored on a laptop.

“We can send a SIP message to a softphone running on a laptop, and it takes control of that laptop,” he said. “It can copy certain files or delete them.”

Traditional firewalls can’t stop these threats, Kurapati added, and neither can traditional authentication security processes. Sipera believes most enterprise IT managers aren’t aware of the dangers.

What the industry needs, and what Sipera is working to provide, he said, is technology developed for real-time communications that takes a comprehensive look at incoming traffic to protect suspicious content or anomalies. Sipera is regularly publishing VoIP vulnerabilities that it has detected on its Web site, and the numbers are in the thousands, the company said.

Want to use this article? Click here for options!
© 2009 Penton Media Inc.

  • Telephony Content


blog comments powered by Disqus
Get Updates Via Email
  • Telephony Content

related resources

popular articles

Webcasts

WEBCAST

Reduce Customer Churn and Cut Costs Webcast | July 22, 2009

Learn the best practices for online customer billing and service – how to implement a paperless bill, drive traffic to your web site, improve customer service.

REGISTER NOW

White Papers

WHITE PAPER

Automated End-to-End Managed Service Delivery. Sponsored by Ciena.

Ciena’s industry-leading CoreDirector Multiservice Optical Switch with FastMesh® has been used for efficient and robust core switching in the world’s largest networks. DOWNLOAD NOW

Podcasts

PODCAST

Wikimedia explores the phone as encyclopedia

Kul Wadhwa, head of business development, Wikimedia Foundation, discusses with senior editor Kevin Fitchard the Wikipedia’s future on the mobile phone. LISTEN

Blogs

BLOG

I-feature: Readers respond

As promised, a key component of Telephony’s new Interactive Featureis reader participation READ

E-Books

Telephony May Special Section: Carrier Ethernet

No slowdown in sight!

Read how carrier Ethernet is defying the slow economy. DOWNLOAD NOW!

  • Telephony Content
  • Telephony Content

commentary

Carol Wilson
Energy bill should energize change

June 29, 2009

Read Now

Carol Wilson
Steve Hilton
Ask Steve

June 29, 2009

Read Now

Steve Hilton

Recent Comments

Follow comments on Telephony

More ways to stay informed

Find us on Facebook

follow us on twitter

Browse Issues

  • June 1, 2009
  • October 1, 2008
  • April 1, 2009
  • March 1, 2009
  • February 1, 2009
  • January 1, 2009
  • December 1, 2008