Tuesday, 27 November 2012
Scam Free Work At Home Jobs
Voice over IP security in general, or for that matter, 50% of small and medium sized businesses (SMBs) had very little trust in the security offered by VoIP vendors, the Computer Technology Industry Association, in a recent report issued by CompTIA.
And having your voice network go down for even the shortest time is intolerable for most business, and worms can all wreak havoc on a network, trojan Horses, viruses. Having your voice and data running on the same infrastructure leaves your telecommunications particularly vulnerable to all the security threats inherent in an IP network, it is true.
And pose a very real threat to the very time sensitive requirements of voice over IP, if not imminent, the possibilities are there, while attacks on VoIP networks in particular are by no means widespread. And most attacks can be stopped at the gateway by a good network administrator, security has come a long way, that said.
As well as some security measures that could be taken to prevent such attacks, the following is a compilation of just some of the security threats facing a voice over IP network.
SPIT - The new Spam for VoIP
In some cases put in jail, and major offenders have been fined heavily, laws have been made to reduce the clutter in our mailboxes. Clogging up our mailboxes and causing us to waste our valuable time, who among us has not received dozens of unsolicited emails? Most anybody that receives email is familiar with the term Spam.
Albeit a few minutes later than it would normally take, eventually the recipient will receive their emails intact, as email applications are connectionless and not sensitive to time delay. And can also cause network problems utilizing a good majority of bandwidth that is meant for other things, spam is frustrating for the recipient, at worst. Ending up in the mail boxes of anyone that has an email address on that network, over a network or networks, or other unwanted messages, announcements, spam is basically the broadcasting of advertisements.
Severely disrupting Quality of Service and causing a major degradation in voice quality, spitters that target VoIP gateways can use up the available bandwidth. Can have far greater consequences than email spam, otherwise known as SPIT, spam over Internet telephony.
Be done, however, it can. It is a little more difficult as the spitter would have to hack into the network in order to implement the broadcast, or even your companies LAN, on closed networks like Vonage or Skype. The open nature of VoIP phone calls makes it easy for spitters to broadcast audio commercials just as email advertisements are broadcast.
Or warn of impending disasters in the event of catastrophe, emergency services could easily communicate mandatory evacuations, and on a broader scope, companies should be able to get out important messages quickly. Necessarily a bad thing, in itself, the ability to broadcast audio messages over a VoIP network is not.
To prevent solicitors from bombarding your voice mail box one other legal recourse is to get on the national Do Not Call list, Skype had found and closed the loophole in the network, shortly thereafter. And users were inundated with unsolicited audio messages, the peer to peer VoIP network Skype got hacked into, in 2004. We have not seen a lot of it, to date, while Spit is certainly a technical possibility.
Eavesdropping
To gain knowledge of confidential business information, or worse, hackers then have the ability to learn user ids and passwords. Saving the data as an audio file, and in the case of VoIP, and generally requires a packet analyzer to intercept IP packets, this concept is nothing new to IP data networks. Probably one of the scariest vulnerabilities of VoIP is the ability of an outsider to eavesdrop on a private conversation.
And the knowledge of how to hack into your network, some readily available software, a hacker requires only a laptop, in the case of an IP network. For someone to tap into your home phone line pretty much requires a physical presence outside your house, while it is true that eavesdropping occurs on traditional telephone lines as well as cellular networks.
To protect confidentiality and as not to slow down the packet flow, the challenge with voice is to encrypt strongly and quickly. And the same concept holds true for voice packets, security analysts have long used encryption techniques to protect the confidentiality of data traveling through an IP network.
No type of telecommunication is 100% secure, if someone really wants to listen in on your calls, nevertheless.
Phishing the Waters of Voice over IP
Or to steal identities, hackers can use it to access bank accounts, depending on what information they get. Touch tones can be easily deciphered, even if the call is automated. The attack could come as a voice mail message urging you to call a designated number and provide your user information, in the case of VoIP. And even social security numbers, credit cards, bank accounts, passwords, phishing is designed to trick a user into revealing sensitive data such as user names, another variation of an email attack.
Be it via data or voice, it becomes common knowledge to never give out sensitive information to automated media, as more users become familiar with the pitfalls of the Internet, while you can program a PBX to restrict call backs to known phishers.
SIP Registration Hijacking
And basically maps their telephone number to an IP address, which maintains a database of all users subscribed to the network, the process involves a Registrar (in some cases the company PBX itself). The Session Initiation Protocol (SIP) is becoming widely accepted as the method for setting up VoIP phone calls.
Or a simple diversion of communication, denial of service attacks that can render the user's device useless, attacks can take the form of fraudulent toll free calls. Who substitutes his IP address for that of the legitimate one, registration hijacking occurs when the packet header of either party is intercepted by a hacker.
Spoofing
Transfer cash from a stolen credit card number, or in the case of Caller ID Spoofing, modify data, hackers can use this attack to misdirect communications, once the IP address or phone number of the trusted host is discovered. Spoofing requires hacking into a network and intercepting packets being sent between two parties, another hack that is well known in data networks is spoofing Also known as a man in the middle attack.
Putting these two protocols together forms the acronym SIPS. The up and coming mechanism to achieve this is to send SIP messages over an encrypted Transport Layer Security channel, today. Can be prevented by employing encryption techniques at the call set up phase, as well as other hacks such as eavesdropping, both of these spoofs. SIP registration hijacking is a form of spoofing.
Such interruptions are considered intolerable for voice applications, but with a downtime tolerance of no more than 5 minutes a year, voIP is as vulnerable as any application to these disruptions, since a converged network consists of data and voice. Hacked into, and are, there is no doubt that IP networks can be.
Malicious hacking attempts are bound to follow, industry experts agree that as voice over Internet telephony becomes more wide spread. And are presented here as a what could happen in the future scenario, most of these security threats are not wide spread, as of today.
And diligent intrusion detection, utilizing firewalls and VPNs for network communications, closing down unused ports and services, including but not limited to changing default passwords, and must be locked down by using common sense approaches, no VoIP solution is secure out of the box. Using all the known security precautions typical of an IP network, these and other VoIP security threats can be prevented by a vigilant network staff.
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment