VoIP Security Considerations

written by: Waqas Taimoor; article published: year 2010, month 01;

In: Root » Electronics and communication » VOIP

  Share  
|
  PL  |  NL  |  FR  |  ES  |  PT  |  IT  |  DE  |  DK  |  NO  |  SE  |  FI  |  GR  |  JP  |  CN  |  KR  |  RU  |  AE


Factors to be considered when deploying VoIP infrastructure across an organization to help eliminate the most common VoIP security threats such as the distributed denial of service (DoS) attack, spams and frauds.

VoIP Security Considerations

For a successful VoIP rollout across an organization, several factors should be considered. The following percausions will help eliminate the most common VoIP security threats such as the distributed denial of service (DoS) attack, spams and frauds.

During VoIP configuration/installation, it is important to establish security infrastructure including firewalls, VPNs etc. to be capable of supporting the advanced security requirements for VoIP and be voice optimized at the same time. The VoIP security protocols dynamically allocate ports during call setup, requireing opening and closing of ports at the security gateway on demad. The protocal required the voice traffic inspection at the network and application level to address the challenges of VoIP protocols in Network Address Translation (NAT) environments.

Similar to other services using network, there are critical security vulnerabilities being identified for VoIP.
It is important to have the IP-PBX and IP Phone firmwares always updated and patched for the latest security vulnerabilities. Regular security assessments of your VoIP infrastructure provide identification and remediation of such security flaws to avoid attacks and prevent outages. Your IP-PBX is the heart of your VoIP infrastructure and it must be updated and patched as necessary.

Since the VoIP gateways, servers and phone can be configured remotely, backdoor and front door access is sometimes enabled for ease of configuration. It is recommended to properly secure any remote access and configuration capabilities to individual VoIP devices to eliminate any security breaches. It is important to note that the endpoint credentials and administrator passwords on such devices are a very common avenue for attacks. In general disable any insecure remote access features, such as FTP and Telnet, and disable local administration and management features.

If your VoIP traffic goes over the Internet, use encryption technologies like IPsec tunnels to secure the VoIP traffic. While many of the VoIP protocols include capabilities for encryption and authentication, most of them are optional. It is essential to establish secure tunnels for carrying the VoIP information streams (call signaling, call control and media) between sites.

Wherever possible, leverage VLANs to separate voice and data devices and traffic. This may have limited impact on security, however deploying VoIP devices on separate VLANs isolates data traffic from voice and signaling traffic and permits utilization of Quality of Service (QoS) capabilities.

When creating passwords for accounts, follow secure password guidelines such as making password long, using a combination of numbers and alphabets, not using common names, or same as the account numbers.

SigVoice Telecom Corp., is a provider of Voice over IP (VoIP) equipment to small and medium businesses in Canada and US. It has been serving small and medium businesses since 2005 with its reliable, stable and enterprise-class VoIP Phone Systems.

Share

Disclaimer

1) E-articles is not responsible for the information contained by this article as well for any and all copyright infringements by authors and writers. E-articles is a free information resource. If you suspect this article for any copyright infringement, please read the terms of service and contact us or use the "Report this article" button on this page to investigate the problem.
2) E-articles is not responsible for inaccuracies, falsehoods, or any other types of misinformation this article may contain and will not be liable for any loss or damage suffered by a user through the user's reliance on the information gained here.