VoIP security wake-up call

VoIP security wake-up call

Staff Writer  |   August 01, 2006

A recent high-profile hacking case involving VoIP operators has once again focused attention on security issues. How widespread the problem becomes, however, could be dictated by service providers' attention to IP security in general

Warnings about inherent vulnerabilities in VoIP services are not new, but until recently they were more theoretical than 'in the wild'. That all changed in June, however, when two alleged high-tech thieves were charged with defrauding unwitting service providers of more than a million dollars.


One of the two, Edwin Andrew Pena, was the owner of a seemingly legitimate VoIP wholesaler, Fortes Telecom, which would illegally route calls, up to 10 million minutes' worth, through service providers including Net2Phone and then bill for those calls. The hack involved finding a compromised corporate IP-PBX to disguise where the traffic was coming from - actually an IP variation of a similar scam involving company PBXs from years ago.


(For full details of the incident and charges, the court documents are available here
)
While the incident has gained attention because it's the first large-scale VoIP fraud to be made public, the more important question is, was it an isolated incident or does it point to a growing trend of attacking VoIP services now that there is a critical mass of users‾ Opinions differ.
VoIP pioneer Jeff Pulver, one of the co-founders of Vonage, believes there is too much hype surrounding the incident. 'I think the theft of minutes from Net2phone was a straight steal and the fact that it was IP minutes is once again getting too much attention,' he told Telecom Asia.
However, there are plenty of experts who believe that there are serious problems that will only grow if security issues related to VoIP are not addressed. David Piscitello, president of network and security consulting firm Core Competence and co-author of the recently published book 'Understanding Voice over IP Security', has noticed a rise in incidents reported through security mailing lists and other forums.

'Increasingly, more VoIP product vulnerabilities are being reported and more inquiries are made about how to penetrate networks through VoIP protocols and SIP/IPBX configurations,' Piscitello said. 'This tells me that VoIP is large enough and there is a financial motivation (eg, toll fraud) to make it a serious target.'

Of course media hype and security do go hand-in-hand, as evidenced by scaremongering about viruses for mobile phones and IM (which is not to say the industry shouldn't pay attention to these platforms). In the case of VoIP, the media focus could also be on the wrong areas, according to David Endler, chairman of the Voice Over IP Security Alliance (VOIPSA) and director of security research for 3Com's TippingPoint security division.


'Lately there seems to be an explosion of press hype around the possibility of hackers exploiting voice over IP networks and services,' Endler said, pointing to areas such as caller ID spoofing, toll fraud, eavesdropping and call hijacking. However, there is less attention given to the threats that can hit any IP data network, including VoIP services, such as denial-of-service attacks, worms, viruses and hacker exploitation.

Tell Us What You Think

Add comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <a> <p> <span> <div> <h1> <h2> <h3> <h4> <h5> <h6> <img> <img /> <map> <area> <hr> <br> <br /> <ul> <ol> <li> <dl> <dt> <dd> <table> <tr> <td> <em> <b> <u> <i> <strong> <font> <del> <ins> <sub> <sup> <quote> <blockquote> <pre> <address> <code> <cite> <embed> <object> <strike> <caption>
  • Lines and paragraphs break automatically.
  • Use <!--pagebreak--> to create page breaks.

More information about formatting options

Voices_tabs

Nicole McCormick
As opposition still ponders its policy
Robert Clark
Nokia lacks confidence in its OS and CEO
Santosh Sathanur/Ovum
As do enterprise services
Evan Kirchheimer/Ovum
Operators are turning to the technology with renewed vigor
Martin Creaner
The next evolution of NGOSS
John C. Tanner
It's not clear how consumers benefit from industry-preferred model of exclusive TV content contracts

Video from Telecom Channel

Converged billing still top concern -- Cerillion
The industry has attempted to move to simpler billing models but complexity still dominates, driven by product bundling and data packaging.    
 

businessweek_industryview

Ville Heiskanen, Peter Elstrom
FCC says 14-24m unlikely to get higher-speed connection any time soon
Sampath Paranavitane, hSenid Mobile
The foundation of a loyal following around self-created applications

Frontpage Content by Category

Telecomasia.net's most popular news stories, blogs, analysis and features in the first six months of 2010

MWC2010 List

MOBILE WORLD CONGRESS 2010
HTC guns for top 3 smartphone makers
Powermat wants to charge your desktop
Femtos outlook improves as cellcos seek offload options
Cheaper smartphones key to broadband takeup

lighter_side_telecom_career

Staff writer
Turning your mobile device into its own mouse
Dylan Bushell-Embling
Responding to panel suggestions for turning around the PSUs