TMCnet News
Why VoIP Security is DifferentSecurity has emerged as one of the biggest hurdles to the successful deployment of VoIP. One of the keys to deploying secure VoIP is understanding the true nature of VoIP networks, how they differ from data networks, as well as the new security issues created by VoIP.
By Bogdan Materna, CTO and VP Engineering, VoIPshield Systems
The emergence of VoIP technology is creating a major discontinuity in telecommunications. The promise of reduced hardware and operations costs coupled with a promise of new add-value services makes VoIP a compelling solution for enterprises and service providers. But at the same time VoIP introduces a whole new set of problems.
Current PSTN voice services provide high voice quality and very high reliability (99.999%), while carrying critical services such as E911, providing federal agencies with ability for lawful intercept, and ensuring a very high level of security. Clearly, all of these issues have to be addressed before VoIP services are deployed on mass scale, but security is the most critical area that has potential of delaying and disrupting VoIP deployment.
With the deployment of VoIP or IP Telephony accelerating, comes the increasing need to find ways to effectively secure VoIP so it as secure as PSTN. Currently, over half of all Private Branch Exchange (PBX) lines now shipping are VoIP and by 2006, for new installations, VoIP lines are projected to exceed the number of traditional telephone lines for both business and residential use.
As more and more organizations and service providers plan their migration to VoIP, the need to secure IP communications is becoming more urgent. For service providers who have established their respective brands as being synonymous with high levels of reliability, quality, and security, they must preserve these attributes in their VoIP offerings. Similarly, enterprises expect Internet telephony service to be as reliable and secure as the traditional telephone service. For both service providers and enterprises, there is a direct link between VoIP security infrastructure and VoIP service reliability, integrity, and performance. For any organization to successfully deploy VoIP, their must be a clear understanding of both the characteristics of VoIP and how they compare with traditional data networks.
Understanding How VoIP Security is Different: Traditional Data Security vs. VoIP Security
For service providers and enterprises to successfully deploy VoIP, it is important to understand that while some of VoIP security requirements in are similar to those in data networks, there are several areas that are specific to VoIP. Let’s examine these differences:
VoIP is Real-Time: First and foremost, VoIP is a real time service and requires security infrastructure to provide automated, real time response to the security threats in order to preserve very high availability expected by telephony users. The types of attacks that are common in the data security realm and may render email or the computer network unusable for several hours, are not acceptable when it comes to IP communication.
New Hardware and Components: VoIP infrastructures includes a wide range of components and applications such as telephone handsets, conferencing units, mobile units, call processors/call managers, gateways, routers, firewalls, and protocols that allow for new form and types of security attacks. Since the VoIP communications are carried in the form of packetized voice there is a potential for such malicious activities as call eavesdropping, malicious replay or identity theft.
New Types of Threats: VoIP services are offered with many features such call ID, call forward, voice mail, three-way calling and the like which open up service providers to a number of new threats such as toll fraud, service theft, voice spam (SPIT), and identity theft.
Delay, Packet Loss, and Jitter: Data security is based on deployment of a number of security devices and applications to protect and observe networks such as firewalls, Intrusion Detection Systems (IDS), Intrusion Prevention Systems (IPS), Virtual Private Networks (VPN), authentication services, anti-virus software and gateways. Paradoxically, VoIP is highly sensitive to delay, packet loss and jitter, making these security measures inadequate. For example, current firewalls/NAT will delay or block call setups, encryption engines will introduce additional jitter and in-line IDS/IPS devices will add delay to inspected packets. Another challenge of using data security devices for VoIP security is that there’s a lack of coordination between security devices making it ineffective in protecting VoIP services from sophisticated, system level attacks and internal threats.
New Technologies: Introduction of new wireless technologies and concepts such as VoIP over Wi-Fi, Wi-Max and IMS creates another area of security concerns. Presently VoIP wireless networks do not provide strong encryption and authentication and they are much more accessible to potential attackers. While the wireline networks require a physical access to the wires, wireless technology allows remote attackers tap into the VoIP networks without any physical access to the network.
Gateways: For the foreseeable future PSTN and VoIP networks will coexist and require media gateways that provide internetworking between carrier’s IP network and TDM based PSTN networks. This could enable cross-network security attacks impacting mission critical PSTN networks.
The stated goal of service providers and enterprises is to deliver VoIP services at availability levels approaching those of PSTN, e.g., less than one minute downtime a year. Upon examining the unique nature of VoIP networks and how they differ from data networks, it becomes clear current security practices that rely on human-centered response are insufficient to counter the threats and to maintain availability and integrity of VoIP infrastructure at those levels. Additionally, the sheer scale of VoIP deployments creates a need for the security infrastructure to scale to these multi-million subscriber deployments.
Conclusion
Real-time nature of VoIP, stringent QoS and availability requirements impose new requirements on the security infrastructure and processes and existing data security technologies fall short in addressing the unique needs of VoIP deployments. Security applications and devices must seamlessly support VoIP protocols without impacting QoS parameters such as packet delay, loss and jitter. The infrastructure used to secure VoIP must be able to support automated detection and response to the security threats in order to support PSTN like availability requirements. Without recognizing the differences between VoIP and data security, PSTN-level service will not become a reality.
About the Author
Bogdan Materna is the CTO and VP of Engineering at VoIPshield Systems (www.voipshield.com) a provider of VoIP security software. He can be reached at [email protected] or (613) 224-4443.
|
