Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Different Passwords for Differrent Sites without the Hassle | Main | SQL Injection Attacks: Websites' New Vulnerability »

Security Issues with VoIP

We've posted an article in the Messaging and Web Security Digital Library on security issues you should keep in mind when deploying and using voice of IP (VoIP). Here's an excerpt:

Voice over IP (VoIP) services over a compelling alternative to traditional telephony services. VoIP provides comparable levels of quality and features but at a fraction of the cost plain old telephone service (aka "POTS"). As with any network service, there are security issues to contend with. VoIP is subject to general threats that affect other services, such as denial of service attacks, as well as some more limited range attacks, like threats to Session Initiation Protocol (SIP). (SIP may also be used for multimedia communications and streaming multimedia so attacks against it are not strictly VoIP specific). In spite of risks associated with voice over IP services, businesses are adapting it because of favorable costs, benefits of messaging consolidation, and additional features available in VoIP systems. If you have adopted or are considering a move to VoIP, here are some security issues to consider when planning and maintaining your deployment:
  • Spit, or voice over IP spam
  • Vishing, voice over IP phishing
  • Denial of service attacks
  • Data leaks
  • VoIP device configurations and spoofing attacks

Other recent articles cover virtualization, online gaming, managing security budgets, dealing with evolving malware, Ajax security, data loss prevention and more. Check them out in the digital library.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/753

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net