Home > Security News > Is it time for a VoIP firewall?
Security News:
EMAIL THIS

Is it time for a VoIP firewall?

By Amy Storer, News Writer
17 Aug 2005 | SearchEnterpriseVoice.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Spam commonly proliferates using STMP and HTTP protocols, which are critical to e-mail and the Internet, but it could soon become the nemesis of SIP as well.

Session Initiation Protocol (SIP) is a VoIP call-control and application protocol technology serving as the Internet Engineering Task Force's de facto standard for initiating a multimedia interactive user session.

More VoIP security resources
Visit SearchSecurity's VoIP Security Resource Guide for all the latest tips, expert advice and news related to securing voice over Internet Protocol.
Andrew Graydon, vice president of technology with Mississauga, Ontario-based BorderWare Technologies Inc., said traditional security measures -- such as authentication, authorization and IPsec -- are not designed to secure and manage SIP-based communications in real time.

But, Graydon said, new technologies like SIP firewalls are emerging to address the protocol's distinct security requirements. A SIP firewall is an appliance that manages and protects the traffic, flow and quality of VoIP and other SIP-related communications.

According to Graydon, the industry is working to secure voice communications at the transport layer with VPN-like encryption. But he said hackers will eventually learn how to attack Internet calls at the application layer.

BorderWare's recently released hardware and software SIP-based firewall, SIPassure, authenticates user connections and allows system administrators to set and enforce VoIP security policies to address application layer exploits.

More specifically, SIPassure's features include:

  • Protection with a range of controls, including unique session profiling that prevent spam and denial-of-service (DoS) attacks.
  • Antispam filters for securing, managing, monitoring and administering SIP-enabled communications.
  • Built-in audit and reporting capabilities designed to address critical security issues by providing visibility into all SIP-related communications, including SIP proxy, SIP registrar, spam, user access and capacity planning.

    While SIP-based firewalls aren't necessary today, Teney Takahashi, market analyst for The Radicati Group Inc. in Palo Alto, Calif., said companies will soon need a device like SIPassure to protect themselves from communication exploits.

    "It would be prudent for a company not to invest in something like this over the next couple of years," Takahashi said. "If they're going to protect their e-mail and their Web traffic, they should also protect their SIP traffic -- especially if they have VoIP or an instant messaging system they rely on for business communications."

    Takahashi said companies such as Cisco Systems Inc. may have security measures in place to prevent attacks on its SIP networks, but BorderWare was the first to market with its dedicated application for filtering out illegitimate SIP traffic.

    He said some vendors have products that filter out IM traffic or VoIP traffic, but no other offering filters SIP traffic at the application layer like BorderWare.

    "It definitely seems that SIP is the chosen protocol for real-time communication," Takahashi said. "As this trend progresses over the next few years, a SIP-specific firewall will become very valuable to companies."

    This article originally appeared on our sister site, SearchEnterpriseVoice.com.

    Tags: Network Protocols and SecurityVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Network Protocols and Security
    Expert calls SSL protocol vulnerability a non issue
    How to prevent phishing attacks with social engineering tests
    How SSL-encrypted Web connections are intercepted
    DNSSEC deployment challenges can be overcome
    Microsoft issues SMB vulnerability advisory, patch pending
    Microsoft repairs Windows media, TCP/IP vulnerabilities
    How to test IPv6 infrastructures
    DNSSEC deployments gain momentum since Kaminsky DNS bug
    Kaminsky interview: DNSSEC addresses cross-organizational trust and security
    How to create secure Windows FTP automation

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    5 terms you need to know before you employ VoIP  (SearchSecurity.com)
    digest authentication  (SearchSecurity.com)
    IGP  (SearchSecurity.com)
    IP spoofing  (SearchSecurity.com)
    Secure Sockets Layer  (SearchSecurity.com)
    smurfing  (SearchSecurity.com)
    Transport Layer Security  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts