Feeds

VoIP security group goes on the defensive

Circle the wagons

  • alert
  • submit to reddit

Intelligent flash storage arrays

More than 20 networking and security organisations have formed the voice-over-IP telephony (VoIP) Security Alliance. The group will monitor security risks to VoIP services, work to reduce existing threats, and identify new dangers. Members include 3Com, the SANS Institute, Symantec and Siemens.

The group warns that attacks on VoIP systems are inevitable, as the technology becomes more widespread. VoIP is still quite new, and the numbers of people using it are small enough that there is no commercial reason to attack the systems.

However, as voice and data networks converge, the security risks of one will apply to the other. Organisations must be ready for spam or phishing attacks on their telephone systems, for instance.

VoIPSA's efforts to combat this perceived risk will include running email discussion forums, publishing white papers and funding research into VoIP security, as well as developing tools and methodologies for public use.

Ari Takanen, CEO and co-founder of Codenomicon, argues that an active community in VoIP security now, could prevent a descent into the "patch-and-penetrate race" that has afflicted email.

Brian Kelly, director of the Giuliani Advanced Security Center at Ernst & Young said: "Despite the advantages of VoIP, if the technology is not implemented properly and securely, we will likely circumvent existing security controls and expose our networks," said

Find out more about VoIPSA here. ®

Related stories

Cisco patches VoIP vuln
Pipex gift-wraps VoIP for business
Nokia demos mobile IPv6 call

Top 5 reasons to deploy VMware with Tegile

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.