Feeds

VoIP security group goes on the defensive

Circle the wagons

  • alert
  • submit to reddit

Internet Security Threat Report 2014

More than 20 networking and security organisations have formed the voice-over-IP telephony (VoIP) Security Alliance. The group will monitor security risks to VoIP services, work to reduce existing threats, and identify new dangers. Members include 3Com, the SANS Institute, Symantec and Siemens.

The group warns that attacks on VoIP systems are inevitable, as the technology becomes more widespread. VoIP is still quite new, and the numbers of people using it are small enough that there is no commercial reason to attack the systems.

However, as voice and data networks converge, the security risks of one will apply to the other. Organisations must be ready for spam or phishing attacks on their telephone systems, for instance.

VoIPSA's efforts to combat this perceived risk will include running email discussion forums, publishing white papers and funding research into VoIP security, as well as developing tools and methodologies for public use.

Ari Takanen, CEO and co-founder of Codenomicon, argues that an active community in VoIP security now, could prevent a descent into the "patch-and-penetrate race" that has afflicted email.

Brian Kelly, director of the Giuliani Advanced Security Center at Ernst & Young said: "Despite the advantages of VoIP, if the technology is not implemented properly and securely, we will likely circumvent existing security controls and expose our networks," said

Find out more about VoIPSA here. ®

Related stories

Cisco patches VoIP vuln
Pipex gift-wraps VoIP for business
Nokia demos mobile IPv6 call

Internet Security Threat Report 2014

More from The Register

next story
George Clooney, WikiLeaks' lawyer wife hand out burner phones to wedding guests
Day 4: 'News'-papers STILL rammed with Clooney nuptials
Shellshock: 'Larger scale attack' on its way, warn securo-bods
Not just web servers under threat - though TENS of THOUSANDS have been hit
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
PEAK IPV4? Global IPv6 traffic is growing, DDoS dying, says Akamai
First time the cache network has seen drop in use of 32-bit-wide IP addresses
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
Stunned by Shellshock Bash bug? Patch all you can – or be punished
UK data watchdog rolls up its sleeves, polishes truncheon
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.