Feeds

VoIP security framework erected

Talks about talk

Build a business case: developing custom apps

An industry group has released what's billed as the first comprehensive description of security and threats to Voice over IP (VoIP) systems. The framework - dubbed the VoIP Security Threat Taxonomy - was put together by the newly formed Voice over IP Security Alliance (VOIPSA) and is designed to provide the industry with a clearer view of VoIP security risks put into context with a discussion of technical trade-offs.

"Until now, the public has been uncertain about the various threats, how risks related to each other and technical trade-offs. This is fundamental to all future work in the field," said Jonathan Zar, secretary and outreach chair for VOIPSA, head of the taxonomy project and senior director for firewall supplier SonicWALL.

Major elements of the work include:

  • Core definitions that give specific meaning to privacy and security
  • A framework that effectively connects public policy and technology issues
  • Recognition of the human element in threats as distinct from their technical means
  • Specific sets of issues for consideration by legislative bodies and by law enforcement
  • A detailed structure for technical vulnerabilities across the value chain

The security framework is intended to be a framework for further (more detailed) technical work and discussion. VoIPSA is inviting comments on its work. Portions of the VoIP Security Threat Taxonomy are available for discussion by registering here.

The discussions will help inform the direction VoIPSA takes on net telephony security. David Endler, chairman of VoIPSA and director of security research for 3Com’s TippingPoint division, said it expects to deliver a list of security requirements for VoIP by the end of the year.

VOIPSA has recruited 100 organisations - including major carriers, software firms, equipment vendors, large users and system integrators - since its foundation in February 2005. More about the organisation can be found here. A public VoIP security discussion board (VOIPSEC) run by VOISPA can be found here. ®

The essential guide to IT transformation

More from The Register

next story
Rupert Murdoch says Google is worse than the NSA
Mr Burns vs. The Chocolate Factory, round three!
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Know what Ferguson city needs right now? It's not Anonymous doxing random people
U-turn on vow to identify killer cop after fingering wrong bloke
Germany 'accidentally' snooped on John Kerry and Hillary Clinton
Dragnet surveillance picks up EVERYTHING, USA, m'kay?
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
Think crypto hides you from spooks on Facebook? THINK AGAIN
Traffic fingerprints reveal all, say boffins
prev story

Whitepapers

Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Solving today's distributed Big Data backup challenges
Enable IT efficiency and allow a firm to access and reuse corporate information for competitive advantage, ultimately changing business outcomes.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.