Ensuring the Security of Your Calls
From VoIP.ms Wiki
| [checked revision] | [quality revision] |
| Line 30: | Line 30: | ||
| - | If the expected value of the items they intend to steal from the house outweighs the risks of breaking in, that’s when they will make their decision. When hacking a business phone system, the principles are similar, but the scale is different. | + | If the expected value of the items they intend to steal from the house outweighs the risks of breaking in, that’s when they will make their decision. When hacking a business phone system, the principles are similar, but the scale is different. With the global VoIP market predicted to reach $93.2 billion by 2024, phone system hacking and exploitation is fast becoming a lucrative undertaking for suitably skilled cyber criminals. With the value of these ill-gotten gains rising exponentially year-on-year, it is essential for everyone in the industry including the carriers, service providers, system integrators, IT administrators/users and of course the hardware and software vendors and manufacturers themselves to prioritize and improve network security. |
| - | + | ||
| - | + | ||
| - | With the global VoIP market predicted to reach $93.2 billion by 2024, phone system hacking and exploitation is fast becoming a lucrative undertaking for suitably skilled cyber criminals. With the value of these ill-gotten gains rising exponentially year-on-year, it is essential for everyone in the industry including the carriers, service providers, system integrators, IT administrators/users and of course the hardware and software vendors and manufacturers themselves to prioritize and improve network security. | + | |
| Line 56: | Line 53: | ||
| - | While this is the primary way for hackers and fraudsters to take advantage of a poorly-protected system, weak passwords and a lack of encryption in an IP-PBX infrastructure can leave the doors wide open to other types of malicious activity. For example, as a result of the computerized nature of IP telephony, it is much simpler than with fixed-line telephones to secretly record internal calls. Rather than having to install a physical device, calls can simply be recorded using the right software. Often, this kind of threat comes from an employee inside the organization, making it difficult to protect against. If a company is using an unencrypted VoIP protocol, then there is no barrier in place to stop calls from being recorded. Even if the threat doesn’t come from an employee, or outside groups with an interest in recording a company’s telephone conversations, a Trojan could be used to install the recording tool. And things could get even worse if the phone is used to get into the company’s network – entering the entire server structure, like a burglar accessing a house via the cellar. | + | While this is the primary way for hackers and fraudsters to take advantage of a poorly-protected system, weak passwords and a lack of encryption in an IP-PBX infrastructure can leave the doors wide open to other types of malicious activity. For example, as a result of the computerized nature of IP telephony, it is much simpler than with fixed-line telephones to secretly record internal calls. Rather than having to install a physical device, calls can simply be recorded using the right software. Often, this kind of threat comes from an employee inside the organization, making it difficult to protect against. If a company is using an unencrypted VoIP protocol, then there is no barrier in place to stop calls from being recorded. Even if the threat doesn’t come from an employee, or outside groups with an interest in recording a company’s telephone conversations, a Trojan could be used to install the recording tool. And things could get even worse if the phone is used to get into the company’s network – entering the entire server structure, like a burglar accessing a house via the cellar. Think of it like this: You will need a reliable lock for your back door, front door, hatch to the cellar and to all the rooms in your house. Also making sure you have the keys to these locks, the risks are minimized, but it is still up to the owner to ensure that the doors are actually locked. |
| - | + | All these security threats make it imperative for companies / providers to run as much tests as possible, in order to ensure their customers and their communications are protected as they can be. Companies like SNOM have rooms with banks of devices being tested in a sped-up but true-to-life environment. Basically, the ATF (Automatic Test Framework) ran continuously tests their software. This means the elimination of security issues and software update before a problem has even been detected by the end customers. In other words, companies are proactively identifying and fixing issues, rather than waiting for customers to come banging on their support team's door screaming for help. In the particular case of SNOM, in addition to running a non-stop ATF security and software check, they also provide users with a comprehensive overview for implementing security and privacy measures on its service hub, service.snom.com. Topics covered include Port Authentication via 802.1x, Dynamic Blacklist Check. DECT encryption, TLS support and devices in a VPN. | |
| - | + | ||
| - | + | ||
| - | All these security threats make it imperative for companies / providers to run as much tests as possible, in order to ensure their customers and their communications are protected as they can be. Companies like SNOM have rooms with banks of devices being tested in a sped-up but true-to-life environment. Basically, the ATF (Automatic Test Framework) ran continuously tests their software. This means the elimination of security issues and software update before a problem has even been detected by the end customers. In other words, companies are proactively identifying and fixing issues, rather than waiting for customers to come banging on their support team's door screaming for help. | + | |
| - | + | ||
| - | + | ||
| - | In the particular case of SNOM, in addition to running a non-stop ATF security and software check, they also provide users with a comprehensive overview for implementing security and privacy measures on its service hub, service.snom.com. Topics covered include Port Authentication via 802.1x, Dynamic Blacklist Check. DECT encryption, TLS support and devices in a VPN. | + | |
| Line 97: | Line 88: | ||
| - | Imagine we are in the year 2025. There has been a catalogue of major changes to technology and behavior. People across the entire world have a multitude of tailored communications solutions designed to meet all of their personal and business requirements at their fingertips. To get to this point however, many businesses, across all industries and scales, have been lost. Their legacy is a lesson in security: take responsibility, maintain ongoing reviews, leave no stone unturned and shine a torch on every shadow. | + | Imagine we are in the year 2025. There has been a catalogue of major changes to technology and behavior. People across the entire world have a multitude of tailored communications solutions designed to meet all of their personal and business requirements at their fingertips. To get to this point however, many businesses, across all industries and scales, have been lost. Their legacy is a lesson in security: take responsibility, maintain ongoing reviews, leave no stone unturned and shine a torch on every shadow. This over-simplified statement is of no help to those responsible for their business’ security today, but what might help is to understand that most nowadays companies, work to the highest standards of development and innovation. As a fundamental basis of IP telephony and in recognition of our responsibilities, security is an area to which we dedicate a great deal of our resources. |
| - | + | ||
| - | + | ||
| - | This over-simplified statement is of no help to those responsible for their business’ security today, but what might help is to understand that most nowadays companies, work to the highest standards of development and innovation. As a fundamental basis of IP telephony and in recognition of our responsibilities, security is an area to which we dedicate a great deal of our resources. | + | |
| Line 106: | Line 94: | ||
| - | ''Final note from VoIP.ms: We have developed an outstanding relationship with SNOM over the past few months and keep on working in close cooperation with them to allow a seamless integration for our customers in common. | + | ''Final note from VoIP.ms: We have developed an outstanding relationship with SNOM over the past few months and keep on working in close cooperation with them to allow a seamless integration for our customers in common.'' |
Latest revision as of 20:43, 25 August 2021
|
Dear VoIP.ms blog enthusiasts, below you will find a guest blog article from one of our partners, an industry leading company: SNOM, a company founded in 1997 in Berlin, Germany; currently a multinational corporation that manufactures professional and enterprise VoIP telephone devices, they are known for VoIP pioneering as well as mass producing VoIP devices.
Once a hacker has access to the system, there are many ways in which they can disrupt the IP telephony network and potentially cause the business to lose large sums of money. One of the most common attacks, and indeed one of the most damaging, is when professional criminals attach an entire call center to the compromised network connection, routing thousands of calls over the one connection in a short period of time. Depending on how the IP-PBX routes its calls, and how regularly the company receives its bills, this activity can continue for months before being discovered, running up an astronomical telephone bill.
How much?!? Network security means financial security.
______ For more information, visit us at |