Author Michael Talbert is a certified systems engineer and web designer with over 7 years experience in the industry. For more information on VoIP Telecommunications, visit the website VoIP-Facts.net, or the VoIP Facts Blog for up to date industry news and commentary.
In a recent report issued by CompTIA, the Computer Technology Industry Association, 50% of small and medium sized businesses (SMBs) had very little trust in the security offered by VoIP vendors, or for that matter, voice over IP security in general.
It is true, having your voice and data running on the same infrastructure leaves your telecommunications particularly vulnerable to all the security threats inherent in an IP network. Viruses, Trojan Horses, and worms can all wreak havoc on a network, and having your voice network go down for even the shortest time is intolerable for most business.
That said, security has come a long way, and most attacks can be stopped at the gateway by a good network administrator. While attacks on VoIP networks in particular are by no means widespread, the possibilities are there, if not imminent, and pose a very real threat to the very time sensitive requirements of voice over IP.
The following is a compilation of just some of the security threats facing a voice over IP network, as well as some security measures that could be taken to prevent such attacks.
SPIT: The new Spam for VoIP
Most anybody that receives email is familiar with the term Spam. Who among us has not received dozens of unsolicited emails, clogging up our mailboxes and causing us to waste our valuable time? Laws have been made to reduce the clutter in our mailboxes, and major offenders have been fined heavily and in some cases put in jail.
Spam is basically the broadcasting of advertisements, announcements, or other unwanted messages, over a network or networks, ending up in the mail boxes of anyone that has an email address on that network. At worst, spam is frustrating for the recipient, and can also cause network problems utilizing a good majority of bandwidth that is meant for other things. As email applications are connectionless and not sensitive to time delay, eventually the recipient will receive their emails intact, albeit a few minutes later than it would normally take.
Spam over Internet telephony, otherwise known as SPIT, can have far greater consequences than email spam. Spitters that target VoIP gateways can use up the available bandwidth, severely disrupting Quality of Service and causing a major degradation in voice quality.
The open nature of VoIP phone calls makes it easy for spitters to broadcast audio commercials just as email advertisements are broadcast. On closed networks like Vonage or Skype, or even your companies LAN, it is a little more difficult as the spitter would have to hack into the network in order to implement the broadcast. It can, however, be done.
The ability to broadcast audio messages over a VoIP network is not, in itself, necessarily a bad thing. Companies should be able to get out important messages quickly, and on a broader scope, emergency services could easily communicate mandatory evacuations, or warn of impending disasters in the event of catastrophe.
While Spit is certainly a technical possibility, to date, we have not seen a lot of it. In 2004, the peer to peer VoIP network Skype got hacked into, and users were inundated with unsolicited audio messages. Shortly thereafter, Skype had found and closed the loophole in the network. One other legal recourse is to get on the national Do Not Call list, to prevent solicitors from bombarding your voice mail box
Eavesdropping
Probably one of the scariest vulnerabilities of VoIP is the ability of an outsider to eavesdrop on a private conversation. This concept is nothing new to IP data networks, and generally requires a packet analyzer to intercept IP packets, and in the case of VoIP, saving the data as an audio file. Hackers then have the ability to learn user ids and passwords, or worse, to gain knowledge of confidential business information.
While it is true that eavesdropping occurs on traditional telephone lines as well as cellular networks, for someone to tap into your home phone line pretty much requires a physical presence outside your house. In the case of an IP network, a hacker requires only a laptop, some readily available software, and the knowledge of how to hack into your network.
Security analysts have long used encryption techniques to protect the confidentiality of data traveling through an IP network, and the same concept holds true for voice packets. The challenge with voice is to encrypt strongly and quickly, to protect confidentiality and as not to slow down the packet flow.
Nevertheless, if someone really wants to listen in on your calls, no type of telecommunication is 100% secure.
Phishing the Waters of Voice over IP
Another variation of an email attack, Phishing is designed to trick a user into revealing sensitive data such as user names, passwords, bank accounts, credit cards, and even social security numbers. In the case of VoIP, the attack could come as a voice mail message urging you to call a designated number and provide your user information. Even if the call is automated, touch tones can be easily deciphered. Depending on what information they get, hackers can use it to access bank accounts, or to steal identities.
While you can program a PBX to restrict call backs to known phishers, as more users become familiar with the pitfalls of the Internet, it becomes common knowledge to never give out sensitive information to automated media, be it via data or voice.
SIP Registration Hijacking
The Session Initiation Protocol (SIP) is becoming widely accepted as the method for setting up VoIP phone calls. The process involves a Registrar (in some cases the company PBX itself), which maintains a database of all users subscribed to the network, and basically maps their telephone number to an IP address.
Registration hijacking occurs when the packet header of either party is intercepted by a hacker, who substitutes his IP address for that of the legitimate one. Attacks can take the form of fraudulent toll free calls, denial of service attacks that can render the users device useless, or a simple diversion of communication.
Spoofing
Another hack that is well known in data networks is spoofing Also known as a man in the middle attack, spoofing requires hacking into a network and intercepting packets being sent between two parties. Once the IP address or phone number of the trusted host is discovered, hackers can use this attack to misdirect communications, modify data, or in the case of Caller ID Spoofing, transfer cash from a stolen credit card number.
SIP registration hijacking is a form of spoofing. Both of these spoofs, as well as other hacks such as eavesdropping, can be prevented by employing encryption techniques at the call set up phase. Today, the up and coming mechanism to achieve this is to send SIP messages over an encrypted Transport Layer Security channel. Putting these two protocols together forms the acronym SIPS.
There is no doubt that IP networks can be, and are, hacked into. Since a converged network consists of data and voice, VoIP is as vulnerable as any application to these disruptions, but with a downtime tolerance of no more than 5 minutes a year, such interruptions are considered intolerable for voice applications.
As of today, most of these security threats are not wide spread, and are presented here as a what could happen in the future scenario. Industry experts agree that as voice over Internet telephony becomes more wide spread, malicious hacking attempts are bound to follow.
These and other security threats can be prevented by a vigilant network staff, using all the known security precautions typical of an IP network. No VoIP solution is secure out of the box, and must be locked down by using common sense approaches, including but not limited to changing default passwords, closing down unused ports and services, utilizing firewalls and VPNs for network communications, and diligent intrusion detection.
- Related Videos
- Related Articles
- Ask / Related Q&A
- Is Wholesale VoIP a Secure Option?
- VoIP Pbx: Securing Its Position Among Latest Technologies
- Voip Security - How Secure Are your Calls?
- Encrypting Your VoIP Network for a Secure Connection
- Small Business VOIP - Ensure Business Safety While Using Wireless VoIP Signals
- VoIP Security Partnership Launched in the Usa
- Jajah and Lingo VoIP Phone Service: More Equal Than Other Telephony Services
- Minimize your Phone Bill With VoIP




Is VoIP really cheap?
By: Yukko | 01/12/2009Some details about cheap VoIP, Skype-out like services and other tricks to get money from the pockets of the clients
Issues with my Electronic Cigarette
By: Danilo Guzman | 01/12/2009I started using my e cigarette about two months ago and found it to be very helpful in stopping my nasty tobacco cigarette habit. I did stop smoking tobacco cigarettes after about five days with my new digital cigarette.
Advantages of VoIP PBX Telephone Systems for Small Offices
By: John Kinskey | 01/12/2009VoIP PBX phone systems are provided with highly advanced call management functions. VoIP phone systems are provided with highly advanced call management features.
Save Money with Cheap Call India Plans
By: Chris Jenkinson | 27/11/2009If you want to make a cheap call, India calling plans are abundantly available. Not all plans are equal but a great rate could be just a few clicks away.
Do You Know the Cheapest Call Pakistan Options?
By: Chris Jenkinson | 27/11/2009If you are looking for the cheapest call Pakistan options, it may take a bit of searching. Once you delve into the options, you’ll see that not all of them are equal.
Free VOIP Phone Calls with new VOIP Technology
By: Jack Daniels | 27/11/2009Most of the business communications are happening through VOIP and several organizations use VOIP services to communicate with their branches across the world. Families are able to get these services as well to get the cheapest VOIP calls and save money.
Your next Ventrilo Server Provider
By: Planetventrilo | 26/11/2009PlanetVentrilo is the number one Ventrilo Server Provider for Guilds and Gaming Clans around the world. with our years of experience managing ventrilo servers for the most demanding clients you can rest assured we have the knowledge and skills to make your hosting experience the best possible.
Ohio answering service keeps local shipping company in constant contact with clients
By: Gary Holthaus | 24/11/2009The past year’s recession has kept local businesses on their toes. An efficiency revolution is taking place across all industries as part of a push to be better prepared for similar economic woes if they occur again in the future.
Life Cycle of a Converged Network: Ongoing Operations and Network Optimization
By: Michael Talbert | 18/08/2008 | VoIPWhether you plan to use an MSP for ongoing operations, or you feel the IT staff is sufficiently trained to handle it in house, failure to have the proper management tools can evaporate your ROI through network outages and costly troubleshooting practices.
Pre-Deployment Testing and Implementation of a Converged Network
By: Michael Talbert | 08/11/2007 | VoIPAfter all the planning has been done and the network assessed, the conclusions drawn and assumptions made must be tested to assure that they are correct before moving on with the migration.
Rules of Deployment: Inventory of Assets and Existing Capabilities
By: Michael Talbert | 06/11/2007 | VoIPFailure to plan, test and assess for IP Telephony will surely result in a failed deployment marred with dropped calls, unacceptable call quality and connection times, and potential disruptions of your companies other critical business applications.
Rules of Deployment: The Life Cycle of a Converged Network
By: Michael Talbert | 06/11/2007 | VoIPA major shift in telecommunications from circuit to packet switched technology, along with increasing sophistication of the corporate LAN/WAN, is prompting businesses of all sizes to consider merging their voice and data networks. Increased bandwidth availability through gigabit Ethernet and fiber trunk lines allow for telephony to be treated as any other application on the IP network...
WiMax, VoIP, and the Metropolitan Area Network
By: Michael Talbert | 18/06/2007 | VoIPThe emerging IEEE 802.16 standard, commonly known as WiMAX, promises to deliver last mile wireless broadband internet access capable of carrying data intensive applications, such as VoIP and streaming video, to Metropolitan Area Networks, as well as sub-urban and rural communities.
WiMAX, VoIP, Killer Apps and the Digital Divide
By: Michael Talbert | 23/05/2007 | InternetThe emerging standard 802.16 defines a network of wireless broadband at speeds capable of delivering triple play access to voice, data, and multimedia internet services. As a disruptive technology, WiMAX stands to compete with cable companies, the Telcos, and the 3G cellular networks.
Road Trip to the Blue Ridge Mountains of North Carolina: Banner Elk and Grandfather Mountain
By: Michael Talbert | 23/05/2007 | TravelOne hot, sweltering day last summer in the flat lands of North Carolina, me and my biker buddy thought it was about time to plan for a weekend road trip...we decided to check out Banner Elk and the Grandfather Mountain area in the North Carolina Blue Ridge Mountains.
The FCC, TWC, Skype, and the Cellular Industry
By: Michael Talbert | 22/03/2007 | VoIPIf it is truly the mission of the FCC to foster competition, new technology, and to protect consumer rights as the TWC decision implies, then there is a golden opportunity for them to do just that.