Thank you for Subscribing to Telecom Business Review Weekly Brief
Telecom Business Review | Monday, August 22, 2022
The key is being diligent and systematic regarding endpoint protection and proactive regarding network security audits and testing.
FREMONT, CA: Reducing attacks in VoIP environments requires a systematic approach. First, build your protection from the bottom up, beginning with IP phones and ending with comprehensive network security testing & occasional penetration tests.
IP Phones Protection
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
IP phones offer a physical pathway to deeper network penetration. Do not undervalue the importance of basic precautions, like:
• Protection against unauthorized usage and calls.
• Mandatory utilization of extra security codes when dialing international or toll numbers.
• Accession to regularly updated security codes for regular usage.
• Execution of geo-fencing for general users.
• Regular firmware updates on every phone.
On a network level, you should also think about implementing the respective solutions against VoIP attacks:
• Voice packet encryption to/from any VoIP phone. You can structure your device to add SIPS instead of SIP at the start of the address by default to auto-execute call encryption through Transport Layer Security (TLS). Instead, you can think of setting up a virtual private network (VPN) or virtual LAN (VLAN) to defend your connection further.
• Segregate voice on a separate voice VLAN. Doing so can support you further protect all the voice traffic.
• Set up a SIP-capable firewall to sift using message contents, capture malware, and other types of spoofing.
• Constantly evaluate your VLAN configuration, user authentication mechanisms, and the security of configuring and signaling methods. As you do so, verify that you comply with HIPAA, SOX, or PCI recommendations if those are implemented for you.
IP PBXs Security
Most IP PBXs depend on Linux-based or Windows-based servers that can be hacked into by a malicious party unless there are definite precautions. Particularly, you’ll need to ensure that:
• Your servers have installed the latest antivirus, firewalls, and malware protection software.
• Regular data backups are configured.
Some IP PBXs systems may depend on router-type appliances, other than servers, that should also be hardened following these best practices:
• Apply strong passwords.
• Allow encrypted management communication.
• Make access lists for blocking malicious IP address ranges and Transport Layer ports.
• Repeal access to any services that are not in regular use.
SIP Trunks Safeguarding
SIP trunks can be a frail security link for hacking, as voice packets can be overpowering as they travel between two SIP endpoints. To defend that connection, look beyond the standard hashed password encryption. Some of the essential measures to consider are as follows:
• Verify that encryption is used for both the voice portion of the communication and the SIP signaling and control packets.
• Curb the number of devices that can institute contact with your SIP trunk.
• Fix a secure protocol and session validity that cover SIP port settings, SIP protocol inspection and termination, registration, and authentication methods.
• Implement privacy control mechanisms for every SIP trunk session. Appropriately configure SIP privacy headers, allow SIP normalization, protect against digit manipulation, and add additional encryption methods for the indicating and the media streams, like TLS, IPSec tunnel, or VPNs on the IP connections.
Regular Network Testing
Lastly, conduct regular security audits and tests of your VoIP systems. We recommend employing the SIPVicious OSS toolkit for SIP audits and the Viproy penetration testing kit, designed especially for VoIP systems. You can also explore the novel generation of AI-based network security and monitoring solutions emerging on the market.
Being proactive regarding your network security is worth manifolds as you deal with potential vulnerabilities beforehand instead of throwing emergency resources into handling the complex (and costly) aftermath of compromised VoIP devices or part of your network.
More in News