Thank you for Subscribing to Telecom Business Review Weekly Brief
Telecom Business Review | Tuesday, October 04, 2022
The hour requirement is a proactive approach to detect and nip the vulnerabilities and risks of a service provider in the bud.
FREMONT, CA: With the conversion from telecom operators to digital service providers, the communication procedure and the essential protocols have changed over the years. The digital details are packetized, wherein the transmission occurs over IP packets instead of the earlier circuit-switched transmission.
Currently, VoIP technology has overshadowed conventional communication technologies, which are comprehensible due to its edge in terms of accessibility, scalability, voice quality, portability, flexibility & lower costs.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
While several protocols are utilized in voice-over-IP (VoIP) communications, Session Initiation Protocol (SIP) has become the most popular. This is because there are different benefits that it brings in for a service provider, which include lower costs, immediate ROI, global potential, mobility & network consolidation.
With the immense advantages it brings to businesses, certain risks are also associated with it. Security is one such issue of paramount importance to the service providers and their customers, as it relates to direct and indirect attacks by fraudsters and cybercriminals, causing financial losses and customer churn for the service providers.
SIP has turned even more widespread due to enterprise customers placing more SIP endpoints outside the confines of a logical network. An interesting statistic indicates the importance of VoIP security-roughly 46% of illegally made calls across the world involve VoIP technology. Furthermore, as much as 65% of the global DDoS attacks in 2018 were aimed at communication service providers.
Additionally, there has been a strong rise in cyber-fraud operations targeting VoIP phone systems worldwide. What’s even more worrying is that hackers worldwide generate their own social media groups to share tips and know-how relating to VoIP phone system hacking and organize and coordinate future attacks.
Although most telecom networks are still private, since they also provide SIP trunks to smaller carriers or enterprises, they expose some parts of their network to a public network and thus become vulnerable to attacks.
Interconnect using SIP exposes telecom networks to attacks as the network is laid down for immediate partners and may be private and secure. Still, if the partner’s network is exposed to a public network, it links the telecom’s network to the public network via other carriers.
Also, an international call passes through many networks before it’s terminated at the destination. Every carrier may not have the maximum level of security. Thus, such calls are vulnerable to eavesdropping and hi-jacking. As a result, SIP is vulnerable to a range of attacks, and more importantly, the attackers utilize them to initiate direct or indirect losses to service providers.
The hour requirement is a proactive approach to detect and nip the vulnerabilities and risks of a service provider in the bud.
In the conventional approaches, their reactive approach is inadequate and unsatisfactory for the fraud & security strategy of the service providers. This is due to the reliance on xDRs and the lack of timely availability of real-time threat intelligence.
Still, we believe the way forward is to have a system that uses real-time signalling level analysis, complete with advanced machine learning techniques. And real-time threat intelligence will offer new opportunities to drive a prevention-based way and support operators more effectively in addressing these types of threats.
More in News