Thank you for Subscribing to Telecom Business Review Weekly Brief
Telecom Business Review | Tuesday, June 01, 2021
Legacy on-premises systems require physical access for hacking, whereas VoIP devices and networks can be negotiated remotely.
Fremont, CA: Seamless scaling, lower implementation costs, and the rising demand among end customers make Voice over IP (VoIP) services an appealing new business avenue for telecoms. As much as that by 2025, the global VoIP industry is awaited to reach $55 billion.
While the advantages of VoIP adoption are certainly attractive, they are somewhat offset by the increased cybersecurity risks this new technology poses. Legacy on-premises systems require physical access for hacking, whereas VoIP devices and networks can be negotiated remotely.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
The lack of standardization among IP phone manufacturers and PBX device providers has made protecting individual systems harder for businesses. For telecom providers, the security issues of VoIP are further magnified by the over-reliance on two dominating VoIP protocols – Session Initiation Protocol(SIP) and Skinny Client Control Protocol(SCCP).
The General Types of VoIP Attacks To Beware of
VoIP technology is as strong and secure as traditional telephony and is arguably more secure than a traditional cellular connection. However, every network must be properly configured and reinforced to be fully hacker-proof.
Most VoIP cyber attacks initiate from the fact that administrators fail to put appropriate protective measures in place:
• Establish isolated VoIP networks with open physical access, weak VPNs, or MPLS.
• Over-dependence on automation tools for setting the defense perimeter, and hence, miss certain vulnerabilities.
• Fail to set proper protection facing network-based attacks such as DOS, DDoS, phishing, surveillance and spying, and VAS services abuses.
• Failing to configure the VoIP devices properly relies on weak passwords, legacy software, and vulnerable leverage protocols.
The above often causes the following VoIP security attacks, particularly SIP hacking. After all, SIP servers are located in the heart of both internal IP telephony and commercial services, as pictured:
DDoS – SIP Amplification Attack
SIP hacking rests on one of the most pervasive security threats in the telecom field as this protocol has evolved to be commonly used in VoIP systems. A SIP amplification attack generally assumes the following scenario:
A hacker stages a pile application layer attack on the SIP protocol using DDoS, targeting to destabilize the system. For example, the attacker may compromise the SIP servers to send multiple (10+) errors to transmit IP Spoofed packets and several Responses to the victim.
Hacking SIP Trust Relationships
SIP gateways use SIP Trunks for trusted call initiation and CDR/invoice management, which makes them appealing targets for VoIP attacks. Anyway, SIP trunks often have no passwords or IP-based filters utilized for trunk authentication. Most SIP trunks have Direct INVITE privilege without REGISTER, again turning a good avenue for attacks.
A normal SIP trust relationship hack will entail the following steps:
• A hacker locates Trusted SIP Networks;
• They transmit IP Spoofed Requests from each combination IP: Port;
• Specifically, they’ll target calls that hold IP: Port in the “From” section;
• Once they take a call, they’ll capture the Trusted SIP Gateway IP and Port and utilize it to initiate unauthorized calls.
Spoofing Caller ID
Caller ID doesn’t have sufficient protection in SIP, and hackers have plenty of tools for varying the SIP INVITE Request Message from the header to carry out the spoof. In particular, this is a common way of voice fraud used to compromise PBX systems. Thus, to avoid roaming fraud or call hijacking, you must also protect that endpoint.
More in News