VoIP Scams, Phishing, And Denial Of Service Attacks and What You Can Do
VoIP-News is running a nice little informative piece discussing some of the general voip security issues that exist and some basic solutions people can take to minimize their exposure. Below is an excerpt from the article:
"While enterprise VoIP offers many cost, efficiency and productivity benefits, it also opens the door to external threats. That's because VoIP is, at its heart, a data networking technology, making it a prime target for hackers, data thieves and other types of online troublemakers."
The Threat: Denial of Service (DoS) Attacks
The Problem: DoS attacks pose perhaps the greatest threat to enterprise VoIP systems. In fact, VoIP applications provide excellent cover for launching DoS attacks because VoIP runs continuous media over IP packets. To create mayhem, hackers only have to keep multiple packet streams running and running and running and running.
Worse yet, the ability to dial in and out of VoIP overlays allows the control of applications via a voice network, making it nearly impossible to trace an attack's source. Additionally, proprietary protocols, used by a number of VoIP applications, inhibit the ability of ISPs to track DoS activity.
The Solution: Any VoIP network can be targeted for a DoS attack. Preventative measures include strengthening authentication safeguards, removing unnecessary network services, avoiding link ups with unauthenticated components and using strong firewalls. All of this may not stop a mass DoS attack, but it will give your system a fighting chance at survival.

blinklist
BoingBoing
del.icio.us
digg
furl
shadows
simpy
Slashdot
spurl
yahoo