Voice-over-IP — Security

Voice-over-IP — Security

Security in the Internet

Due to the progressing broad use of the Internet in private, commercial and business environments new threads arise nearly every day. Viruses, Internet worms and other malware threaten single PCs as well as complete local or enterprise networks. Targeted attacks on servers menace enterprises at their modern basis, their IT infrastructure. Even if the defence against these threads often seems impossible to hold, the fight is already lost if no adequate defence technologies are used.

Like buildings are certainly secured against unwanted access with doors and often advanced security mechanisms and procedures; an enterprise network has to be secured against intruders from the Internet. Data connections over the Internet must use strong encryption to protect sensitive or confidential data. For business use, nearly all data can be classified like this.

Security and VoIP

With the appearance of Internet telephony new threads arise. Certainly the traditional telephone system has its weaknesses; analogue lines and even ISDN lines can easily be wiretapped, manipulated or destroyed, but attacks to that network need physical presence of the attacker.

With Internet telephony the situation is different: While the worldwide Internet opens new possibilities and chances; it appears like Pandora's box from the security's point of view. A voice over IP device in a German city can easily be attacked by crackers from Brazil, Korea, China or South Africa. Obviously geographic distance is no defence in the Internet, apart from the fact that it is nearly impossible to use jurisdiction to satisfy your rights.

Threads to Internet telephone systems are manifold: Denial-of-service attacks can disrupt the service and even interrupt ongoing calls, connections can be hijacked or wiretapped, service provider accounts can be abused and privacy of the user can be breached with unsolicited calls.

Combination of VoIP and Firewall

Given the findings so far, the securing of Internet access should not only cover the computer network but also protect Internet telephony. Voice connections over the Internet should be always encrypted and authenticated like data connections. Regrettably, many VoIP service provider do not offer a secure service yet and many firewalls block VoIP traffic completely. So building a secure solution currently is not an easy task.

The netea smartway series combines a secure Internet router with VPN capabilities, a firewall and a VoIP exchange in one device. This unique combination allows the firewall to track VoIP connections rather than blocking them. Modern and efficient encryption technology allows secure connections for data (VPN) and for voice calls (SIP with TLS, SRTP) for interconnections with other netea smartway devices or selected VoIP service provider offering a secure service.