SlideShare a Scribd company logo
Securing Communications!
SpeechTEK New York 2010!
Dan York, CISSP

   Director of Conversations, Voxeo

   Best Practices Chair, VoIP Security Alliance

   Author, Seven Deadliest UC Attacks!
About Dan York!



                                               www.voipsa.org
                         www.voxeo.com




                      www.blueboxpodcast.com     www.7ducattacks.com


© Voxeo Corporation
About Voxeo!

        Founded in 1999
        World’s largest hosted VoiceXML and CCXML platform – Over
         82,000 hosted ports globally; hundreds of premise deployments
        Over 150,000 developers using Voxeo platforms
        The Voxeo difference: Unlocked Communications, Customer
         Obsession Teams, Communications Passion
        www.voxeo.com




© Voxeo Corporation
The Change VoIP Brings!



                                 SIP              SIP
                                Proxy            Proxy
                                  A      SIP       B

                          SIP                             SIP




                      Alice                                Bob
                                Media (RTP, MSRP, etc.)




© Voxeo Corporation
The Larger Reality!



                      SIP           SIP             SIP             SIP         SIP
                      Proxy         Proxy           Proxy         Proxy         Proxy
                       A      SIP    B      SIP      C      SIP     D     SIP    N

          SIP                               Internet                                    SIP



                                    Media                   Media
  Alice                             Proxy                   Proxy                        Bob
                      Media           A           Media       B             Media




© Voxeo Corporation
Once Upon A Time!




                                   PSTN
                        PBX
                                  Gateways




                                  Physical
                      Voicemail
                                   Wiring




© Voxeo Corporation
1. Understand Your Ecosystem!

                                                         Mobile
                                                         Devices
                           IM                                                                 Application
                                                                       Internet                Servers
                        Networks
                                             Operating
                                             Systems
                                                            PSTN
                                  IP-PBX                                            VoIP
                                                           Gateways


                         Web                  IP                                               Social
                                                                      Firewalls
                        Servers             Network                                           Networks


                                                           Physical               Directory
                                Voicemail
                                                            Wiring                Servers

                                            Desktop
                       Email                 PCs                                           Database
                      Servers                                       CRM                     Servers
                                                                   Systems




© Voxeo Corporation
2. Understand Your Endpoints!

        IP Phones, Smartphones, Softphones

        What services are running on them?

        Default passwords?

        How do you patch/secure them?




© Voxeo Corporation
3. Secure Your Media!


                             SIP           SIP                   SIP
                            Proxy         Proxy                 Proxy
                              A     SIP     B     SIP             N

                      SIP                                               SIP




           Alice                          Eve                            Bob
                            Media                       Media




© Voxeo Corporation
Secure Media – Hop By Hop!



                                      Internet


                              Media              Media
Alice                         Proxy              Proxy           Bob
                      Media     A      Media       B     Media




© Voxeo Corporation
Secure Media – End to End!



                                      Internet


                              Media              Media
Alice                         Proxy              Proxy           Bob
                      Media     A      Media       B     Media




© Voxeo Corporation
4. Secure Your Signalling!



                       SIP           SIP                         SIP
                      Proxy         Proxy           Eve         Proxy
                        A     SIP     B     SIP           SIP     N

              SIP                                                       SIP




      Alice                                                              Bob
                                            Media




© Voxeo Corporation
Signalling Attacks!

        Toll Fraud

        Identity Theft




© Voxeo Corporation
Traditional Telephony!



                                       Internet




                                                  Carrier   PSTN
                          PBX




                      Corp	
  HQ	
  




© Voxeo Corporation
IP Communications!



                                     ITSP



                          Internet
              PBX

                                            PSTN

         Corp	
  HQ	
  




© Voxeo Corporation
Failover!



             PBX
                                    ITSP


        Corp	
  HQ	
  
                         Internet          PSTN



              PBX



           Office	
  
            A	
  



© Voxeo Corporation
Redundancy / Geography!

                                   ITSP
                                   (Boston)




                        Internet
            PBX                    ITSP
                                   (Paris)
                                              PSTN

       Corp	
  HQ	
  



                                   ITSP
                                   (Tokyo)




© Voxeo Corporation
5. Secure Your PSTN Connectivity!

        Attacks
          •  Toll Fraud
          •  Denial of Service
          •  Spam

        Solutions
          •  Encryption
          •  Strong Authentication
          •  Transport Security



© Voxeo Corporation
6. Secure Your Identity!

        Attacks
          •  Fraud
          •  Identity Theft
          •  Social Engineering

        Solutions
          •  Education
          •  Lock Down Spoofing
          •  Strong Identity



© Voxeo Corporation
7. Secure Distributed Systems!


                                                                     Laptop
                                                                       UC
                                                                      client
                                                        WiFi
                   UC
                 System
                               Firewall   Internet      Café
                                                       Router



              Corp	
  HQ	
  
                                             Mobile
                                              Data
                                             Network        Mobile
                                                             UC
                                                            client




© Voxeo Corporation
How Do You Securely Federate?!

                                                       Internet




                          Corporate                                        Corporate
                           Network                                          Network



                        UC                UC                          UC                  UC
                      System            System                      System              System



                Corp	
  HQ	
           Office	
  A	
                Corp	
  HQ	
         Office	
  A	
  

                           Company	
  A	
                                  Company	
  B	
  

© Voxeo Corporation
What if the Cloud Isnʼt There?!

                        Corporate
                                                               Internet
                         Network


                                                         IVR              Voicemail
              IM              IM              IM

          Presence        Presence        Presence

             Call            Call            Call
            Control         Control         Control




       Corp	
  HQ	
      Office	
  A	
     Office	
  B	
  




                         PSTN


© Voxeo Corporation
Questions About the Cloud!

        What kind of availability guarantees / Service Level Agreements (SLAs)
         does the platform vendor provide?

        What kind of geographic redundancy is built into the underlying
         network?

        What kind of network redundancy is built into the underlying network?

          What kind of physical redundancy is built into the data centers?

        What kind of monitoring does the vendor perform?

        What kind of scalability is in the cloud computing platform?

        What kind of security, both network and physical, is part of the
         computing platform?

        Finally, what will the vendor do if there is downtime? Will the downtime
         be reflected in your bill?

© Voxeo Corporation
The Way It Used To Be!




© Voxeo Corporation
Today...!                                                                ITSP
                                                                                         ITSP
                                                                                                        ITSP
                                                          ITSP
                                  ITSP

                                                                                            ITSP

                                                                                                                ITSP
                    ITSP
                                                       ITSP
                                                                          ITSP              ITSP
                                         ITSP
                                                                                                           ITSP



            ITSP                                       PSTN                       ITSP
                                     ITSP

            ITSP
                                                                                                 ITSP
                                                   ITSP            ITSP
                           ITSP

ITSP
                                                                                          ITSP
                                                                                                         ITSP

            ITSP                  ITSP      ITSP                        ITSP



                                                                                         ITSP       ITSP
ITSP                    ITSP                    ITSP             ITSP          ITSP
  © Voxeo Corporation
Resources!

        VoIP Security Alliance
          •  www.voipsa.org
          •  www.voipsa.org/blog


        Hacking Exposed: VoIP
          •  www.hackingvoip.com


        Seven Deadliest Unified Communications
         Attacks
          •  www.7ducattacks.com

© Voxeo Corporation
Securing Unified Communications Systems

More Related Content

PDF
07 a t kishore.pdf
PDF
Scenarios for-context-aware-sip-07-a t kishore.pdf
PDF
10 fn s15
PPTX
Mobile 2 Internet
PDF
Watch out - The Norwegian Version
PDF
Securing Communications - VoiceCon Orlando 2010
PDF
10 fn s14
PPTX
VOIP Presentation
07 a t kishore.pdf
Scenarios for-context-aware-sip-07-a t kishore.pdf
10 fn s15
Mobile 2 Internet
Watch out - The Norwegian Version
Securing Communications - VoiceCon Orlando 2010
10 fn s14
VOIP Presentation

What's hot (19)

PPTX
Luxemburg event - airtight networks
PPTX
WinWire Webinar: Messaging and Networking with Windows Azure
PDF
Wireless lan solutions_for_education
PDF
Video the new voice
PDF
Network Storage: State of the Industry
PDF
Meet Xo Core Presentation 2011
PDF
Siemens: The Evolution of Corporate Communications
PDF
Disruptive Analysis LTE Summit 2011 voice presentation may 2011
PDF
VOIspeed Presentation
PDF
Traffic Management, DPI, Internet Offload Gateway
PDF
How to Optimize VoIP Call Quality Across Multiple Calling Environments
PDF
fonYou UTR Presentation 19-Nov-2009
PDF
Katina Leisure Mobile 2010
DOCX
PDF
VoIP and You - 2011
PPTX
NGN voice corporate seminar
PDF
4th Generation IP for Mobility, Video and Cloud
PDF
Driving true convergence in metro networks a
PDF
Luxemburg event - airtight networks
WinWire Webinar: Messaging and Networking with Windows Azure
Wireless lan solutions_for_education
Video the new voice
Network Storage: State of the Industry
Meet Xo Core Presentation 2011
Siemens: The Evolution of Corporate Communications
Disruptive Analysis LTE Summit 2011 voice presentation may 2011
VOIspeed Presentation
Traffic Management, DPI, Internet Offload Gateway
How to Optimize VoIP Call Quality Across Multiple Calling Environments
fonYou UTR Presentation 19-Nov-2009
Katina Leisure Mobile 2010
VoIP and You - 2011
NGN voice corporate seminar
4th Generation IP for Mobility, Video and Cloud
Driving true convergence in metro networks a
Ad

Viewers also liked (7)

PPTX
#online tuesday The Floor is Yours: Peter doesburg
PPTX
Presentatie webcare robert lommers 8 maart
PDF
20100504 opta jaarverslag 2009 interactief nl
KEY
Sinsai.info - Global ICT Summit
PPT
Presentatie Agis Loyalty Facts Café sept. 2010
PPTX
Presentatie webcare alex van leeuwen buzz capture 8 maart
PPTX
Presentatie webcare tjalling smit klm 8 maart definitief
#online tuesday The Floor is Yours: Peter doesburg
Presentatie webcare robert lommers 8 maart
20100504 opta jaarverslag 2009 interactief nl
Sinsai.info - Global ICT Summit
Presentatie Agis Loyalty Facts Café sept. 2010
Presentatie webcare alex van leeuwen buzz capture 8 maart
Presentatie webcare tjalling smit klm 8 maart definitief
Ad

Similar to Securing Unified Communications Systems (20)

PDF
3. FOMS_ IMS services_Shane_Dempsey
PDF
IPv6 and How It Impacts Communication Applications
PPT
Mitel BPC
PDF
Hacking and Attacking VoIP Systems - What You Need To Know
PDF
SIP Trunking & Security in an Enterprise Network
PPTX
Mwc wip jam jabber sdk final
PDF
How IPv6 Will Kill Telecom - And What We Need To Do About It
PDF
Mobivox Company Overview
PDF
COLLABORATION
PDF
IP communications to billions of people coming soon to a web broswer near y...
PPT
Gaurav kumar VOIP MMMEC
PPTX
Skypepresentation
PDF
SpeechTEK 2009: Securing Cloud Telephony Aug2009
PDF
I N T E R O P09 Suhas Desai Secure Your Vo I P Network With Open Source
PDF
PDF
PPTX
Mobility and SmartTAP Recording for Lync
PDF
Open Source Telephony Disruptive Solutions
PPTX
Avaya sipwithinyourenterprise-090629022848-phpapp02
PPTX
Avaya sipwithinyourenterprise-090629022848-phpapp02
3. FOMS_ IMS services_Shane_Dempsey
IPv6 and How It Impacts Communication Applications
Mitel BPC
Hacking and Attacking VoIP Systems - What You Need To Know
SIP Trunking & Security in an Enterprise Network
Mwc wip jam jabber sdk final
How IPv6 Will Kill Telecom - And What We Need To Do About It
Mobivox Company Overview
COLLABORATION
IP communications to billions of people coming soon to a web broswer near y...
Gaurav kumar VOIP MMMEC
Skypepresentation
SpeechTEK 2009: Securing Cloud Telephony Aug2009
I N T E R O P09 Suhas Desai Secure Your Vo I P Network With Open Source
Mobility and SmartTAP Recording for Lync
Open Source Telephony Disruptive Solutions
Avaya sipwithinyourenterprise-090629022848-phpapp02
Avaya sipwithinyourenterprise-090629022848-phpapp02

More from Voxeo Corp (20)

PDF
Voxeo Summit Day 2 -What's new in CXP 14
PDF
Voxeo Summit Day 2 -Voxeo APIs and SDKs
PPTX
Voxeo Summit Day 2 - Voxeo CXP - IVR on Steroids
PPTX
Voxeo Summit Day 2 - Using CXP hotspot analytics
PPTX
Voxeo Summit Day 2 - Securing customer interactions
PPTX
Voxeo Summit Day 2 - Real-time communications with WebRTC
PPTX
Voxeo Summit Day 2 - Voxeo CXP for business users
PPTX
Voxeo Summit Day 2 - Creating raving fans
PPTX
Voxeo Summit Day 2 - Advanced CCXML topics
PPTX
Voxeo Summit Day 2 - The science of customer obsession
PDF
Voxeo Summit Day 1 - Extending your IVR investment to mobile
PPTX
Voxeo Summit Day 1 - The Art of The Possible
PPTX
Voxeo Summit Day 1 - Prophecy log search
PPTX
Voxeo Summit Day 1 - Customer experience analytics
PPTX
Voxeo Summit Day 1 - Communications-enabled Business Processes (CEBP)
PPTX
Voxeo Summit Day 1 - A view into the Voxeo cloud
PPTX
Voxeo Summit Day 1 - Lessons learned from large scale deployments
PDF
Voxeo Jam Session: What's New in Prophecy 11 and VoiceObjects 11?
PPTX
How Do You Hear Me Now?
PPTX
CCXML For Advanced Communications Applications
Voxeo Summit Day 2 -What's new in CXP 14
Voxeo Summit Day 2 -Voxeo APIs and SDKs
Voxeo Summit Day 2 - Voxeo CXP - IVR on Steroids
Voxeo Summit Day 2 - Using CXP hotspot analytics
Voxeo Summit Day 2 - Securing customer interactions
Voxeo Summit Day 2 - Real-time communications with WebRTC
Voxeo Summit Day 2 - Voxeo CXP for business users
Voxeo Summit Day 2 - Creating raving fans
Voxeo Summit Day 2 - Advanced CCXML topics
Voxeo Summit Day 2 - The science of customer obsession
Voxeo Summit Day 1 - Extending your IVR investment to mobile
Voxeo Summit Day 1 - The Art of The Possible
Voxeo Summit Day 1 - Prophecy log search
Voxeo Summit Day 1 - Customer experience analytics
Voxeo Summit Day 1 - Communications-enabled Business Processes (CEBP)
Voxeo Summit Day 1 - A view into the Voxeo cloud
Voxeo Summit Day 1 - Lessons learned from large scale deployments
Voxeo Jam Session: What's New in Prophecy 11 and VoiceObjects 11?
How Do You Hear Me Now?
CCXML For Advanced Communications Applications

Recently uploaded (20)

PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PPT
Teaching material agriculture food technology
PPTX
Spectroscopy.pptx food analysis technology
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
Machine learning based COVID-19 study performance prediction
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PPTX
SOPHOS-XG Firewall Administrator PPT.pptx
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Approach and Philosophy of On baking technology
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
“AI and Expert System Decision Support & Business Intelligence Systems”
Teaching material agriculture food technology
Spectroscopy.pptx food analysis technology
Dropbox Q2 2025 Financial Results & Investor Presentation
Machine learning based COVID-19 study performance prediction
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Mobile App Security Testing_ A Comprehensive Guide.pdf
Building Integrated photovoltaic BIPV_UPV.pdf
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
SOPHOS-XG Firewall Administrator PPT.pptx
The Rise and Fall of 3GPP – Time for a Sabbatical?
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Network Security Unit 5.pdf for BCA BBA.
MIND Revenue Release Quarter 2 2025 Press Release
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Approach and Philosophy of On baking technology
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...

Securing Unified Communications Systems

  • 1. Securing Communications! SpeechTEK New York 2010! Dan York, CISSP
 Director of Conversations, Voxeo
 Best Practices Chair, VoIP Security Alliance
 Author, Seven Deadliest UC Attacks!
  • 2. About Dan York! www.voipsa.org www.voxeo.com www.blueboxpodcast.com www.7ducattacks.com © Voxeo Corporation
  • 3. About Voxeo!   Founded in 1999   World’s largest hosted VoiceXML and CCXML platform – Over 82,000 hosted ports globally; hundreds of premise deployments   Over 150,000 developers using Voxeo platforms   The Voxeo difference: Unlocked Communications, Customer Obsession Teams, Communications Passion   www.voxeo.com © Voxeo Corporation
  • 4. The Change VoIP Brings! SIP SIP Proxy Proxy A SIP B SIP SIP Alice Bob Media (RTP, MSRP, etc.) © Voxeo Corporation
  • 5. The Larger Reality! SIP SIP SIP SIP SIP Proxy Proxy Proxy Proxy Proxy A SIP B SIP C SIP D SIP N SIP Internet SIP Media Media Alice Proxy Proxy Bob Media A Media B Media © Voxeo Corporation
  • 6. Once Upon A Time! PSTN PBX Gateways Physical Voicemail Wiring © Voxeo Corporation
  • 7. 1. Understand Your Ecosystem! Mobile Devices IM Application Internet Servers Networks Operating Systems PSTN IP-PBX VoIP Gateways Web IP Social Firewalls Servers Network Networks Physical Directory Voicemail Wiring Servers Desktop Email PCs Database Servers CRM Servers Systems © Voxeo Corporation
  • 8. 2. Understand Your Endpoints!   IP Phones, Smartphones, Softphones   What services are running on them?   Default passwords?   How do you patch/secure them? © Voxeo Corporation
  • 9. 3. Secure Your Media! SIP SIP SIP Proxy Proxy Proxy A SIP B SIP N SIP SIP Alice Eve Bob Media Media © Voxeo Corporation
  • 10. Secure Media – Hop By Hop! Internet Media Media Alice Proxy Proxy Bob Media A Media B Media © Voxeo Corporation
  • 11. Secure Media – End to End! Internet Media Media Alice Proxy Proxy Bob Media A Media B Media © Voxeo Corporation
  • 12. 4. Secure Your Signalling! SIP SIP SIP Proxy Proxy Eve Proxy A SIP B SIP SIP N SIP SIP Alice Bob Media © Voxeo Corporation
  • 13. Signalling Attacks!   Toll Fraud   Identity Theft © Voxeo Corporation
  • 14. Traditional Telephony! Internet Carrier PSTN PBX Corp  HQ   © Voxeo Corporation
  • 15. IP Communications! ITSP Internet PBX PSTN Corp  HQ   © Voxeo Corporation
  • 16. Failover! PBX ITSP Corp  HQ   Internet PSTN PBX Office   A   © Voxeo Corporation
  • 17. Redundancy / Geography! ITSP (Boston) Internet PBX ITSP (Paris) PSTN Corp  HQ   ITSP (Tokyo) © Voxeo Corporation
  • 18. 5. Secure Your PSTN Connectivity!   Attacks •  Toll Fraud •  Denial of Service •  Spam   Solutions •  Encryption •  Strong Authentication •  Transport Security © Voxeo Corporation
  • 19. 6. Secure Your Identity!   Attacks •  Fraud •  Identity Theft •  Social Engineering   Solutions •  Education •  Lock Down Spoofing •  Strong Identity © Voxeo Corporation
  • 20. 7. Secure Distributed Systems! Laptop UC client WiFi UC System Firewall Internet Café Router Corp  HQ   Mobile Data Network Mobile UC client © Voxeo Corporation
  • 21. How Do You Securely Federate?! Internet Corporate Corporate Network Network UC UC UC UC System System System System Corp  HQ   Office  A   Corp  HQ   Office  A   Company  A   Company  B   © Voxeo Corporation
  • 22. What if the Cloud Isnʼt There?! Corporate Internet Network IVR Voicemail IM IM IM Presence Presence Presence Call Call Call Control Control Control Corp  HQ   Office  A   Office  B   PSTN © Voxeo Corporation
  • 23. Questions About the Cloud!   What kind of availability guarantees / Service Level Agreements (SLAs) does the platform vendor provide?   What kind of geographic redundancy is built into the underlying network?   What kind of network redundancy is built into the underlying network?   What kind of physical redundancy is built into the data centers?   What kind of monitoring does the vendor perform?   What kind of scalability is in the cloud computing platform?   What kind of security, both network and physical, is part of the computing platform?   Finally, what will the vendor do if there is downtime? Will the downtime be reflected in your bill? © Voxeo Corporation
  • 24. The Way It Used To Be! © Voxeo Corporation
  • 25. Today...! ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP PSTN ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP © Voxeo Corporation
  • 26. Resources!   VoIP Security Alliance •  www.voipsa.org •  www.voipsa.org/blog   Hacking Exposed: VoIP •  www.hackingvoip.com   Seven Deadliest Unified Communications Attacks •  www.7ducattacks.com © Voxeo Corporation