Hype vs. Reality in VoIP Security
Gartner research director Lawrence Orans believes that some of the security threats associated with voice over IP (VoIP) are exaggerated and will never really be that great a danger. Orans says VoIP is just another application running over a network and vulnerable to attacks that can cause problems on other parts of the network, but the hyped-up threats such as eavesdropping and VoIP spam are not truly great dangers. However, consultant Frank Dzubeck argues that VoIP is lacking built-in security and that opens up the possibility for all types of attacks. Dzubeck believes eavesdropping is over-hyped but still a security threat, and suggests encrypting voice calls inside the local area network. Dzubeck and Orans agree that VoIP spam, also known as SPIT, will be minimal because of the legal precedent of the Do Not Call lists, and that it will not be as effective as email spam. Both Dzubeck and Orans acknowledge the threats against IP PBX servers and IP telephony handsets, and caution that threats down the line may include attacks against the server and massive denial-of-service attacks.
© Copyright 2007 INFORMATION, INC.


