Showing posts with label SIP Security. Show all posts
Showing posts with label SIP Security. Show all posts

Thursday, May 16, 2019

Switching to SIP? Four Facts to Check When Switching to SIP

Image result for SIP Trunk
SIP Trunking

SIP Communication in the business sector is getting traction as the businesses realize they can save a packet, sometimes up to 70% from traditional phone communications costs, by switching to SIP. So the SIP trunking is too gaining attraction to fill the technical needs of SIP communications.
SIP is traditionally a simple calling protocol yet there are some things to watch out when making the switch. Sangoma gives us Four most important and how to tackle them,

SIP Needs Security

Since SIP is in plain text, it doesn’t take an IT genius to decipher a SIP session (call). Without the proper security measures, anyone can run a packet capture tool (such as Wireshark) and extract audio from calls.

The good news is that this is an easy problem to solve with Secure Real-Time Transport protocol (SRTP) and a Session Border Controller (SBC), which is basically an application-layer firewall designed for SIP.

Make SIP (a) Priority

Between the media streaming and file sharing, chances are you have a lot of traffic on your network. If you implement SIP trunking on top of that without preparation, you may have delays in video buffering, slow email send speeds, or decreased audio quality on your VoIP calls.

To avoid this, make sure you utilize the standard QoS feature found in most business-grade routers and switches. The QoS feature will ensure your voice calls receive priority on the network, ensuring the available bandwidth is delivered straight to them first before less important network traffic.
Prior to SIP, Know Your Network

When switching to SIP, it’s important to have an accurate idea of how many concurrent calls your business makes. Review your call logs and understand the total number of calls your business makes, as well as how many concurrent calls are made at your busiest times.

SIP Bandwidth Needs 


The second thing to understand about your network is that SIP depends on bandwidth, and a lack of it can cause poor audio, dropped calls, and busy signals. Luckily, bandwidth is cheap and usually readily available!

Make sure you have enough to support the maximum number of concurrent calls your business requires. (To calculate the necessary bandwidth, simply multiply the maximum number of concurrent calls by Number of max concurrent calls x 100kb/sec = average bandwidth per call needed.) Simply add the bandwidth required to the amount you already use for business duties, and you should be good to go.

If You Fax Over SIP, Be Smart.

Faxing over IP can be very messy, particularly when it comes to the T.38 fax limitation. In very simple terms, a fax message cannot be compressed in the same manner as a voice packet. Packet loss with a phone call can result in poor audio quality, but you can often still understand what the person is saying. With faxing over IP, any packet loss can potentially cause the fax to fail completely.

That being said, if faxing is important to your business, then you should consider a reliable FoIP (fax over IP) solution such as FaxStation. With Sangoma’s FaxStation you can enjoy an analog fax experience without the added cost of an additional PSTN line.

You can find more information and solutions at Sangoma.

Tuesday, April 20, 2010

Broadvox SIP Trunking Certified With UM Labs Enhanced SIP Security Controller

Broadvox SIP Trunking Certified with UM Labs Enhanced SIP Security Controller http://snapvoip.blogspot.com/

Broadvox and UM Labs announced today interoperability certification between Broadvox GO! SIP Trunking and UM Labs’ family of enhanced SIP security controllers. Broadvox as you may know is a premier ITSP Internet Telephony Service Provider since 2001, and UM Labs, is a leader in SIP security and SIP connectivity

“Interoperability certification provides resellers and customers with confidence that Broadvox’s growing ecosystem of technology partners can support their specific PBX environment and provide enhanced cost effective connectivity and security solutions,  We welcome UM Labs as a technology interop partner.” said Isaac Parampottil, Director of Product Management at Broadvox.
“We are very pleased to work with Broadvox, an industry leader in SIP Trunking, to provide their customers with additional proven solutions for SIP connectivity, security and voice encryption.”  concurred  Peter Cox, CEO of UM Labs.

The interoperability certification covers the entire range of Broadvox SIP Trunking services and UM Labs RC-2100 Small Business and EC-4200 Enterprise product lines.
Press Release

Thursday, October 29, 2009

VoIP Security, Asterisk, SIP, Brute Force Attacks, Explained By John Todd Of Digium.

VoIP Security snapvoip.blogspot.com
My thoughts when I read the article saying  “Asterisk attacks are endemic” were ????*&^ and I also knew that John Todd knew what he is doing. So I let the article pass as I was certain it was not the case.
Today Todd has posted an article explaining the misinterpretation of his thoughts and the verbalization of the same.

My comment in the article was not that “Asterisk attacks are endemic”, but that SIP-based brute force attacks are endemic.  Every SIP system that is open to the “public” Internet is seeing large numbers of brute-force attacks.  Sites that have weak username and weak password control will be compromised – this is little different than email accounts being taken over by password-guessing systems and used for sending floods of email.  The significant difference is that when someone takes over a SIP platform to make outbound calls, there is usually a direct monetary cost, which gets people’s attention very quickly.
We all know that Asterisk is used world over and is the favorite SIP based telephony platform is likely to attract people who are interested in hacking or attacking the system. But we also have seen security measures taken by Asterisk as well. Just like the one released day before yesterday, AST-2009-07, where the advisory and the fix was released simultaneously.
But what Todd wrote makes sense and as Asterisk, Broadsoft, Cisco, Kamailio, OpenSER, FreeSwitch, Avaya are all vulnerable to brute force attacks and every bit of  information will help. Whether it is news worthy or not.
Asterisk and SIP Security Redux

Thursday, May 07, 2009

SIP Security, A New Book From Wiley

SIP and SIP Security
The big guns at Fraunhofer Institute Fokus,who brought us the SIP Express Router (SER), has written a very good book on SIP Security.
Authors, Dr. Dorgham Sisalem, Dr. John Floroiu, Jiri Kuthan, Ulrich Abend, and Prof. Henning Schulzrinne are pioneers in SIP technology and have vested interest and knowledge of the subject SIP and SIP Security. If you need further assuarence, you can read a forward by security guru Phil Zimmerman on the site which is linked below.
SIP Accounts are used by many now for day to day communications and all major IP Telephony and VoIP carriers are deploying or already have deployed SIP Back Bones. I learned my SIP from SER, when most people were wondering what VoIP was.
I cant comment much on the book itself as I have not read it yet but I will assure you, it is something you need to have near by, if you are involved in Communications.
The authors have a website to provide information on the book.

You can read an excerpt of the book here.

Tuesday, December 09, 2008

IC3, Asterisk And SIP Security

http://snapvoip.blogspot.com/
If you followed the recent security saga about the Asterisk and caller ID spoofing and Vishing attacks, Digium has issued a very explanatory post on their website, SIP Security and Asterisk
This should clear any doubts about Asterisk's security measures and bugs. Also how the SIP Security should be addressed. But as always security is a continuous challenge and continue to be vigilant.
It is must read and once you are done with it you may also want to read the new IC3 warning with the update.
You should get to know IC3.GOV in any case, if you are an Internet user.

Sunday, January 06, 2008

Asterisk 1.4.17 released to fix SIP Security Issue.

The Asterisk development team has released Asterisk version 1.4.17 which fixes SIP security issue, as well as a number of other bug fixes.

The SIP security issue is documented in the published security advisory, AST-2008-001. This issue only affects Asterisk 1.4. Asterisk 1.2 is not affected. Systems that do not use chan_sip are also not affected.

The security advisory is here in PDF format.

The release 1.4.17 is available for immediate download.


tag: , , , ,

Thursday, August 30, 2007

A VoIP Security attack Demo


VoIP security that is in everyones mind, at least those who are involved with VoIP IP Telephony, have a one more new source for looking up VoIP Security and related information. Sipera Systems that I wrote about in the "VoIP Security at the BlackHat 2007" has launched a new blog, Sipera VIPER Lab Blog.

I was at the VoiceCon San Francisco 2007 and had the chance of seeing the demonstration of the VoIP-to-data attack presentation. This demo was also done at the BlackHat 2007. The demo Sachin Joglekar, Vulnerability Research Lead, shows how by sending a specific SIP packet, he can crash the SIP softphone and have it execute a server code to which he can connect via netcat. This process leads to a terminal (or Command Prompt) on the Windows system and he was in control of the target system. I guess at this point there is no need to explain further.
I think it is good to see the demo podcast presented by Dan York of the “Blue Box: The VoIP Security Podcast”.
So follow the links and enjoy the Blog and the podcast!


Blog Widget by LinkWithin