SlideShare ist ein Scribd-Unternehmen logo
1 von 85
Downloaden Sie, um offline zu lesen
The State Of VoIP Security, a.k.a.!
                   !
“Does Anyone Really Give A _____ About
           VoIP Security?”




               Dan York, CISSP!
        Chair, VoIP Security Alliance



                                         October 5, 2011
© 2011 VOIPSA
                http://www.flickr.com/photos/willpate/46488553/
Does Anyone Really !
                Give A _____ About!
                  VoIP Security?


© 2011 VOIPSA
Does Anyone Really !
        Give A _____ About!
           VoIP Unified
     Communications Security?

© 2011 VOIPSA
Technical Solutions




© 2011 VOIPSA
Widely Deployed




© 2011 VOIPSA
TLS-Encrypted SIP




© 2011 VOIPSA
Secure RTP (SRTP)




© 2011 VOIPSA
MORE Secure!
                 Than PSTN



© 2011 VOIPSA
© 2011 VOIPSA
                http://www.flickr.com/photos/mattblaze/2275723713/
MORE Secure!
                Than Ever Before



© 2011 VOIPSA
Almost All Venders!
                  Have Support



© 2011 VOIPSA
Almost All Customers!
                  Don’t Turn It On



© 2011 VOIPSA
Why Not?




© 2011 VOIPSA
Complexity




© 2011 VOIPSA
Fingerpointing, a.k.a. “One Throat To Choke”



                              PSTN
                   PBX       Gateways




                             Physical
                 Voicemail
                              Wiring




© 2011 VOIPSA
Fingerpointing - 2011
                                            Mobile
                                            Devices
                    IM                                                      Application
                                                          Internet           Servers
                 Networks          Operating
                                   Systems
                                                PSTN
                      IP-PBX                   Gateways
                                                                     VoIP


                  Web               IP                                       Social
                                                       Firewalls
                 Servers          Network                                   Networks

                                               Physical         Directory
                      Voicemail
                                                Wiring          Servers
                                  Desktop
                 Email             PCs                                  Database
                Servers                                CRM               Servers
                                                      Systems
                                       Session
                                       Border
                                      Controllers




© 2011 VOIPSA
“UC”




© 2011 VOIPSA
Debugging




© 2011 VOIPSA
Turn It Back On?




© 2011 VOIPSA
SIP Is So Simple, Right?




© 2011 VOIPSA
Riiiiiigggghhhttt… (Fingerpointing Redux)




© 2011 VOIPSA
Evolution




© 2011 VOIPSA
The Old Boys’ Club


                                  Carrier
                                                 Carrier
                    Carrier



                                  PSTN                Carrier
                Carrier


                              Carrier       Carrier




© 2011 VOIPSA
The Wild West… 
                                                                    ITSP
                                                                                                    ITSP
                                                                                                                   ITSP
                                                                     ITSP
                                             ITSP

                                                                                                       ITSP

                                                                                                                           ITSP
                              ITSP
                                                                  ITSP
                                                                                     ITSP              ITSP
                                                    ITSP
                                                                                                                      ITSP


                     ITSP                                         PSTN                       ITSP
                                                ITSP

                     ITSP                                                                                   ITSP
                                                              ITSP            ITSP
                                      ITSP

     ITSP
                                                                                                     ITSP           ITSP
                     ITSP                    ITSP      ITSP                        ITSP



                                                                                                    ITSP       ITSP
      ITSP                           ITSP                  ITSP             ITSP          ITSP
© 2010 VOIPSA and Owners as Marked
© 2011 VOIPSA
Evolution of Attacks




© 2011 VOIPSA
DoS




© 2011 VOIPSA
DDoS




© 2011 VOIPSA
Fraud




© 2011 VOIPSA
If 1 Is Good, Why Not 3?




© 2011 VOIPSA
Geography



© 2011 VOIPSA
Internet   LAN




© 2011 VOIPSA
PC


                    UC
                  System
                                 Firewall   Internet    Home
                                                       Firewall



                                                                    IP
                Corp	
  HQ	
                                      Phone
                                                       Home	
  




© 2011 VOIPSA
Laptop
                                                                         UC
                                                                        client
                                                          WiFi
                    UC
                  System
                                 Firewall   Internet      Café
                                                         Router



                Corp	
  HQ	
  
                                               Mobile
                                                Data
                                               Network        Mobile
                                                               UC
                                                              client




© 2011 VOIPSA
Corporate
                                                                   Internet
                             Network

                                                             IVR                    Voicemail
                   IM             IM              IM

                Presence       Presence        Presence

                  Call           Call            Call
                 Control        Control         Control              Conferencing




           Corp	
  HQ	
      Office	
  A	
     Office	
  B	
  



                             PSTN


© 2011 VOIPSA
© 2011 VOIPSA
Benefits
                (for us… and for attackers)




© 2011 VOIPSA
DDoS!
                     (the old-fashioned kind)!
                                               
                (Asterisk & Amazon EC2, anyone?)




© 2011 VOIPSA
SPIT!
                                              
                (“SPam for Internet Telephony”)




                           SPAM

© 2011 VOIPSA
Complexity




© 2011 VOIPSA
Fingerpointing - 2011
                                            Mobile
                                            Devices
                    IM                                                      Application
                                                          Internet           Servers
                 Networks          Operating
                                   Systems
                                                PSTN
                      IP-PBX                   Gateways
                                                                     VoIP


                  Web               IP                                       Social
                                                       Firewalls
                 Servers          Network                                   Networks

                                               Physical         Directory
                      Voicemail
                                                Wiring          Servers
                                  Desktop
                 Email             PCs                                  Database
                Servers                                CRM               Servers
                                                      Systems
                                       Session
                                       Border
                                      Controllers




© 2011 VOIPSA
The Device Formerly!
                    Known As A!
                     “Phone”



© 2011 VOIPSA
Mobility




© 2011 VOIPSA
RTCWEB / WebRTC




© 2011 VOIPSA
Complexity




© 2011 VOIPSA
Fingerpointing - 2011
                                            Mobile
                                            Devices
                    IM                                                      Application
                                                          Internet           Servers
                 Networks          Operating
                                   Systems
                                                PSTN
                      IP-PBX                   Gateways
                                                                     VoIP


                  Web               IP                                       Social
                                                       Firewalls
                 Servers          Network                                   Networks

                                               Physical         Directory
                      Voicemail
                                                Wiring          Servers
                                  Desktop
                 Email             PCs                                  Database
                Servers                                CRM               Servers
                                                      Systems
                                       Session
                                       Border
                                      Controllers




© 2011 VOIPSA
Interoperability




© 2011 VOIPSA
“The Hitchiker’s Guide!
                       To SIP”



© 2011 VOIPSA
Forgotten!
                Simple Things



© 2011 VOIPSA
Biggest Financial Threat?




© 2011 VOIPSA
Toll Fraud




© 2011 VOIPSA
IT Security 101




© 2011 VOIPSA
PIN = “1234”




© 2011 VOIPSA
Password = “password”




© 2011 VOIPSA
Default password list




© 2011 VOIPSA
VoIP = bits




© 2011 VOIPSA
IT Security 101




© 2011 VOIPSA
Does Anyone Really !
                Give A _____ About!
                  VoIP Security?


© 2011 VOIPSA
WHEN Will They Care?




© 2011 VOIPSA
EVENT




© 2011 VOIPSA
Identity Theft




© 2011 VOIPSA
Celebrity




© 2011 VOIPSA
Trusted Leader




© 2011 VOIPSA
“VoIP Is Insecure!!!”




© 2011 VOIPSA
depl oyed
            tupi dly
        S
                “VoIP Is Insecure!!!”
                 ^



© 2011 VOIPSA
“VoIP Is Insecure!!!”




© 2011 VOIPSA
Cover Your ____




© 2011 VOIPSA
SOLUTIONS?




© 2011 VOIPSA
IT Security 101




© 2011 VOIPSA
Audit, Audit, Audit




© 2011 VOIPSA
Enable What You Have




© 2011 VOIPSA
Interoperability




© 2011 VOIPSA
www.sipit.net




© 2011 VOIPSA
Identity




© 2011 VOIPSA
Simplicity




© 2011 VOIPSA
Fabric




© 2011 VOIPSA
Air




© 2011 VOIPSA
© 2011 VOIPSA
Secure By Default




© 2011 VOIPSA
Education




© 2011 VOIPSA
What is the Industry Doing to Help?




       Security Vendors                  VoIP Vendors

       “The Sky Is Falling!”             “Don’t Worry, Trust Us!”
       (Buy our products!)                 (Buy our products!)




© 2011 VOIPSA
www.voipsa.org/Resources/tools.php




© 2011 VOIPSA
Security Links

    •  VoIP Security Alliance - http://www.voipsa.org/ 
         –  Threat Taxonomy      
- http://www.voipsa.org/Activities/taxonomy.php
         –  VOIPSEC email list   
- http://www.voipsa.org/VOIPSEC/
         –  Weblog 
        
    
- http://www.voipsa.org/blog/
         –  Security Tools list  
- http://www.voipsa.org/Resources/tools.php
         –  Blue Box: The VoIP Security Podcast - http://www.blueboxpodcast.com 


    •  NIST SP800-58, “Security Considerations for VoIP Systems”
         –  http://csrc.nist.gov/publications/nistpubs/800-58/SP800-58-final.pdf
    •  Network Security Tools
         –  http://sectools.org/
    •  Hacking Exposed VoIP site and tools
         –  http://www.hackingvoip.com/
    •  Seven Deadliest Unified Communications Attacks
         –  http://www.7ducattacks.com/



© 2011 VOIPSA
Thank You For!
                Giving A _____



© 2011 VOIPSA
Thank you!               Q & eh?




                www.voipsa.org
                                                   7ducattacks.com

                Dan York - dan.york@voipsa.org!
                +1-802-735-1624
                DisruptiveTelephony.com
                danyork.com!                      blueboxpodcast.com
                twitter.com/danyork




© 2011 VOIPSA

Weitere ähnliche Inhalte

Mehr von Dan York

Open Source and The Global Disruption Of Telecom: What Choices Will We Make?
Open Source and The Global Disruption Of Telecom: What Choices Will We Make?Open Source and The Global Disruption Of Telecom: What Choices Will We Make?
Open Source and The Global Disruption Of Telecom: What Choices Will We Make?
Dan York
 

Mehr von Dan York (17)

Yes, IPv6 is Real! How To Make Your Apps Work (And Be As Fast As Possible)
Yes, IPv6 is Real! How To Make Your Apps Work (And Be As Fast As Possible) Yes, IPv6 is Real! How To Make Your Apps Work (And Be As Fast As Possible)
Yes, IPv6 is Real! How To Make Your Apps Work (And Be As Fast As Possible)
 
SIPNOC 2014 - Is It Time For TLS for SIP?
SIPNOC 2014 - Is It Time For TLS for SIP?SIPNOC 2014 - Is It Time For TLS for SIP?
SIPNOC 2014 - Is It Time For TLS for SIP?
 
A Choice Of Internet Futures: Will Nonprofits Be Stuck In The Slow Lane?
A Choice Of Internet Futures: Will Nonprofits Be Stuck In The Slow Lane?A Choice Of Internet Futures: Will Nonprofits Be Stuck In The Slow Lane?
A Choice Of Internet Futures: Will Nonprofits Be Stuck In The Slow Lane?
 
Open Source and The Global Disruption Of Telecom: What Choices Will We Make?
Open Source and The Global Disruption Of Telecom: What Choices Will We Make?Open Source and The Global Disruption Of Telecom: What Choices Will We Make?
Open Source and The Global Disruption Of Telecom: What Choices Will We Make?
 
DNS / DNSSEC / DANE / DPRIVE Results at IETF93 Hackathon
DNS / DNSSEC / DANE / DPRIVE Results at IETF93 HackathonDNS / DNSSEC / DANE / DPRIVE Results at IETF93 Hackathon
DNS / DNSSEC / DANE / DPRIVE Results at IETF93 Hackathon
 
Deploying New DNSSEC Algorithms (IEPG@IETF93 - July 2015)
Deploying New DNSSEC Algorithms (IEPG@IETF93 - July 2015)Deploying New DNSSEC Algorithms (IEPG@IETF93 - July 2015)
Deploying New DNSSEC Algorithms (IEPG@IETF93 - July 2015)
 
How IPv6 Will Kill Telecom - And What We Need To Do About It
How IPv6 Will Kill Telecom - And What We Need To Do About ItHow IPv6 Will Kill Telecom - And What We Need To Do About It
How IPv6 Will Kill Telecom - And What We Need To Do About It
 
SIP, Unified Communications (UC) and Security
SIP, Unified Communications (UC) and SecuritySIP, Unified Communications (UC) and Security
SIP, Unified Communications (UC) and Security
 
ClueCon2009: The Security Saga of SysAdmin Steve
ClueCon2009: The Security Saga of SysAdmin SteveClueCon2009: The Security Saga of SysAdmin Steve
ClueCon2009: The Security Saga of SysAdmin Steve
 
SIP Trunking & Security in an Enterprise Network
SIP Trunking & Security  in an Enterprise NetworkSIP Trunking & Security  in an Enterprise Network
SIP Trunking & Security in an Enterprise Network
 
OSCON 2008: Mashing Up Voice and the Web Using Open Source and XML
OSCON 2008: Mashing Up Voice and the Web Using Open Source and XMLOSCON 2008: Mashing Up Voice and the Web Using Open Source and XML
OSCON 2008: Mashing Up Voice and the Web Using Open Source and XML
 
IP Telephony Security 101
IP Telephony Security 101IP Telephony Security 101
IP Telephony Security 101
 
Recording Remote Hosts/Interviews with VoIP/Skype
Recording Remote Hosts/Interviews with VoIP/SkypeRecording Remote Hosts/Interviews with VoIP/Skype
Recording Remote Hosts/Interviews with VoIP/Skype
 
Hacking and Attacking VoIP Systems - What You Need To Know
Hacking and Attacking VoIP Systems - What You Need To KnowHacking and Attacking VoIP Systems - What You Need To Know
Hacking and Attacking VoIP Systems - What You Need To Know
 
E Tel2007 Black Bag Session - VoIP Security Threats, Tools and Best Practices
E Tel2007 Black Bag Session - VoIP Security Threats, Tools and Best PracticesE Tel2007 Black Bag Session - VoIP Security Threats, Tools and Best Practices
E Tel2007 Black Bag Session - VoIP Security Threats, Tools and Best Practices
 
BLISS Problem Statement and Motivation
BLISS Problem Statement and MotivationBLISS Problem Statement and Motivation
BLISS Problem Statement and Motivation
 
ETel2007: The Black Bag Security Review (VoIP Security)
ETel2007: The Black Bag Security Review (VoIP Security)ETel2007: The Black Bag Security Review (VoIP Security)
ETel2007: The Black Bag Security Review (VoIP Security)
 

Kürzlich hochgeladen

Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 

Kürzlich hochgeladen (20)

Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 

The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"