Author Archives: Martyn Davies

About Martyn Davies

Martyn is Principal Consultant for Weird Crater, a telecom and software consultancy.

The 3rd Annual VoIP Security Workshop opens today, Berlin

There’s an excellent turnout, and Fraunhofer Fokus are doing a great job of hosting, with free WLAN (hence this blog entry) and everything you would expect from a well-run conference.

The keynote speech today was provided by Virgil Gligor of the University of Maryland, on the subject Adversary Models; in other words it is necessary to define the adversary before we can decide what ‘secure’ means. Prof. Gligor was the 2006 recipient of the prestigious National Security Award, and he also has the distinction of being the first person ever to write a paper about Denial of Service attacks

In a wide-ranging talk, Prof Gligor pointed out that in the history of computing there has often been a 10 or more year gap between the use of technology and the addressing of security issues that arise from it. This of course also true today of VoIP and VoIP security, and he assures us that at least this means we will all have jobs for life.

One of the key messages of his talk was that “Perfect is the Enemy of the Good”, or in other words, we can secure a system 100%, but end up with a completely unworkable system. On the other hand we can engineer systems that work, but only detect perhaps 70% of intrusions and other security problems. There is no such thing as a completely secure system.

Conferences Coming Up

I can see that the VoIP Developer conference in August has a couple of sessions led by VOIPSA members, namely Andrew Graydon and Bogdan Materna. I’m looking forward to this conference, should have some excellent material.

On the subject of conferences: as Dan York mentioned, the Berlin VoIP Security Workshop starts tomorrow; I’ll be attending, so I hope I bump into a few fellow VOIPSA people over the next couple of days. Stay tuned for a brief conference report here, and also an audio report on Dan’s Bluebox podcast.