[VOIPSEC] On the topic of Vishing

Simon Horne s.horne at packetizer.com
Fri Jul 14 01:28:12 CDT 2006


Recently I read this article
http://news.com.com/Phishers+come+calling+on+VoIP/2100-7349_3-6092366.html?tag=fd_nbs_ent&tag=nl.e433

Vishing is a major concern for SIP. Without any form of peer-entity 
(end-to-end caller) authentication and secure call admission mechanism (or 
the capability to support it) then there appears to be no real method for 
addressing this incredibly major problem.

Let me explain using the example from the article and how Vishing can be 
prevented in standard based VoIP.

As I have mentioned in previous emails that one possible solution is the 
use of 2 factor authentication, Something I have (a PKI cert etc) and 
something I know (username/password)

Certainly using end-to-end authentication will definitely help reduce the 
risk as the caller will have some certainty to whom they are calling but it 
is not a complete answer as the Vishers may acquire a valid digital 
certificate which makes them appear that they are someone who they are not. 
This is where the importance of the second factor comes in. The Bank issues 
the user with a user and password and this is used to verify the client at 
the bank so their is no need to enter user/pass or credit card information 
(or in fact depending on the application there so no need for an IVR system 
at all). Although human conditioning may still be an issue, but proper 
education will go a long way to resolve a lot of the vishing problems in VoIP.

All this is possible to do today using the H.235 framework of H.323.


Simon










More information about the Voipsec mailing list