[VOIPSEC] IPS to protect against VOIP Attacks?

J. Oquendo sil at infiltrated.net
Wed Jan 6 09:54:42 CST 2010


Juan B wrote:
> man thanks for your answer.. im sure you are right. the issue is that this client is really stupid, they dont have time to invest in VOIP security so they want an IPS which they can configure and not have too much work with it.. I now its bad practice but I only need to present a one week consulting of voip security and part of it is to install an ips, you now of a normal commercial one?
>
> btw, maybe you can answer me this question which I send to the list, It didnt got posted:
> Cisco call manager encrypting signaling and voice
>
> am doing a voip security consulting for a big client of mine.
>
> I want to recomend to implement call encryption. the client has 6 cisco call manager version 6.1.3.1000-16 it is an appliance. according to a menual im reading call encryption can be done only if call manager is installed on windows 2000/2003 is it true?? i found a menual named secoview.pdf in the internet.
>
> thanks again!
>
> juan
>
>
> --- On Wed, 1/6/10, J. Oquendo <sil at infiltrated.net> wrote:
>
>   

I believe in CCM you need to install Cisco's CTL Provider unsure if you
can do TLS without it on Cisco. I'd have to actually turn on my CCM and
RTFM myself to answer that. As for encryption on the wire... VPN tunnels
should suffice (if properly configured and aggressive mode is not in
your vocab). Won't do much internally though ;) Another thing to think
about it *DECRYPTION* though. For example: "This call is being monitored
for quality assurance" Depending on the industry, if calls are being
recorded and stored, make sure you have a capable and repeatable way to
decrypt a call. E-Discovery can potentially hurt you there.

You state: "they dont have time to invest in VOIP security so they want
an IPS which they can configure and not have too much work with it.." If
it were me, I would educate them on the risks involved with not properly
implementing the right protections. That's just me... W/E though...
Recommendations... Jeez, I've met so many cool people at cool companies
I don't know who to recommend without offending anyone I know...

Let's see - if you say they don't have time to invest - I'm thinking
they're likely limited in budget too... Anyway, these would be my
recommendations on "pretty" while not solving the issue of VoIP security
(in no particular order) Juniper, Tipping Point and Juniper and Tipping
Point.

There *was* another company somewhere around these parts... They were
the most uber company you ever heard of. Released an astonishing 100
advisories at a time - multiple times. They're too scary to name but I
will quote their literature (omitting their name... clever Googling can
yield their name): "XXXXX is the industry's first Enterprise VoIP
Intrusion Prevention System (VIPS) with comprehensive protection for
Voice over IP systems from the leading VoIP vendors.  XXXXX provides
effective protection against known and new attacks aimed at compromising
the security of VoIP networks." I say: *yawn* ... Beware of "Snake Oil."

If it were me on this matter and I had to fork out cash... It would be
Juniper or Tipping Point period. Otherwise like the glutton for
punishment I am, I'd probably want to make my own butchered up program.

Hola Juniper(eans?) and Tipping Point(sters?)



-- 

=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
J. Oquendo
SGFA, SGFE, C|EH, CNDA, CHFI, OSCP

"It takes 20 years to build a reputation and five minutes to
ruin it. If you think about that, you'll do things
differently." - Warren Buffett

227C 5D35 7DCB 0893 95AA  4771 1DCE 1FD1 5CCD 6B5E
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x5CCD6B5E





More information about the Voipsec mailing list