SlideShare una empresa de Scribd logo
1 de 27
Descargar para leer sin conexión
Securing Communications!
SpeechTEK New York 2010!
Dan York, CISSP

   Director of Conversations, Voxeo

   Best Practices Chair, VoIP Security Alliance

   Author, Seven Deadliest UC Attacks!
About Dan York!



                                               www.voipsa.org
                         www.voxeo.com




                      www.blueboxpodcast.com     www.7ducattacks.com


© Voxeo Corporation
About Voxeo!

        Founded in 1999
        World’s largest hosted VoiceXML and CCXML platform – Over
         82,000 hosted ports globally; hundreds of premise deployments
        Over 150,000 developers using Voxeo platforms
        The Voxeo difference: Unlocked Communications, Customer
         Obsession Teams, Communications Passion
        www.voxeo.com




© Voxeo Corporation
The Change VoIP Brings!



                                 SIP              SIP
                                Proxy            Proxy
                                  A      SIP       B

                          SIP                             SIP




                      Alice                                Bob
                                Media (RTP, MSRP, etc.)




© Voxeo Corporation
The Larger Reality!



                      SIP           SIP             SIP             SIP         SIP
                      Proxy         Proxy           Proxy         Proxy         Proxy
                       A      SIP    B      SIP      C      SIP     D     SIP    N

          SIP                               Internet                                    SIP



                                    Media                   Media
  Alice                             Proxy                   Proxy                        Bob
                      Media           A           Media       B             Media




© Voxeo Corporation
Once Upon A Time!




                                   PSTN
                        PBX
                                  Gateways




                                  Physical
                      Voicemail
                                   Wiring




© Voxeo Corporation
1. Understand Your Ecosystem!

                                                         Mobile
                                                         Devices
                           IM                                                                 Application
                                                                       Internet                Servers
                        Networks
                                             Operating
                                             Systems
                                                            PSTN
                                  IP-PBX                                            VoIP
                                                           Gateways


                         Web                  IP                                               Social
                                                                      Firewalls
                        Servers             Network                                           Networks


                                                           Physical               Directory
                                Voicemail
                                                            Wiring                Servers

                                            Desktop
                       Email                 PCs                                           Database
                      Servers                                       CRM                     Servers
                                                                   Systems




© Voxeo Corporation
2. Understand Your Endpoints!

        IP Phones, Smartphones, Softphones

        What services are running on them?

        Default passwords?

        How do you patch/secure them?




© Voxeo Corporation
3. Secure Your Media!


                             SIP           SIP                   SIP
                            Proxy         Proxy                 Proxy
                              A     SIP     B     SIP             N

                      SIP                                               SIP




           Alice                          Eve                            Bob
                            Media                       Media




© Voxeo Corporation
Secure Media – Hop By Hop!



                                      Internet


                              Media              Media
Alice                         Proxy              Proxy           Bob
                      Media     A      Media       B     Media




© Voxeo Corporation
Secure Media – End to End!



                                      Internet


                              Media              Media
Alice                         Proxy              Proxy           Bob
                      Media     A      Media       B     Media




© Voxeo Corporation
4. Secure Your Signalling!



                       SIP           SIP                         SIP
                      Proxy         Proxy           Eve         Proxy
                        A     SIP     B     SIP           SIP     N

              SIP                                                       SIP




      Alice                                                              Bob
                                            Media




© Voxeo Corporation
Signalling Attacks!

        Toll Fraud

        Identity Theft




© Voxeo Corporation
Traditional Telephony!



                                       Internet




                                                  Carrier   PSTN
                          PBX




                      Corp	
  HQ	
  




© Voxeo Corporation
IP Communications!



                                     ITSP



                          Internet
              PBX

                                            PSTN

         Corp	
  HQ	
  




© Voxeo Corporation
Failover!



             PBX
                                    ITSP


        Corp	
  HQ	
  
                         Internet          PSTN



              PBX



           Office	
  
            A	
  



© Voxeo Corporation
Redundancy / Geography!

                                   ITSP
                                   (Boston)




                        Internet
            PBX                    ITSP
                                   (Paris)
                                              PSTN

       Corp	
  HQ	
  



                                   ITSP
                                   (Tokyo)




© Voxeo Corporation
5. Secure Your PSTN Connectivity!

        Attacks
          •  Toll Fraud
          •  Denial of Service
          •  Spam

        Solutions
          •  Encryption
          •  Strong Authentication
          •  Transport Security



© Voxeo Corporation
6. Secure Your Identity!

        Attacks
          •  Fraud
          •  Identity Theft
          •  Social Engineering

        Solutions
          •  Education
          •  Lock Down Spoofing
          •  Strong Identity



© Voxeo Corporation
7. Secure Distributed Systems!


                                                                     Laptop
                                                                       UC
                                                                      client
                                                        WiFi
                   UC
                 System
                               Firewall   Internet      Café
                                                       Router



              Corp	
  HQ	
  
                                             Mobile
                                              Data
                                             Network        Mobile
                                                             UC
                                                            client




© Voxeo Corporation
How Do You Securely Federate?!

                                                       Internet




                          Corporate                                        Corporate
                           Network                                          Network



                        UC                UC                          UC                  UC
                      System            System                      System              System



                Corp	
  HQ	
           Office	
  A	
                Corp	
  HQ	
         Office	
  A	
  

                           Company	
  A	
                                  Company	
  B	
  

© Voxeo Corporation
What if the Cloud Isnʼt There?!

                        Corporate
                                                               Internet
                         Network


                                                         IVR              Voicemail
              IM              IM              IM

          Presence        Presence        Presence

             Call            Call            Call
            Control         Control         Control




       Corp	
  HQ	
      Office	
  A	
     Office	
  B	
  




                         PSTN


© Voxeo Corporation
Questions About the Cloud!

        What kind of availability guarantees / Service Level Agreements (SLAs)
         does the platform vendor provide?

        What kind of geographic redundancy is built into the underlying
         network?

        What kind of network redundancy is built into the underlying network?

          What kind of physical redundancy is built into the data centers?

        What kind of monitoring does the vendor perform?

        What kind of scalability is in the cloud computing platform?

        What kind of security, both network and physical, is part of the
         computing platform?

        Finally, what will the vendor do if there is downtime? Will the downtime
         be reflected in your bill?

© Voxeo Corporation
The Way It Used To Be!




© Voxeo Corporation
Today...!                                                                ITSP
                                                                                         ITSP
                                                                                                        ITSP
                                                          ITSP
                                  ITSP

                                                                                            ITSP

                                                                                                                ITSP
                    ITSP
                                                       ITSP
                                                                          ITSP              ITSP
                                         ITSP
                                                                                                           ITSP



            ITSP                                       PSTN                       ITSP
                                     ITSP

            ITSP
                                                                                                 ITSP
                                                   ITSP            ITSP
                           ITSP

ITSP
                                                                                          ITSP
                                                                                                         ITSP

            ITSP                  ITSP      ITSP                        ITSP



                                                                                         ITSP       ITSP
ITSP                    ITSP                    ITSP             ITSP          ITSP
  © Voxeo Corporation
Resources!

        VoIP Security Alliance
          •  www.voipsa.org
          •  www.voipsa.org/blog


        Hacking Exposed: VoIP
          •  www.hackingvoip.com


        Seven Deadliest Unified Communications
         Attacks
          •  www.7ducattacks.com

© Voxeo Corporation
Securing Unified Communications Systems

Más contenido relacionado

La actualidad más candente

Luxemburg event - airtight networks
Luxemburg event - airtight networksLuxemburg event - airtight networks
Luxemburg event - airtight networksKappa Data
 
WinWire Webinar: Messaging and Networking with Windows Azure
WinWire Webinar: Messaging and Networking with Windows AzureWinWire Webinar: Messaging and Networking with Windows Azure
WinWire Webinar: Messaging and Networking with Windows AzureWinWire Technologies Inc
 
Wireless lan solutions_for_education
Wireless lan solutions_for_educationWireless lan solutions_for_education
Wireless lan solutions_for_educationAdvantec Distribution
 
Network Storage: State of the Industry
Network Storage: State of the IndustryNetwork Storage: State of the Industry
Network Storage: State of the IndustryIMEX Research
 
Meet Xo Core Presentation 2011
Meet Xo Core Presentation 2011Meet Xo Core Presentation 2011
Meet Xo Core Presentation 2011Rwaegerle
 
Siemens: The Evolution of Corporate Communications
Siemens: The Evolution of Corporate CommunicationsSiemens: The Evolution of Corporate Communications
Siemens: The Evolution of Corporate CommunicationsEntel
 
Disruptive Analysis LTE Summit 2011 voice presentation may 2011
Disruptive Analysis   LTE Summit 2011 voice presentation may 2011Disruptive Analysis   LTE Summit 2011 voice presentation may 2011
Disruptive Analysis LTE Summit 2011 voice presentation may 2011Dean Bubley
 
VOIspeed Presentation
VOIspeed PresentationVOIspeed Presentation
VOIspeed Presentationgvslideshare
 
Traffic Management, DPI, Internet Offload Gateway
Traffic Management, DPI, Internet Offload GatewayTraffic Management, DPI, Internet Offload Gateway
Traffic Management, DPI, Internet Offload GatewayContinuous Computing
 
How to Optimize VoIP Call Quality Across Multiple Calling Environments
How to Optimize VoIP Call Quality Across Multiple Calling EnvironmentsHow to Optimize VoIP Call Quality Across Multiple Calling Environments
How to Optimize VoIP Call Quality Across Multiple Calling EnvironmentsAshik Jibon
 
fonYou UTR Presentation 19-Nov-2009
fonYou UTR Presentation 19-Nov-2009fonYou UTR Presentation 19-Nov-2009
fonYou UTR Presentation 19-Nov-2009fonuser
 
Katina Leisure Mobile 2010
Katina Leisure Mobile 2010Katina Leisure Mobile 2010
Katina Leisure Mobile 2010StevenShields
 
VoIP and You - 2011
VoIP and You - 2011VoIP and You - 2011
VoIP and You - 2011rosecheng
 
4th Generation IP for Mobility, Video and Cloud
4th Generation IP for Mobility, Video and Cloud4th Generation IP for Mobility, Video and Cloud
4th Generation IP for Mobility, Video and CloudEricsson Slides
 
Driving true convergence in metro networks a
Driving true convergence in metro networks aDriving true convergence in metro networks a
Driving true convergence in metro networks aEricsson Slides
 

La actualidad más candente (19)

Luxemburg event - airtight networks
Luxemburg event - airtight networksLuxemburg event - airtight networks
Luxemburg event - airtight networks
 
WinWire Webinar: Messaging and Networking with Windows Azure
WinWire Webinar: Messaging and Networking with Windows AzureWinWire Webinar: Messaging and Networking with Windows Azure
WinWire Webinar: Messaging and Networking with Windows Azure
 
Wireless lan solutions_for_education
Wireless lan solutions_for_educationWireless lan solutions_for_education
Wireless lan solutions_for_education
 
Video the new voice
Video the new voiceVideo the new voice
Video the new voice
 
Network Storage: State of the Industry
Network Storage: State of the IndustryNetwork Storage: State of the Industry
Network Storage: State of the Industry
 
Meet Xo Core Presentation 2011
Meet Xo Core Presentation 2011Meet Xo Core Presentation 2011
Meet Xo Core Presentation 2011
 
Siemens: The Evolution of Corporate Communications
Siemens: The Evolution of Corporate CommunicationsSiemens: The Evolution of Corporate Communications
Siemens: The Evolution of Corporate Communications
 
Disruptive Analysis LTE Summit 2011 voice presentation may 2011
Disruptive Analysis   LTE Summit 2011 voice presentation may 2011Disruptive Analysis   LTE Summit 2011 voice presentation may 2011
Disruptive Analysis LTE Summit 2011 voice presentation may 2011
 
VOIspeed Presentation
VOIspeed PresentationVOIspeed Presentation
VOIspeed Presentation
 
Traffic Management, DPI, Internet Offload Gateway
Traffic Management, DPI, Internet Offload GatewayTraffic Management, DPI, Internet Offload Gateway
Traffic Management, DPI, Internet Offload Gateway
 
How to Optimize VoIP Call Quality Across Multiple Calling Environments
How to Optimize VoIP Call Quality Across Multiple Calling EnvironmentsHow to Optimize VoIP Call Quality Across Multiple Calling Environments
How to Optimize VoIP Call Quality Across Multiple Calling Environments
 
fonYou UTR Presentation 19-Nov-2009
fonYou UTR Presentation 19-Nov-2009fonYou UTR Presentation 19-Nov-2009
fonYou UTR Presentation 19-Nov-2009
 
Katina Leisure Mobile 2010
Katina Leisure Mobile 2010Katina Leisure Mobile 2010
Katina Leisure Mobile 2010
 
Wifi
WifiWifi
Wifi
 
VoIP and You - 2011
VoIP and You - 2011VoIP and You - 2011
VoIP and You - 2011
 
NGN voice corporate seminar
NGN voice corporate seminarNGN voice corporate seminar
NGN voice corporate seminar
 
4th Generation IP for Mobility, Video and Cloud
4th Generation IP for Mobility, Video and Cloud4th Generation IP for Mobility, Video and Cloud
4th Generation IP for Mobility, Video and Cloud
 
Driving true convergence in metro networks a
Driving true convergence in metro networks aDriving true convergence in metro networks a
Driving true convergence in metro networks a
 
Bio
Bio Bio
Bio
 

Destacado

#online tuesday The Floor is Yours: Peter doesburg
#online tuesday The Floor is Yours: Peter doesburg#online tuesday The Floor is Yours: Peter doesburg
#online tuesday The Floor is Yours: Peter doesburgMarketingfacts
 
Presentatie webcare robert lommers 8 maart
Presentatie webcare robert lommers 8 maartPresentatie webcare robert lommers 8 maart
Presentatie webcare robert lommers 8 maartMarketingfacts
 
20100504 opta jaarverslag 2009 interactief nl
20100504 opta jaarverslag 2009 interactief nl20100504 opta jaarverslag 2009 interactief nl
20100504 opta jaarverslag 2009 interactief nlMarketingfacts
 
Sinsai.info - Global ICT Summit
Sinsai.info - Global ICT SummitSinsai.info - Global ICT Summit
Sinsai.info - Global ICT SummitHal Seki
 
Presentatie Agis Loyalty Facts Café sept. 2010
Presentatie Agis Loyalty Facts Café sept. 2010Presentatie Agis Loyalty Facts Café sept. 2010
Presentatie Agis Loyalty Facts Café sept. 2010Marketingfacts
 
Presentatie webcare alex van leeuwen buzz capture 8 maart
Presentatie webcare alex van leeuwen buzz capture 8 maartPresentatie webcare alex van leeuwen buzz capture 8 maart
Presentatie webcare alex van leeuwen buzz capture 8 maartMarketingfacts
 
Presentatie webcare tjalling smit klm 8 maart definitief
Presentatie webcare tjalling smit klm 8 maart definitiefPresentatie webcare tjalling smit klm 8 maart definitief
Presentatie webcare tjalling smit klm 8 maart definitiefMarketingfacts
 

Destacado (7)

#online tuesday The Floor is Yours: Peter doesburg
#online tuesday The Floor is Yours: Peter doesburg#online tuesday The Floor is Yours: Peter doesburg
#online tuesday The Floor is Yours: Peter doesburg
 
Presentatie webcare robert lommers 8 maart
Presentatie webcare robert lommers 8 maartPresentatie webcare robert lommers 8 maart
Presentatie webcare robert lommers 8 maart
 
20100504 opta jaarverslag 2009 interactief nl
20100504 opta jaarverslag 2009 interactief nl20100504 opta jaarverslag 2009 interactief nl
20100504 opta jaarverslag 2009 interactief nl
 
Sinsai.info - Global ICT Summit
Sinsai.info - Global ICT SummitSinsai.info - Global ICT Summit
Sinsai.info - Global ICT Summit
 
Presentatie Agis Loyalty Facts Café sept. 2010
Presentatie Agis Loyalty Facts Café sept. 2010Presentatie Agis Loyalty Facts Café sept. 2010
Presentatie Agis Loyalty Facts Café sept. 2010
 
Presentatie webcare alex van leeuwen buzz capture 8 maart
Presentatie webcare alex van leeuwen buzz capture 8 maartPresentatie webcare alex van leeuwen buzz capture 8 maart
Presentatie webcare alex van leeuwen buzz capture 8 maart
 
Presentatie webcare tjalling smit klm 8 maart definitief
Presentatie webcare tjalling smit klm 8 maart definitiefPresentatie webcare tjalling smit klm 8 maart definitief
Presentatie webcare tjalling smit klm 8 maart definitief
 

Similar a Securing Unified Communications Systems

3. FOMS_ IMS services_Shane_Dempsey
3. FOMS_ IMS services_Shane_Dempsey3. FOMS_ IMS services_Shane_Dempsey
3. FOMS_ IMS services_Shane_DempseyFOMS011
 
IPv6 and How It Impacts Communication Applications
IPv6 and How It Impacts Communication ApplicationsIPv6 and How It Impacts Communication Applications
IPv6 and How It Impacts Communication ApplicationsVoxeo Corp
 
Hacking and Attacking VoIP Systems - What You Need To Know
Hacking and Attacking VoIP Systems - What You Need To KnowHacking and Attacking VoIP Systems - What You Need To Know
Hacking and Attacking VoIP Systems - What You Need To KnowDan York
 
SIP Trunking & Security in an Enterprise Network
SIP Trunking & Security  in an Enterprise NetworkSIP Trunking & Security  in an Enterprise Network
SIP Trunking & Security in an Enterprise NetworkDan York
 
How IPv6 Will Kill Telecom - And What We Need To Do About It
How IPv6 Will Kill Telecom - And What We Need To Do About ItHow IPv6 Will Kill Telecom - And What We Need To Do About It
How IPv6 Will Kill Telecom - And What We Need To Do About ItDan York
 
Mobivox Company Overview
Mobivox Company OverviewMobivox Company Overview
Mobivox Company OverviewPhil Wolff
 
IP communications to billions of people coming soon to a web broswer near y...
IP communications to billions of people   coming soon to a web broswer near y...IP communications to billions of people   coming soon to a web broswer near y...
IP communications to billions of people coming soon to a web broswer near y...Ericsson Slides
 
Gaurav kumar VOIP MMMEC
Gaurav kumar VOIP MMMECGaurav kumar VOIP MMMEC
Gaurav kumar VOIP MMMECGaurav Kumar
 
SpeechTEK 2009: Securing Cloud Telephony Aug2009
SpeechTEK 2009: Securing Cloud Telephony Aug2009SpeechTEK 2009: Securing Cloud Telephony Aug2009
SpeechTEK 2009: Securing Cloud Telephony Aug2009Voxeo Corp
 
I N T E R O P09 Suhas Desai Secure Your Vo I P Network With Open Source
I N T E R O P09  Suhas  Desai  Secure  Your  Vo I P  Network With  Open  SourceI N T E R O P09  Suhas  Desai  Secure  Your  Vo I P  Network With  Open  Source
I N T E R O P09 Suhas Desai Secure Your Vo I P Network With Open SourceSuhas Desai
 
Mobility and SmartTAP Recording for Lync
Mobility and SmartTAP Recording for LyncMobility and SmartTAP Recording for Lync
Mobility and SmartTAP Recording for LyncMUCUGL
 
Open Source Telephony Disruptive Solutions
Open Source Telephony Disruptive SolutionsOpen Source Telephony Disruptive Solutions
Open Source Telephony Disruptive SolutionsMarco Mouta
 
Avaya sipwithinyourenterprise-090629022848-phpapp02
Avaya sipwithinyourenterprise-090629022848-phpapp02Avaya sipwithinyourenterprise-090629022848-phpapp02
Avaya sipwithinyourenterprise-090629022848-phpapp02Newlink
 
Avaya sipwithinyourenterprise-090629022848-phpapp02
Avaya sipwithinyourenterprise-090629022848-phpapp02Avaya sipwithinyourenterprise-090629022848-phpapp02
Avaya sipwithinyourenterprise-090629022848-phpapp02Newlink
 

Similar a Securing Unified Communications Systems (20)

3. FOMS_ IMS services_Shane_Dempsey
3. FOMS_ IMS services_Shane_Dempsey3. FOMS_ IMS services_Shane_Dempsey
3. FOMS_ IMS services_Shane_Dempsey
 
IPv6 and How It Impacts Communication Applications
IPv6 and How It Impacts Communication ApplicationsIPv6 and How It Impacts Communication Applications
IPv6 and How It Impacts Communication Applications
 
Mitel BPC
Mitel BPCMitel BPC
Mitel BPC
 
Hacking and Attacking VoIP Systems - What You Need To Know
Hacking and Attacking VoIP Systems - What You Need To KnowHacking and Attacking VoIP Systems - What You Need To Know
Hacking and Attacking VoIP Systems - What You Need To Know
 
SIP Trunking & Security in an Enterprise Network
SIP Trunking & Security  in an Enterprise NetworkSIP Trunking & Security  in an Enterprise Network
SIP Trunking & Security in an Enterprise Network
 
Mwc wip jam jabber sdk final
Mwc wip jam jabber sdk finalMwc wip jam jabber sdk final
Mwc wip jam jabber sdk final
 
How IPv6 Will Kill Telecom - And What We Need To Do About It
How IPv6 Will Kill Telecom - And What We Need To Do About ItHow IPv6 Will Kill Telecom - And What We Need To Do About It
How IPv6 Will Kill Telecom - And What We Need To Do About It
 
Mobivox Company Overview
Mobivox Company OverviewMobivox Company Overview
Mobivox Company Overview
 
COLLABORATION
COLLABORATIONCOLLABORATION
COLLABORATION
 
IP communications to billions of people coming soon to a web broswer near y...
IP communications to billions of people   coming soon to a web broswer near y...IP communications to billions of people   coming soon to a web broswer near y...
IP communications to billions of people coming soon to a web broswer near y...
 
Gaurav kumar VOIP MMMEC
Gaurav kumar VOIP MMMECGaurav kumar VOIP MMMEC
Gaurav kumar VOIP MMMEC
 
Skypepresentation
SkypepresentationSkypepresentation
Skypepresentation
 
SpeechTEK 2009: Securing Cloud Telephony Aug2009
SpeechTEK 2009: Securing Cloud Telephony Aug2009SpeechTEK 2009: Securing Cloud Telephony Aug2009
SpeechTEK 2009: Securing Cloud Telephony Aug2009
 
I N T E R O P09 Suhas Desai Secure Your Vo I P Network With Open Source
I N T E R O P09  Suhas  Desai  Secure  Your  Vo I P  Network With  Open  SourceI N T E R O P09  Suhas  Desai  Secure  Your  Vo I P  Network With  Open  Source
I N T E R O P09 Suhas Desai Secure Your Vo I P Network With Open Source
 
Pbx
PbxPbx
Pbx
 
Pbx
PbxPbx
Pbx
 
Mobility and SmartTAP Recording for Lync
Mobility and SmartTAP Recording for LyncMobility and SmartTAP Recording for Lync
Mobility and SmartTAP Recording for Lync
 
Open Source Telephony Disruptive Solutions
Open Source Telephony Disruptive SolutionsOpen Source Telephony Disruptive Solutions
Open Source Telephony Disruptive Solutions
 
Avaya sipwithinyourenterprise-090629022848-phpapp02
Avaya sipwithinyourenterprise-090629022848-phpapp02Avaya sipwithinyourenterprise-090629022848-phpapp02
Avaya sipwithinyourenterprise-090629022848-phpapp02
 
Avaya sipwithinyourenterprise-090629022848-phpapp02
Avaya sipwithinyourenterprise-090629022848-phpapp02Avaya sipwithinyourenterprise-090629022848-phpapp02
Avaya sipwithinyourenterprise-090629022848-phpapp02
 

Más de Voxeo Corp

Voxeo Summit Day 2 -What's new in CXP 14
Voxeo Summit Day 2 -What's new in CXP 14Voxeo Summit Day 2 -What's new in CXP 14
Voxeo Summit Day 2 -What's new in CXP 14Voxeo Corp
 
Voxeo Summit Day 2 -Voxeo APIs and SDKs
Voxeo Summit Day 2 -Voxeo APIs and SDKsVoxeo Summit Day 2 -Voxeo APIs and SDKs
Voxeo Summit Day 2 -Voxeo APIs and SDKsVoxeo Corp
 
Voxeo Summit Day 2 - Voxeo CXP - IVR on Steroids
Voxeo Summit Day 2 - Voxeo CXP - IVR on SteroidsVoxeo Summit Day 2 - Voxeo CXP - IVR on Steroids
Voxeo Summit Day 2 - Voxeo CXP - IVR on SteroidsVoxeo Corp
 
Voxeo Summit Day 2 - Using CXP hotspot analytics
Voxeo Summit Day 2 - Using CXP hotspot analyticsVoxeo Summit Day 2 - Using CXP hotspot analytics
Voxeo Summit Day 2 - Using CXP hotspot analyticsVoxeo Corp
 
Voxeo Summit Day 2 - Securing customer interactions
Voxeo Summit Day 2 - Securing customer interactionsVoxeo Summit Day 2 - Securing customer interactions
Voxeo Summit Day 2 - Securing customer interactionsVoxeo Corp
 
Voxeo Summit Day 2 - Real-time communications with WebRTC
Voxeo Summit Day 2 - Real-time communications with WebRTCVoxeo Summit Day 2 - Real-time communications with WebRTC
Voxeo Summit Day 2 - Real-time communications with WebRTCVoxeo Corp
 
Voxeo Summit Day 2 - Voxeo CXP for business users
Voxeo Summit Day 2 - Voxeo CXP for business usersVoxeo Summit Day 2 - Voxeo CXP for business users
Voxeo Summit Day 2 - Voxeo CXP for business usersVoxeo Corp
 
Voxeo Summit Day 2 - Creating raving fans
Voxeo Summit Day 2 - Creating raving fansVoxeo Summit Day 2 - Creating raving fans
Voxeo Summit Day 2 - Creating raving fansVoxeo Corp
 
Voxeo Summit Day 2 - Advanced CCXML topics
Voxeo Summit Day 2 - Advanced CCXML topicsVoxeo Summit Day 2 - Advanced CCXML topics
Voxeo Summit Day 2 - Advanced CCXML topicsVoxeo Corp
 
Voxeo Summit Day 2 - The science of customer obsession
Voxeo Summit Day 2 - The science of customer obsessionVoxeo Summit Day 2 - The science of customer obsession
Voxeo Summit Day 2 - The science of customer obsessionVoxeo Corp
 
Voxeo Summit Day 1 - Extending your IVR investment to mobile
Voxeo Summit Day 1 - Extending your IVR investment to mobileVoxeo Summit Day 1 - Extending your IVR investment to mobile
Voxeo Summit Day 1 - Extending your IVR investment to mobileVoxeo Corp
 
Voxeo Summit Day 1 - The Art of The Possible
Voxeo Summit Day 1 - The Art of The PossibleVoxeo Summit Day 1 - The Art of The Possible
Voxeo Summit Day 1 - The Art of The PossibleVoxeo Corp
 
Voxeo Summit Day 1 - Prophecy log search
Voxeo Summit Day 1 - Prophecy log searchVoxeo Summit Day 1 - Prophecy log search
Voxeo Summit Day 1 - Prophecy log searchVoxeo Corp
 
Voxeo Summit Day 1 - Customer experience analytics
Voxeo Summit Day 1 - Customer experience analyticsVoxeo Summit Day 1 - Customer experience analytics
Voxeo Summit Day 1 - Customer experience analyticsVoxeo Corp
 
Voxeo Summit Day 1 - Communications-enabled Business Processes (CEBP)
Voxeo Summit Day 1 - Communications-enabled Business Processes (CEBP)Voxeo Summit Day 1 - Communications-enabled Business Processes (CEBP)
Voxeo Summit Day 1 - Communications-enabled Business Processes (CEBP)Voxeo Corp
 
Voxeo Summit Day 1 - A view into the Voxeo cloud
Voxeo Summit Day 1 - A view into the Voxeo cloudVoxeo Summit Day 1 - A view into the Voxeo cloud
Voxeo Summit Day 1 - A view into the Voxeo cloudVoxeo Corp
 
Voxeo Summit Day 1 - Lessons learned from large scale deployments
Voxeo Summit Day 1 - Lessons learned from large scale deploymentsVoxeo Summit Day 1 - Lessons learned from large scale deployments
Voxeo Summit Day 1 - Lessons learned from large scale deploymentsVoxeo Corp
 
Voxeo Jam Session: What's New in Prophecy 11 and VoiceObjects 11?
Voxeo Jam Session: What's New in Prophecy 11 and VoiceObjects 11?Voxeo Jam Session: What's New in Prophecy 11 and VoiceObjects 11?
Voxeo Jam Session: What's New in Prophecy 11 and VoiceObjects 11?Voxeo Corp
 
How Do You Hear Me Now?
How Do You Hear Me Now?How Do You Hear Me Now?
How Do You Hear Me Now?Voxeo Corp
 
CCXML For Advanced Communications Applications
CCXML For Advanced Communications ApplicationsCCXML For Advanced Communications Applications
CCXML For Advanced Communications ApplicationsVoxeo Corp
 

Más de Voxeo Corp (20)

Voxeo Summit Day 2 -What's new in CXP 14
Voxeo Summit Day 2 -What's new in CXP 14Voxeo Summit Day 2 -What's new in CXP 14
Voxeo Summit Day 2 -What's new in CXP 14
 
Voxeo Summit Day 2 -Voxeo APIs and SDKs
Voxeo Summit Day 2 -Voxeo APIs and SDKsVoxeo Summit Day 2 -Voxeo APIs and SDKs
Voxeo Summit Day 2 -Voxeo APIs and SDKs
 
Voxeo Summit Day 2 - Voxeo CXP - IVR on Steroids
Voxeo Summit Day 2 - Voxeo CXP - IVR on SteroidsVoxeo Summit Day 2 - Voxeo CXP - IVR on Steroids
Voxeo Summit Day 2 - Voxeo CXP - IVR on Steroids
 
Voxeo Summit Day 2 - Using CXP hotspot analytics
Voxeo Summit Day 2 - Using CXP hotspot analyticsVoxeo Summit Day 2 - Using CXP hotspot analytics
Voxeo Summit Day 2 - Using CXP hotspot analytics
 
Voxeo Summit Day 2 - Securing customer interactions
Voxeo Summit Day 2 - Securing customer interactionsVoxeo Summit Day 2 - Securing customer interactions
Voxeo Summit Day 2 - Securing customer interactions
 
Voxeo Summit Day 2 - Real-time communications with WebRTC
Voxeo Summit Day 2 - Real-time communications with WebRTCVoxeo Summit Day 2 - Real-time communications with WebRTC
Voxeo Summit Day 2 - Real-time communications with WebRTC
 
Voxeo Summit Day 2 - Voxeo CXP for business users
Voxeo Summit Day 2 - Voxeo CXP for business usersVoxeo Summit Day 2 - Voxeo CXP for business users
Voxeo Summit Day 2 - Voxeo CXP for business users
 
Voxeo Summit Day 2 - Creating raving fans
Voxeo Summit Day 2 - Creating raving fansVoxeo Summit Day 2 - Creating raving fans
Voxeo Summit Day 2 - Creating raving fans
 
Voxeo Summit Day 2 - Advanced CCXML topics
Voxeo Summit Day 2 - Advanced CCXML topicsVoxeo Summit Day 2 - Advanced CCXML topics
Voxeo Summit Day 2 - Advanced CCXML topics
 
Voxeo Summit Day 2 - The science of customer obsession
Voxeo Summit Day 2 - The science of customer obsessionVoxeo Summit Day 2 - The science of customer obsession
Voxeo Summit Day 2 - The science of customer obsession
 
Voxeo Summit Day 1 - Extending your IVR investment to mobile
Voxeo Summit Day 1 - Extending your IVR investment to mobileVoxeo Summit Day 1 - Extending your IVR investment to mobile
Voxeo Summit Day 1 - Extending your IVR investment to mobile
 
Voxeo Summit Day 1 - The Art of The Possible
Voxeo Summit Day 1 - The Art of The PossibleVoxeo Summit Day 1 - The Art of The Possible
Voxeo Summit Day 1 - The Art of The Possible
 
Voxeo Summit Day 1 - Prophecy log search
Voxeo Summit Day 1 - Prophecy log searchVoxeo Summit Day 1 - Prophecy log search
Voxeo Summit Day 1 - Prophecy log search
 
Voxeo Summit Day 1 - Customer experience analytics
Voxeo Summit Day 1 - Customer experience analyticsVoxeo Summit Day 1 - Customer experience analytics
Voxeo Summit Day 1 - Customer experience analytics
 
Voxeo Summit Day 1 - Communications-enabled Business Processes (CEBP)
Voxeo Summit Day 1 - Communications-enabled Business Processes (CEBP)Voxeo Summit Day 1 - Communications-enabled Business Processes (CEBP)
Voxeo Summit Day 1 - Communications-enabled Business Processes (CEBP)
 
Voxeo Summit Day 1 - A view into the Voxeo cloud
Voxeo Summit Day 1 - A view into the Voxeo cloudVoxeo Summit Day 1 - A view into the Voxeo cloud
Voxeo Summit Day 1 - A view into the Voxeo cloud
 
Voxeo Summit Day 1 - Lessons learned from large scale deployments
Voxeo Summit Day 1 - Lessons learned from large scale deploymentsVoxeo Summit Day 1 - Lessons learned from large scale deployments
Voxeo Summit Day 1 - Lessons learned from large scale deployments
 
Voxeo Jam Session: What's New in Prophecy 11 and VoiceObjects 11?
Voxeo Jam Session: What's New in Prophecy 11 and VoiceObjects 11?Voxeo Jam Session: What's New in Prophecy 11 and VoiceObjects 11?
Voxeo Jam Session: What's New in Prophecy 11 and VoiceObjects 11?
 
How Do You Hear Me Now?
How Do You Hear Me Now?How Do You Hear Me Now?
How Do You Hear Me Now?
 
CCXML For Advanced Communications Applications
CCXML For Advanced Communications ApplicationsCCXML For Advanced Communications Applications
CCXML For Advanced Communications Applications
 

Último

Maximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxMaximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxOnBoard
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxMalak Abu Hammad
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxMaking_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxnull - The Open Security Community
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024Scott Keck-Warren
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...shyamraj55
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 
Key Features Of Token Development (1).pptx
Key  Features Of Token  Development (1).pptxKey  Features Of Token  Development (1).pptx
Key Features Of Token Development (1).pptxLBM Solutions
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machinePadma Pradeep
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr LapshynFwdays
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 

Último (20)

Maximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxMaximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptx
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Vulnerability_Management_GRC_by Sohang Sengupta.pptx
Vulnerability_Management_GRC_by Sohang Sengupta.pptxVulnerability_Management_GRC_by Sohang Sengupta.pptx
Vulnerability_Management_GRC_by Sohang Sengupta.pptx
 
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxMaking_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food Manufacturing
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 
Key Features Of Token Development (1).pptx
Key  Features Of Token  Development (1).pptxKey  Features Of Token  Development (1).pptx
Key Features Of Token Development (1).pptx
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 

Securing Unified Communications Systems

  • 1. Securing Communications! SpeechTEK New York 2010! Dan York, CISSP
 Director of Conversations, Voxeo
 Best Practices Chair, VoIP Security Alliance
 Author, Seven Deadliest UC Attacks!
  • 2. About Dan York! www.voipsa.org www.voxeo.com www.blueboxpodcast.com www.7ducattacks.com © Voxeo Corporation
  • 3. About Voxeo!   Founded in 1999   World’s largest hosted VoiceXML and CCXML platform – Over 82,000 hosted ports globally; hundreds of premise deployments   Over 150,000 developers using Voxeo platforms   The Voxeo difference: Unlocked Communications, Customer Obsession Teams, Communications Passion   www.voxeo.com © Voxeo Corporation
  • 4. The Change VoIP Brings! SIP SIP Proxy Proxy A SIP B SIP SIP Alice Bob Media (RTP, MSRP, etc.) © Voxeo Corporation
  • 5. The Larger Reality! SIP SIP SIP SIP SIP Proxy Proxy Proxy Proxy Proxy A SIP B SIP C SIP D SIP N SIP Internet SIP Media Media Alice Proxy Proxy Bob Media A Media B Media © Voxeo Corporation
  • 6. Once Upon A Time! PSTN PBX Gateways Physical Voicemail Wiring © Voxeo Corporation
  • 7. 1. Understand Your Ecosystem! Mobile Devices IM Application Internet Servers Networks Operating Systems PSTN IP-PBX VoIP Gateways Web IP Social Firewalls Servers Network Networks Physical Directory Voicemail Wiring Servers Desktop Email PCs Database Servers CRM Servers Systems © Voxeo Corporation
  • 8. 2. Understand Your Endpoints!   IP Phones, Smartphones, Softphones   What services are running on them?   Default passwords?   How do you patch/secure them? © Voxeo Corporation
  • 9. 3. Secure Your Media! SIP SIP SIP Proxy Proxy Proxy A SIP B SIP N SIP SIP Alice Eve Bob Media Media © Voxeo Corporation
  • 10. Secure Media – Hop By Hop! Internet Media Media Alice Proxy Proxy Bob Media A Media B Media © Voxeo Corporation
  • 11. Secure Media – End to End! Internet Media Media Alice Proxy Proxy Bob Media A Media B Media © Voxeo Corporation
  • 12. 4. Secure Your Signalling! SIP SIP SIP Proxy Proxy Eve Proxy A SIP B SIP SIP N SIP SIP Alice Bob Media © Voxeo Corporation
  • 13. Signalling Attacks!   Toll Fraud   Identity Theft © Voxeo Corporation
  • 14. Traditional Telephony! Internet Carrier PSTN PBX Corp  HQ   © Voxeo Corporation
  • 15. IP Communications! ITSP Internet PBX PSTN Corp  HQ   © Voxeo Corporation
  • 16. Failover! PBX ITSP Corp  HQ   Internet PSTN PBX Office   A   © Voxeo Corporation
  • 17. Redundancy / Geography! ITSP (Boston) Internet PBX ITSP (Paris) PSTN Corp  HQ   ITSP (Tokyo) © Voxeo Corporation
  • 18. 5. Secure Your PSTN Connectivity!   Attacks •  Toll Fraud •  Denial of Service •  Spam   Solutions •  Encryption •  Strong Authentication •  Transport Security © Voxeo Corporation
  • 19. 6. Secure Your Identity!   Attacks •  Fraud •  Identity Theft •  Social Engineering   Solutions •  Education •  Lock Down Spoofing •  Strong Identity © Voxeo Corporation
  • 20. 7. Secure Distributed Systems! Laptop UC client WiFi UC System Firewall Internet Café Router Corp  HQ   Mobile Data Network Mobile UC client © Voxeo Corporation
  • 21. How Do You Securely Federate?! Internet Corporate Corporate Network Network UC UC UC UC System System System System Corp  HQ   Office  A   Corp  HQ   Office  A   Company  A   Company  B   © Voxeo Corporation
  • 22. What if the Cloud Isnʼt There?! Corporate Internet Network IVR Voicemail IM IM IM Presence Presence Presence Call Call Call Control Control Control Corp  HQ   Office  A   Office  B   PSTN © Voxeo Corporation
  • 23. Questions About the Cloud!   What kind of availability guarantees / Service Level Agreements (SLAs) does the platform vendor provide?   What kind of geographic redundancy is built into the underlying network?   What kind of network redundancy is built into the underlying network?   What kind of physical redundancy is built into the data centers?   What kind of monitoring does the vendor perform?   What kind of scalability is in the cloud computing platform?   What kind of security, both network and physical, is part of the computing platform?   Finally, what will the vendor do if there is downtime? Will the downtime be reflected in your bill? © Voxeo Corporation
  • 24. The Way It Used To Be! © Voxeo Corporation
  • 25. Today...! ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP PSTN ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP ITSP © Voxeo Corporation
  • 26. Resources!   VoIP Security Alliance •  www.voipsa.org •  www.voipsa.org/blog   Hacking Exposed: VoIP •  www.hackingvoip.com   Seven Deadliest Unified Communications Attacks •  www.7ducattacks.com © Voxeo Corporation