Exceed with COLT. NGN Architectures, VoIP Security and Protocols
|
|
|
- Hortense Morgan
- 10 years ago
- Views:
Transcription
1 Exceed with COLT NGN Architectures, VoIP Security and Protocols UKNOF 5 25/10/06 Neil J. McRae Director of Network Architecture Nico Fischbach Head of Network Security COLT Telecom Group FOR INTERNAL USE ONLY
2 Agenda What is VoIP? VoIP Architectures VoIP Protocols & Security Concerns Questions
3 COLT and VoIP COLT Telecom > Voice, Data and Managed Services, Tier 1 ISP in EU > 14 countries, 60 cities, 50k business customers > km of fibre across Europe + DSL VoIP experience > 3 major vendor directions One we'recomingfromthetdmworld One we'recomingfromtheipworld One we'reavoipcompany > Internet and MPLS VPN-based VoIP services > Own network (fiber + DSL) and wdsl > Going MSPP + VoIP NGN + IMS TDM scaling issues 3
4 What is VoIP? The Customer Viewpoint Computer with softclient ( or Skype) ((( ((( o ))) Hardphone (analog or or Skype) wap (+ ) Internet 4
5 Hosted IP PBX TDM PSTN Voice Switch PRI (ISDN over E1) PBX POTS PBX could be IP-enabled with IP phones on LAN VoIP/ToIP TDM PSTN Voice Switch IP PBX S B C Internet H.323/RTP CPE NAT TDM PSTN Voice Switch IP PBX F W MPLS H.323/RTP CPE No NAT 5
6 PBX Trunking over IP TDM PSTN Voice Switch PRI (ISDN over E1) PBX POTS VoIP/ToIP DTMF Softswitch H.323(/MGCP) 64kUR (PBX Mgmt) TDM PSTN Voice Switch MGCP MGW RTP F W Internet H.323(/MGCP)/RTP PBX CPE No NAT T.38 (FAX) 6
7 Wholesale VoIP TDM PSTN Voice Switch PRI (ISDN over multiple E1s or STM-1s) Voice Switch TDM PSTN POTS VoIP/ToIP Softswitch TDM PSTN Voice Switch MGCP MGW RTP MGW S B C Internet /RTP H.323/RTP Other Carrier VoIP Core 7
8 Softswitch Architecture (Intermediate Architecture) COLT or 3 rd party TDM/SS7 Networks Softswitch (Call Control, Signalling GW, Media GW Control, Subscriber Database and Voice Applications) Media Gateway Session Border Control COLT or 3 rd party IP Network End Users Management and Provisioning End Users > Softswitch: it combines the Call Control, the Signalling Gateway and the Media Gateway Control function. Together with the Media Gateway function it provides signalling and media inter-working with the legacy TDM voice network. The intelligence of the system (call control functionality) as well the customer database resides within the softswitch function. > Session Border Control: it provides secure access control to the customer appliances and mediates between the COLT IMS and any 3rd party IP network > Management and Provisioning: it is an integrated OSS platform that allows end to end provisioning and management across the technology components.
9 IMS Architecture (Target Architecture) IMS Application Layer COLT or 3 rd party TDM/SS7 Networks Interworking with TDM Voice Network Core Call Control Customer Profile Database Session Border Control COLT or 3 rd party IP Network End Users Management and Provisioning End Users > Interworking with TDM Voice Network: it provides signalling and media inter-working with the TDM voice network > Core Call Control: it is a set of enabled devices that control the flow of messages between the customer appliances (IP phones, soft phones, wireless handhelds) and the rest of the IMS components > Customer Profile Database: it contains the user identity and the user service profile, providing session authentication and access to service applications > Session Border Control: it provides secure access control to the customer appliances and mediates between the IMS and any 3rd party IP network > Application Layer: it provides the service logic, with a set of Application Servers dedicated to specific services (eg an IP Centrex AS for telephony services, a Mobility AS for FMC integration, a Messaging AS for unified messaging and presence services) > IMS Management and Provisioning: it is an integrated OSS platform that allows end to end provisioning and management across the IMS technology components.
10 Softswitch Architecture Logical Level 1 2 Direct VoIP Traffic Indirect VoIP Traffic Softswitch Call Control Application Layer 3 Indirect TDM Traffic Media Signalling AA ISUP MGCF SGW Subscriber DB Voice Apps Legacy Apps NGIN 3 rd party TDM/SS7 Networks 3 TDM MGW H.323 / Media Gateway RTP Proxy ALG Session Border Control RTP 3 rd party IP Networks RTP UA H.323 / H.323 /, RTP 2 COLT NGN Transport Network RTP UA H.323 / 1 H.323 / UA ALG MGW MGCF SGW NGIN User Agent Application Layer Gateway Media Gateway Media Gateway Ctrl Function Signalling Gateway Next Gen IN
11 IMS Architecture Logical Level 1 Direct VoIP Traffic 2 3 Indirect VoIP Traffic Indirect TDM Traffic Interworking with TDM Voice Network NGIN AS Application Layer Media Signalling AA 3 rd party TDM/SS7 Networks ISUP 3 PCM SGW MGCF CSCF HSS MGW Diameter Core Call Control Diameter Customer Profile Database RTP Proxy ALG Session Border Control RTP 3 rd party IP Networks, RTP 2 NGN Transport Network RTP UA RTP UA 1 UA I-BGF A-BGF CSCF HSS User Agent I/C-Border Gw Function Access-BGF Call/Session Ctrl Function Home Subscriber Server MGW MGCF SGW AS NGIN Media Gateway Media Gateway Ctrl Function Signalling Gateway Application Server Next Gen IN
12 VoIP Core Network Architecture with Security Billing DB WEB F W H.323/RTP CPE FW IP PBX IP PBX S F B W C IP / MPLS SBC PBX Softswitch MGW MGW F W H.323/MGCP/RTP CPE TDM / PSTN S B C /RTP Internet Carrier MGW H.323/RTP Carrier 12
13 Nortel CS2000 PSTN SS7 Back Office or T IEMS Element Management MG15K H.248 Network Signalling USP LPP M3UA/SCTP CS2000 Voice Services GWC CS LAN IP Network MS2010 MGCP H.248 Lawful Intercept Conferencing Announcements H.248 BCP (RTP Media Portal) NCS Centrex IP Client Manager (CICM) Session Server Lines Cable CMTS Centrex IP Firewall NAT/NAPT UNIStim MGCP H.323 Hosted PBX HF C Video Feed PC Softclient i2004 Etherset Derived Lines xdsl IAD DSLAM CPE IAD PBX Cable Modem
14 Huawei MM - Meeting Conference IP Centrex GTAS9900 GTAS MM - PS Presence MM - Messaging IM imanagern2000 NMS HSS9820 HSS Application Layer CSC3300 BGCF CSC3300 P-CSCF Session Control Layer CSC3300 S-CSCF CSC3300 I-CSCF SoftX3000 AGCF/MGCF/MGC MRS6200 MRF SE2000 SBC SG7000 SG icg9815 CCF Other Carrier Managed IP Core SS7 H.323 UMG8900 MGW IAD IP-PBX IAD IP-PBX PRI E1 SS7 IP-Phone IP-Phone PBX Access Layer PSTN
15 Alcatel DPNSS Gateway X 10 UK Only 8628 MMIC App Server X OSP App Server 8640CMM LNP X CCCS X CMC X MGC X SLS X CSC X 7 Convedia Media Server X LI X 1 75xx TGW 7510 = = 10 Access Border Gateway X 339 total Intercept Manager X 1 per country In-Country SITE X 5 per country QSIG Gateway(s)
16 Ericsson PBX EAR Access Gateway Control Function (AGCF) TDM V5.2 Q.931 RSS IUA Feature Server TeS AGC H.248 (AGW) TDM SCP Telephony Softswitch PSTN/ISDN Emulation Service H.248 MGW IMS control HSS Diameter CSCF Presence Server MRFC MRFP ISC ~ H.248 IP Centrex Broadband telephony Feature Server MPLS/ IP PBN Telephony RTP / H.323 Media Gateway Control Function (MGCF) TeS Telephony MGC/ Softswitch SGW H.248 MGW ISUP CCS PSTN MSAN RTP D S L Broadband access Router/ BRAS A-SBG RTP N-SBG /H.323 VoIP IAD +RTP
17 Cisco Application Server ISC Billing & Measurement ITPITP COLT STP Presence Engine HSS Cx Sh CSCP-SE PGW MGW COLT PSTN SBC FWSM -T MGCP MGCP /H.323 Interconnect Carrier Reseller CSCP-EP / H.323 IP PBX COLT IP PBX BRI PRI BRI Q.SIG PRI DPNSS end-devices Carrier VoIP Service COLT VoIP Reseller COLT Voice Gateway COLT IP-PBX COLT Total COLT Voice Integrate
18 Lucent Beyond Other Applications Colibria Kodiak Polycom. Lucent Communication Manager Lucent Presence Server Lucent AnyPath Lucent FS 3000 USDS / DF HSS, HLR, AAA VitalQIP DNS / ENUM, DHCP SurePay CCF, OCS Audiocodes IPMedia 2000 Legacy PBX Working Alternative Media Server Lucent SM PRI Lucent CS Gateway S-CSCF I-CSCF P-CSCF S/BC IADs, ATAs, Hard and Soft Phones BGCF Access Network IAD IP Core Acme Packets Acme Packet Net-Net SD H.323 Lucent NC MGCF SGF H.323 IP PBX INAP ETSI ISUP v2 (M2UA) Lucent MG NG E1 IMT STP ETSI ISUP v2 Existing COLT TDM Switch PTT SCP
19 Sonus IMX Open Applications Server/ Broker OSPA Enhanced Services SonusInsight Management System Provisioning, Billing and Monitoring GSX9000 Open Services Switch PSTN/ PLMN GSX9000 Network Border Switching Function Packet Network GSX4000 Open Services Switch PSTN/ PLMN Packet Network PSX - Routing Server SGX - Signaling Gateway ASX VoBB Access Class 5 Services Packet Network
20 VoIP Protocols H.323 > ITU, ASN.1, CPE/Phone<->Gatekeeper > H.225/RAS (1719/UDP) for registration > H.225/Q.931 (1720/TCP) for call setup > H.245 (>1024/TCP or over call setup channel) for call management MGCP (Media Gateway Control Protocol) > IETF, Softswitch (CallAgent)<->MGW > CallAgents->MGW (2427/UDP) > MGW->CallAgents (2727/UDP) > Used to control MGWs > AoC (Advice Of Charge) towards CPE - ** 20
21 >IETF, HTTP-like >Session based Does anyone here not know what is? :D RTP VoIP Protocols >Media stream (one or one per direction) >CODECs (G.711{a,u}, G.726, G.729(a)) >RTCP: control protocol for RTP >SRTP: Secure RTP (w/ MiKEY) >Often /UDP or default NAT range, but can be any UDP>1024 >Can be UA<->UAaka FreIntersite or UA<->MGW<- >UA 21
22 H.323 versus > The majority of current COLT VoIP products is based on H.323 > This is mainly owing to missing functionality on > Questionable interoperability and scalability concerns still exist though (10s of billions of minutes) > not expected to completely replace H.323 in the mid/long term. > Protocols are somewhat complementary- no religion here though! > More detail on the differences > and more insight on understanding of our direction at: > > This is expected to change over time
23 Session Border Controller What the role of an SBC? >Security >Hosted NAT traversal (correct signalling / IP header) >Signalling conversion >Media Conversion >Stateful RTP pin-holing based on signalling Can be located at different interfaces: Customer/Provider, inside customer LAN, Provider/Provider (VoIP peering) What can be done on a FW with ALGs? What can be done on the end-system? Is there a need for a VoIP NIDS (especially with -TLS)? 23
24 VoIP Hardware Mix of software and hardware (mostly DSPs) >Softswitch: usually only signalling >MGW (Media Gateway): RTP<->TDM, SS7oIP<->SS7 >IP-PBX: Softswitch+MGW Operating systems >Real-time OSes (QNX/Neutrino, VxWorks, RTLinux) >Windows >Linux, Solaris Poor OS hardening Patch management: >OSes not up-to-date >Not alowed topatchthem 24
25 Security Challenges VoIP protocols >No, VoIP isn't just > is a driver for IMS services and cheap CPEs >H.323 and MGCP (still) rock the carrier world Security issues >VoIP dialects >Only a couple of OEM VoIP stacks (think x-vendor vulnerabilities) >FWs / SBCs: do they solve issues or introduce complexity? >Are we creating backdoors into customer networks? >CPS and QoS 25
26 One more backdoor? «Executive floor» WLAN AP «IT floor» Internet access ap r fw r cpe s r External laptop r Internet cpe s r s fw av as p Corporate Internet access Remote maintenance CPE Vendor Office ar Remote office/ Partners IP VPN Partner VoIP IP PBX Shared TFTPd Customer B Customer C 26
27 VoIP Dialects No way to firewall / ACL (especially if non-stateful) based on protocol inspection Vendors who never heard of timeouts and don't send keep-alives Result : > Clueful: Permit UDP <port range> <identified systems> > Half clueful: Permit UDP <port>1024> any > Clueless: Permit UDP any any End-result: > 0wn3d via exposed UDP services on COTS systems > Who needs RPC services (>1024/UDP)? 27
28 >Re-use existing solutions: TDM break-out >Install a sniffer (signalling & media stream) >Re-route calls (but hide it in the signalling) >Eavesdropping not a real threat (own network) >Enterprise network : Needs to be a part of a global security strategy How many have this? Clear text Clear text protocols (HTTP, Telnet, etc) VoIP Etc Lawful Intercept >VoIP over WLAN easy. 28
29 Phones and Terminals IP Phones Reliability > Quite easy to crash (weak TCP/IP stacks and buggy software implementation) > Mostly an insider threat How clueful is your cleaner? DHCP server TFTP server (phone configuration) Credentials (login + PIN) Fraud issues. VoIP doesn't mean that you need to move to IP Phones > PBX with E1 (PRI/BRI) to router and then VoIP > PBX with IP interface towards the outside world (but do you really want to put your PBX on the Internet)? > Means that you have to maintain two separate networks, but solves theqos issues on a LAN > What about soft clients?! All the usual Unix/Windows issues. 29
30 Denial of Service Generic DDoS > Not a real issue, you can't talk to our VoIP Core ACLs are complex to maintain use edge-only BGP blackholing > We are used to deal with large DDoS attacks :) DoS that are more of an issue > Generated by customers: not too difficult to trace (IT Clue) > Protocol layer DoS : H.323 / MGCP / signalling Replace CPE / use soft-client Inject crap in the in-band signalling (MGCP commands, weird H.323 TPKTs, etc) Get the state machine of the inspection engine either confused or in a block-state,ifluckyforthe server addresesandnotthe clients Vendors not really thinking about this. 30
31 Security Challenges Online services >Call Management (operator console) >IN routing (Fraud potential) >Reporting / CDRs Security issues >Multi-tenant capabilities >Have the vendors ever heard of web application security? >Who needs security or lawful intercept if a kid can route your voice traffic via SQL injection WebApp FWs are really required... 31
32 Security Challenges TDM / VoIP : two worlds, two realms, becoming one? >Securityby obscurity /complexityvs the IP world >Fraud detection Security issues >New attack surface for legacy TDM/PSTN networks >No security features in old Class4/Class5 equipment >No forensics capabilities, no mapping to physical line >Spoofing and forging >People: Voice Engineers vs Data Engineers vs Security engineers. Engineering vs Operations. Marketing vs Engineering. Conflicts and Time-to-Market 32
33 Operational Concerns VoIP is damn complex Only way to debug most of the issues: VoiceEng + IP/DataEng + SecurityEng on a bridge/online chat Requirement: be able to sniff all traffic Tool: Ethereal/Wireshark Attacker: Just use any of the protocol decoder flaw in the sniffer Make sure your sniffers are on R/O SPAN ports, in a DMZ which only allows in-bound VNC/SSH Do not underestimate the effort on a multi Country setup What is EU?! If the guy is really good and can upload a rootkit over RTP: get his CV and offer him a job you need this guy serious skills shortage 33
34 VoIP Carrier Interconnect Aka VoIPpering /Carierinterconnect Already in place (TDM connectivity for VoIP carriers/skype{in, Out}) Connectivity: over the Internet, IX (public/private), MPLS VPN or VPLS (Ethernet) No end-to-end MPLS VPN, break the VPN and use an IP-IP interface Hide your infrastructure (topology hiding), use {white, black}listing and make sure only the other carrier can talk to you Signalling/Media conversion (SBC) Remember thisisn twebtrafic its termination money in both directions! 34
35 Encryption / Authentication Do we want to introduce it? VendorX: Wearecompliant.Sure. VendorY: It'sonourroadmap.Q1Y31337? VendorZ: Whydoyounedthis?.Hmmmm... IPsec from CPE to VoIP core >Doable (recent HW with CPU or crypto card) >What about CPE<->CPE RTP? >Still within RTT / echo-cancellation window May actually do mobile device<- IPsec ->VoIP core >Bad guys can only attack the VPN concentrators >No impact on directly connected customers Still reliability issues in vendor implementations 35
36 IMS Security The Future IMS = IP Multimedia Subsystem Remember when the mobile operators built their WAP and 3G networks? >Mostly open (akaterminalistrusted) >Evenconnectedwiththeir internal /ITnetwork IMS services with MVNOs, 3G/4G: overly complex architecture with tons of interfaces Large attack surface: registration/tracking servers, application servers, etc Firewalling: complex if not impossible Next thing to try: Attack Fixed<->Mobile handover (GSM<- >WiFi) 36
37 Questions? 37
How To Make A Phone Call From A Cell Phone (Torm) To A Landline (Telnet) (Telcom) (Ipo) (Turbo) Or A Cellphone (Ip) (Phone) (Net) Or
Carrier VoIP Security Nicolas FISCHBACH Senior Manager, Network Engineering Security, COLT Telecom [email protected] - http://www.securite.org/nico/ v1.1 COLT and VoIP COLT Telecom Voice, Data and Managed
Carrier VoIP Security
Carrier VoIP Security Nicolas FISCHBACH Senior Manager, Network Engineering Security, COLT Telecom [email protected] - http://www.securite.org/nico/ COLT and VoIP COLT Telecom Voice, Data and Managed Services,
NGN Interconnection Standards & Protocols
NGN Interconnection Standards & Protocols A G E N D A NGN ENVIRONMENT LICENSING CONDITIONS REGULATORY INITIATIVES INTERCONNECTION PROTOCOLS ISSUES R. R. Mittar DDG(NGN), TEC NGN CONCEPT Central Office
VoIP trends in Fixed Network Operators
VoIP trends in Fixed Network Operators Petros Sarantopoulos Carrier Networks Control SIEMENS GREECE Agenda Standardization MSFORUM / ETSI TISPAN Towards Class-5 VoIP Future trends ETSI NGN Overview Standardization
Session Border Controllers in Enterprise
A Light Reading Webinar Session Border Controllers in Enterprise Thursday, October 7, 2010 Hosted by Jim Hodges Senior Analyst Heavy Reading Sponsored by: Speakers Natasha Tamaskar VP Product Marketing
COPYRIGHTED MATERIAL. Contents. Foreword. Acknowledgments
Contents Foreword Preface Acknowledgments 1 Introduction 1 1.1 Motivation for Network Convergence 1 1.2 The Core Network 2 1.3 Legacy Service Requirements 4 1.4 New Service Requirements 5 1.5 Architectures
NGN Next Generation Nightmare? What telco 2.0 really means
NGN Next Generation Nightmare? What telco 2.0 really means Nicolas FISCHBACH Senior Manager, Network Engineering Security, COLT Telecom [email protected] - http://www.securite.org/nico/ Internet-wide Security
IP Multimedia Subsystem (IMS) Service Architecture
IP Multimedia Subsystem (IMS) Service Architecture Supports multiple applications by providing traditional telephony and non-telephony services Cost savings and revenue generating capabilities are driving
VoIP Services. Maurice Duault [email protected]. 2001, Cisco Systems, Inc. All rights reserved.
VoIP Services Maurice Duault [email protected] 2001, Cisco Systems, Inc. All rights reserved. 1 Agenda Distributed Softswitch Residential Business VoIP access Multiservice over VPN Managed IP Telephony
SIP Trunking Configuration with
SIP Trunking Configuration with Microsoft Office Communication Server 2007 R2 A Dell Technical White Paper End-to-End Solutions Team Dell Product Group - Enterprise THIS WHITE PAPER IS FOR INFORMATIONAL
Acme Packet Net-Net SIP Multimedia-Xpress
Acme Packet Net-Net SIP Overview Net-Net SIP (SMX) combines IP Multimedia Subsystem (IMS) session management with leading session border control (SBC) functions to reduce the complexity and cost of delivering
Recommended IP Telephony Architecture
Report Number: I332-009R-2006 Recommended IP Telephony Architecture Systems and Network Attack Center (SNAC) Updated: 1 May 2006 Version 1.0 [email protected] This Page Intentionally Left Blank ii Warnings
SangomaSBCs Keeping Your VoIP Network Secure. Simon Horton Sangoma [email protected]
SangomaSBCs Keeping Your VoIP Network Secure Simon Horton Sangoma [email protected] Inside this Deck About Sangoma/ProVu SIP Market SBCs Demystified Business Applications and Use Cases Portfolio of SBCs
VIDEO IVR VAS & Customer Care
Marketing Overview Plan Overview VIDEO IVR VAS & Customer Care January 26, 2011 April 2010 xx, APEX 2010 Voice / Page Communications, 1 Inc. All rights reserved. Marketing Who Plan is APEX? Overview VIDEO
SBC WHITE PAPER. The Critical Component
SBC WHITE PAPER The Critical Component Table of Contents of your VoIP Infrastructure... 3 Enter the SBC... 4 Functions... 5 Security... 5 Denial of Service... 5 Toll Fraud... 6 Encryption... 6 Policy...
OpenScape Session Border Controller Delivering security, interoperability and cost savings to the enterprise network border
Siemens Enterprise Communications Session Border Controller Delivering security, interoperability and cost savings to the enterprise network border April 2011 Agenda 1 Industry Trends 2 Customer Initiatives
IMS Services Introduction
IMS Services Introduction www.huawei.com References 3GPP TS 23.002: Network architecture 3GPP TS 23.218: IP Multimedia (IM) session handling; IM call model 3GPP TS 23.228: IP Multimedia Subsystem (IMS);
SIP Trunking Steps to Success, Part One: Key Lessons from IT Managers Who ve Been There
SIP Trunking Steps to Success, Part One: Key Lessons from IT Managers Who ve Been There Q&A Session Date: Wednesday, April 13, 2011 Q: You have to partner with a provider in order to do SIP trunking, correct?
SIP Trunking with Microsoft Office Communication Server 2007 R2
SIP Trunking with Microsoft Office Communication Server 2007 R2 A Dell Technical White Paper By Farrukh Noman Dell Product Group - Enterprise THIS WHITE PAPER IS FOR INFORMATIONAL PURPOSES ONLY, AND MAY
Architectural Overview of IP Multimedia Subsystem -IMS
Architectural Overview of IP Multimedia Subsystem -IMS Presented by: Masood Khosroshahy June 2006 B E G I N N I N G 1 Project supervisor: Prof. Elie Najm Simplified view of the layered architecture in
How To Support An Ip Trunking Service
Small Logo SIP Trunking: Deployment Considerations at the Network Edge at the Network Edge Executive Summary The move to Voice over IP (VoIP) and Fax over IP (FoIP) in the enterprise has, until relatively
IMS & Triple Play Services Architecture
IMS & Triple Play Services Architecture Brian Mahony, VP Marketing Guillaume Widmer, CTO Triple Play Symposium, September 2005 2005 Netcentrex S.A. All rights reserved. Netcentrex S.A. Proprietary Information.
Alcatel-Lucent 1300 Convergent Network Management Center OPEX REDUCTION THROUGH INTEGRATED NETWORK MANAGEMENT
Alcatel-Lucent 1300 Convergent Network Management Center OPEX REDUCTION THROUGH INTEGRATED NETWORK MANAGEMENT The Alcatel-Lucent 1300 Convergent Network Management Center (CMC) provides cost-effective
CompTIA Convergence+ 2006 Examination Objectives
CompTIA Convergence+ 2006 Examination Objectives Introduction The CompTIA Convergence+ examination covering the 2006 objectives certifies that the successful candidate has the necessary knowledge to perform
Advanced SIP Series: SIP and 3GPP
Advanced SIP Series: SIP and 3GPP, Award Solutions, Inc Abstract The Session Initiation Protocol has been selected as the main signaling protocol of the Third Generation Partnership Projects IP Multimedia
Dialogic BorderNet Session Border Controller Solutions
Dialogic BorderNet Session Border Controller Solutions Dialogic BorderNet Session Border Controllers Transform, Connect and Secure Today s Networks and Services Dialogic BorderNet Session Border Controller
Best Practices for Securing IP Telephony
Best Practices for Securing IP Telephony Irwin Lazar, CISSP Senior Analyst Burton Group Agenda VoIP overview VoIP risks Mitigation strategies Recommendations VoIP Overview Hosted by VoIP Functional Diagram
THE REFERENCE OF VOICE SWITCHING PLATFORM FOR MASSIVE VOIP DEPLOYMENTS, PSTN REPLACEMENT, AND MIGRATION TO IMS CIRPACK SOFTSWITCH
THE REFERENCE OF VOICE SWITCHING PLATFORM FOR MASSIVE VOIP DEPLOYMENTS, PSTN REPLACEMENT, AND MIGRATION TO IMS CIRPACK SOFTSWITCH Carrier-grade Voice Switching The NextGen Way The Cirpack Softswitch platform
PARAMETERS TO BE MONITORED IN THE PROCESS OF OPERATION WHEN IMPLEMENTING NGN TECHNICAL MEANS IN PUBLIC TELECOMMUNICATION NETWORKS
Draft Recommendation Q.3902 PARAMETERS TO BE MONITORED IN THE PROCESS OF OPERATION WHEN IMPLEMENTING NGN TECHNICAL MEANS IN PUBLIC TELECOMMUNICATION NETWORKS Summary This Recommendation describes the main
Technology Training Limited Module Portfolio for Customised Courses
Technology Training Limited Module Portfolio for Customised Courses E-mail: [email protected] website: www.technology-training.co.uk Module Catalogue v1.3 Page 1 of 17 CONTENTS LIST 1 ACCESS
Juha Heinänen [email protected]
From Voice over IP to Voice over Internet Juha Heinänen [email protected] From VoIP to VoINET VoIP replaced wires in PBX and PSTN backbones with IP preserves the traditional, centralized telephony service
APPLICATION NOTE. SIP Trunking Connectivity, Security and Deployment Scenarios. Introduction
SIP Trunking Connectivity, Security and Deployment Scenarios Introduction Enterprises have traditionally based their voice communications on an in-premises telephony switch the PBX. Until recently, the
Welltel - Session Border Controller SBC 120
SBC 120 Appliance Welltel - Session Border Controller SBC 120 enhanced performance, increased security Welltel s Session Border Controllers (SBCs) help enterprises to reduce communications costs, enable
IP Multimedia System: general aspects and migration perspectives
IMS TPC EPC IP Multimedia System: general aspects and migration perspectives Dr. Leo Lehmann Federal Office of Communication, Switzerland ITU Workshop on Developments regarding telecommunication network
Acme Packet session border controllers in the enterprise
Acme Packet session border controllers in the enterprise Large enterprises have been expanding their deployments of IP telephony (IPT) for several years now. Planning has already begun to extend the benefits
Interactive communications over IP networks
How many times have you heard "IP networks don't make any money!" Probably way too many! Compared to the PSTN, IP networks are big zeroes in terms of financial appeal. Today, while data consumes more than
Dialogic. BorderNet Products Interwork and Connect Seamlessly and Securely at the Network Edge
Dialogic BorderNet Products Interwork and Connect Seamlessly and Securely at the Network Edge Versatile Dialogic BorderNet Products Handle Network Transitions for Today s Critical Services and Solutions
OfficeMaster Gate (Virtual) Enterprise Session Border Controller for Microsoft Lync Server. Quick Start Guide
OfficeMaster Gate (Virtual) Enterprise Session Border Controller for Microsoft Lync Server Quick Start Guide October 2013 Copyright and Legal Notice. All rights reserved. No part of this document may be
Hosted PBX Platform-asa-Service. Offering
Hosted PBX Platform-asa-Service Offering Hosted PBX Platform Overview VoIP Logic s Hosted PBX Platform-as-a-Service (PaaS) delivers cloud-based PBX functionality encompassing traditional PBX features as
MED: Voice over IP systems
www.ptt.co.uk Online course specification MED: Voice over IP systems Target audience: This online course is designed for those who will be responsible for the design or maintenance of Voice over IP (VoIP)
Voice over IP Security
Voice over IP Security Patrick Park Cisco Press Cisco Press 800 East 96th Street Indianapolis, Indiana 46240 USA vii Contents Introduction xvii Part I VoIP Security Fundamentals 3 Chapter 1 Working with
UC and SIP Trunking Luncheon. Sponsored by:
UC and SIP Trunking Luncheon Sponsored by: Speakers and Agenda Topic Presenter Opening comments, introductions and Jeff Neikirk (Verizon) market updates Verizon Managed Services for Enterprise Brent Carter
Voice over IP Basics for IT Technicians
Voice over IP Basics for IT Technicians White Paper Executive summary The IP phone is coming or has arrived on desk near you. The IP phone is not a PC, but does have a number of hardware and software elements
Voice Over Internet Protocol (VoIP) Issues and Challenges William McCrum [email protected]
Voice Over Internet Protocol (VoIP) Issues and Challenges William McCrum Phone: +1 613-990-4493 Fax: Email: +1 613-957-8845 [email protected] Content Network Evolution and drivers VoIP Realizations
CPNI VIEWPOINT 03/2007 HOSTED VOICE OVER IP
HOSTED VOICE OVER IP AUGUST 2007 Abstract Voice over IP (VoIP) is the term used for a set of technologies that enable real time voice or video conversations to take place across IP networks. VoIP devices
802.1p An IEEE standard for providing QoS using three bits (defined in 802.1q) to allow switches to reorder packets based on priority level.
Glossary and Terms 802.1p An IEEE standard for providing QoS using three bits (defined in 802.1q) to allow switches to reorder packets based on priority level. 802.1q An IEEE standard for providing virtual
IMS Architecture and Network Convergence
IMS Architecture and Network Convergence Larry O Pella Director, Fixed-Mobile Convergence Alcatel ATIS NGN-FocusGroup Viewpoint One picture is worth ten thousand words - Frederick Barnard 2 Framework for
Application Note VoIP in the Hospitality Market Powered by AudioCodes Media Gateways The Challenge Recent developments in technology and telecom have touched all aspects of life, and all global markets.
Hosted PBX Description General Info about Hosted PBX
Hosted PBX Description General Info about Hosted PBX Version Control Revision Date Name 2.0 12/12/2012 Operations 2.1 6/14/2013 Sales & Marketing Product Information Sales & Marketing VoIP Logic LLC, 529
Building Service-driven NGN
Building Service-driven NGN Agenda NGN Overview Commercial Cases Total Solution Product Family Current Communication Networks: network-based & device-oriented Network/service provider Subscriber Close
IMS Interconnect: Peering, Roaming and Security Part One
T E C H N O L O G Y W H I T E P A P E R IMS Interconnect: Peering, Roaming and Security Part One IMS interconnection promises to enable greater reach and richer offerings for the providers that establish
Cisco Introduces Broad Support for SIP across Packet Voice Products
Cisco Introduces Broad Support for SIP across Packet Voice Products External Presentation Session Number 1 Endpoints with voice driving converged IP infrastructure Voice Portals PDA Unified Messaging PC
SS7 & LTE Stack Attack
SS7 & LTE Stack Attack Ankit Gupta Black Hat USA 2013 [email protected] Introduction With the evolution of IP network, Telecom Industries are using it as their core mode of communication for their network
The Evolution of Session Border Control
The Evolution of Session Border Control The Early Days of SBC Session Border Controllers (SBCs) originated as discrete devices in an IP network to provide two key functions: connectivity and security.
VoIP from A to Z. NAEO 2009 Conference Cancun, Mexico
VoIP from A to Z NAEO 2009 Conference Cancun, Mexico VoIP glossary What is VoIP? Bandwidth Signaling Codecs Quality of Service (QoS) What is VoIP? Voice over Internet Protocol (VoIP) is the method of transmitting
Ram Dantu. VOIP: Are We Secured?
Ram Dantu Professor, Computer Science and Engineering Director, Center for Information and Computer Security University of North Texas [email protected] www.cse.unt.edu/~rdantu VOIP: Are We Secured? 04/09/2012
S-Series SBC Interconnect Solutions. A GENBAND Application Note May 2009
S-Series SBC Interconnect Solutions A GENBAND Application Note May 2009 Business Requirements A ubiquitous global voice service offering is the challenge among today s large service providers. The need
VoIP Security regarding the Open Source Software Asterisk
Cybernetics and Information Technologies, Systems and Applications (CITSA) 2008 VoIP Security regarding the Open Source Software Asterisk Prof. Dr.-Ing. Kai-Oliver Detken Company: DECOIT GmbH URL: http://www.decoit.de
Securing SIP Trunks APPLICATION NOTE. www.sipera.com
APPLICATION NOTE Securing SIP Trunks SIP Trunks are offered by Internet Telephony Service Providers (ITSPs) to connect an enterprise s IP PBX to the traditional Public Switched Telephone Network (PSTN)
SIP Trunking and Voice over IP
SIP Trunking and Voice over IP Agenda What is SIP Trunking? SIP Signaling How is Voice encoded and transported? What are the Voice over IP Impairments? How is Voice Quality measured? VoIP Technology Confidential
Release the full potential of your Cisco Call Manager with Ingate Systems
Release the full potential of your Cisco Call Manager with Ingate Systems -Save cost with flexible connection to Service Providers. -Save mobile costs, give VoIP mobility to your workforce. -Setup an effective
Table of Content. Introduction Components Architectural Characteristics Concepts Protocols Service Examples Discussion. ToC
Danar Barzanji Marcel K Steffen Roger Trösch 22.06.2006 Communication Systems IMS www.packetizer.com Table of Content Introduction Components Architectural Characteristics Concepts Protocols Service Examples
VOICE OVER IP SECURITY
VOICE OVER IP SECURITY February 2008 The Government of the Hong Kong Special Administrative Region The contents of this document remain the property of, and may not be reproduced in whole or in part without
EarthLink Business SIP Trunking. ININ IC3 IP PBX Customer Configuration Guide
EarthLink Business SIP Trunking ININ IC3 IP PBX Customer Configuration Guide Publication History First Release: Version 1.0 August 30, 2011 CHANGE HISTORY Version Date Change Details Changed By 1.0 8/30/2011
Fixed versus Mobile Turning Convergence into Reality. Dieter Schuler, Wouter Franx Lucent Technologies
Fixed versus Mobile Turning Convergence into Reality Dieter Schuler, Wouter Franx Lucent Technologies Agenda Fixed Mobile Convergence Service Definition Operator Challenges IP Multimedia Subsystem the
Application Notes. Introduction. Contents. Managing IP Centrex & Hosted PBX Services. Series. VoIP Performance Management. Overview.
Title Series Managing IP Centrex & Hosted PBX Services Date July 2004 VoIP Performance Management Contents Introduction... 1 Quality Management & IP Centrex Service... 2 The New VoIP Performance Management
SBC 1000/2000 Configuration Guide with Lync 2013 for Windstream/ LPAETEC SIP Trunk Deployments
SBC 1000/2000 Configuration Guide with Lync 2013 for Windstream/ LPAETEC SIP Trunk Deployments Application Notes Rev. 1.0 Last Updated: April 10, 2015 Revision Date Revised By Comments 0.1 12/03/2015 Roman
com.sat IP Basic ISDN
com.sat IP Basic ISDN com.sat Multichannel Gateway 1 2009 com.sat GmbH Kommunikationssysteme Schwetzinger Str. 19 D-68519 Viernheim www.comsat.de Tel: +49-(0)6204-7050-0 1. General Overview IP BASIC ISDN:
Broadband Telephony. Terminal Equipment Requirements and Specifications
Broadband Telephony Terminal Equipment Requirements and Specifications TABLE OF CONTENTS 1 Introduction... 3 1.1 Scope... 3 1.2 Intended audience... 3 1.3 Notice... 3 1.4 Definitions... 3 2 BBT Service
Convergence Technologies Professional (CTP) Course 1: Data Networking
Convergence Technologies Professional (CTP) Course 1: Data Networking The Data Networking course teaches you the fundamentals of networking. Through hands-on training, you will learn the vendor-independent
Voice over IP (VoIP) Basics for IT Technicians
Voice over IP (VoIP) Basics for IT Technicians VoIP brings a new environment to the network technician that requires expanded knowledge and tools to deploy and troubleshoot IP phones. This paper provides
Curso de Telefonía IP para el MTC. Sesión 1 Introducción. Mg. Antonio Ocampo Zúñiga
Curso de Telefonía IP para el MTC Sesión 1 Introducción Mg. Antonio Ocampo Zúñiga Conceptos Generales VoIP Essentials Family of technologies Carries voice calls over an IP network VoIP services convert
ABC SBC: Securing the PBX. FRAFOS GmbH
ABC SBC: Securing the PBX FRAFOS GmbH Introduction A widely reported fraud scenarios is the case of a malicious user detecting the address of a company s PBX and accessing that PBX directly. Once the attacker
Presented by: John Downing, B.Eng, MBA, P.Eng
Presented by: John Downing, B.Eng, MBA, P.Eng John Downing co-founder of TrainingCity. VoIP Training Development Lead. VoIP & SIP Consultant to Telecom & Enterprise Clients. [email protected] 613-435-1170
Presenter. Zane Ryan. Director Dot Force [email protected] www.dotforce.co.uk
Presenter Zane Ryan Director Dot Force [email protected] www.dotforce.co.uk Ingate Systems Headquarters in Stockholm, Sweden North American subsidiary in New Hampshire Long Island, New York San
Ingate Firewall/SIParator SIP Security for the Enterprise
Ingate Firewall/SIParator SIP Security for the Enterprise Ingate Systems February, 2013 Ingate Systems AB (publ) Tel: +46 8 600 77 50 BACKGROUND... 1 1 NETWORK SECURITY... 2 2 WHY IS VOIP SECURITY IMPORTANT?...
Colt VoIP Access. 2010 Colt Technology Services Group Limited. All rights reserved.
Colt VoIP Access 2010 Colt Technology Services Group Limited. All rights reserved. Business requirements Are you looking for ways to simplify management of national or even international voice services
Session Border Controller
Session Border Controller SBC OVERVIEW: Media Routes SBC is an advanced, comprehensive Policy enforcement point, Session Management and Service Orchestration engine deployed as a network border element
PETER CUTLER SCOTT PAGE. November 15, 2011
Future of Fax: SIP Trunking PETER CUTLER SCOTT PAGE November 15, 2011 QUESTIONS AND ANSWERS TODAY S SPEAKERS Peter Cutler Vice President of Sales Instant InfoSystems Scott Page Subject Matter Expert Dialogic
How to Effectively Transition to VoIP and IMS Big Bang or Phased Approach?
S T R A T E G I C W H I T E P A P E R How to Effectively Transition to VoIP and IMS Big Bang or Phased Approach? In order to bolster faltering revenue streams and fend off competition from both their traditional
Convergence & Disaggregation in Telecommunications
Convergence & Disaggregation in Telecommunications Stuart Elby VP Network Architecture [email protected] February 11, 2005 Disaggregation Advances in coding enable common abstractions for voice,
Proximus can't be held responsible for any damages due to the use of an outdated version of this specification.
This specification describes the situation of the Proximus network and services. It will be subject to modifications for corrections or when the network or the services will be modified. Please take into
Brochure. Dialogic BorderNet Session Border Controller Solutions
Brochure Dialogic BorderNet Solutions Supercharge Connections between Networks, Services and Subscribers with Ease and Scale The BorderNet family of session border controllers (SBCs) from Dialogic helps
Hands on VoIP. Content. Tel +44 (0) 845 057 0176 [email protected]. Introduction
Introduction This 4-day course offers a practical introduction to 'hands on' VoIP engineering. Voice over IP promises to reduce your telephony costs and provides unique opportunities for integrating voice
VIDEOCONFERENCING. Video class
VIDEOCONFERENCING Video class Introduction What is videoconferencing? Real time voice and video communications among multiple participants The past Channelized, Expensive H.320 suite and earlier schemes
NGN Functional Architecture for Resource Allocation and Admission Control
NGN Functional Architecture for Resource Allocation and Admission Control 1 Hassan Yeganeh, 2 Maryam Shakiba, and 3 Amir hassan Darvishan Iran Telecommunication Research Center 1 [email protected], 2
This specification this document to get an official version of this User Network Interface Specification
This specification describes the situation of the Proximus network and services. It will be subject to modifications for corrections or when the network or the services will be modified. Please take into
Advanced SIP Series: SIP and 3GPP Operations
Advanced S Series: S and 3GPP Operations, Award Solutions, Inc Abstract The Session Initiation Protocol has been chosen by the 3GPP for establishing multimedia sessions in UMTS Release 5 (R5) networks.
Session Border Controller and IP Multimedia Standards. Mika Lehtinen [email protected]
Session Border Controller and IP Multimedia Standards Mika Lehtinen [email protected] December 1, 2005 Contents Introduction Motivation Research problem Research method Results Conclusion December
Firewall-Friendly VoIP Secure Gateway and VoIP Security Issues
Firewall-Friendly VoIP Secure Gateway and VoIP Security Issues v Noriyuki Fukuyama v Shingo Fujimoto v Masahiko Takenaka (Manuscript received September 26, 2003) IP telephony services using VoIP (Voice
