the state of voip security, a.k.a. “does anyone really give a _____ about voip security?"

85
The State Of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?” Dan York, CISSP Chair, VoIP Security Alliance October 5, 2011

Upload: dan-york

Post on 22-Nov-2014

5.451 views

Category:

Technology


0 download

DESCRIPTION

Does anyone really care about VoIP security? Why should they? What are the main issues? At the 2011 Real-Time Communications Conference sponsored by the Illinois Institute of Technology (IIT), Dan York spoke about all these questions and gave a view of the overall state of the industry. A video recording of the Oct 5, 2011, session will be available and will be able to be found at http://www.voipsa.org/blog/ when it is ready.

TRANSCRIPT

Page 1: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

The State Of VoIP Security, a.k.a.��

“Does Anyone Really Give A _____ About VoIP Security?”

Dan York, CISSP�Chair, VoIP Security Alliance

October 5, 2011

Page 2: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA http://www.flickr.com/photos/willpate/46488553/

Page 3: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Does Anyone Really �Give A _____ About�

VoIP Security?

Page 4: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Does Anyone Really �Give A _____ About�

VoIP Unified Communications Security?

Page 5: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Technical Solutions

Page 6: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Widely Deployed

Page 7: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

TLS-Encrypted SIP

Page 8: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Secure RTP (SRTP)

Page 9: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

MORE Secure�Than PSTN

Page 10: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA http://www.flickr.com/photos/mattblaze/2275723713/

Page 11: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

MORE Secure�Than Ever Before

Page 12: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Almost All Venders�Have Support

Page 13: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Almost All Customers�Don’t Turn It On

Page 14: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Why Not?

Page 15: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Complexity

Page 16: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

PBX

Voicemail Physical Wiring

PSTN Gateways

Fingerpointing, a.k.a. “One Throat To Choke”

Page 17: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Physical Wiring

IP Network

IP-PBX

Voicemail

PSTN Gateways

Mobile Devices

IM Networks

Web Servers

Email Servers

Desktop PCs

Operating Systems

Firewalls

Internet

Directory Servers

VoIP

CRM Systems

Social Networks

Database Servers

Application Servers

Fingerpointing - 2011

Session Border

Controllers

Page 18: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

“UC”

Page 19: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Debugging

Page 20: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Turn It Back On?

Page 21: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

SIP Is So Simple, Right?

Page 22: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Riiiiiigggghhhttt… (Fingerpointing Redux)

Page 23: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Evolution

Page 24: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Carrier

PSTN

Carrier

Carrier Carrier

Carrier

Carrier Carrier

The Old Boys’ Club

Page 25: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA © 2010 VOIPSA and Owners as Marked

ITSP

PSTN

ITSP

ITSP ITSP

ITSP

ITSP ITSP ITSP

ITSP

ITSP

ITSP

ITSP

ITSP

ITSP

ITSP

ITSP

ITSP

ITSP

ITSP

ITSP

ITSP

ITSP

ITSP

ITSP

ITSP ITSP

ITSP

ITSP

ITSP

ITSP ITSP

ITSP ITSP

ITSP

ITSP

The Wild West…

Page 26: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Evolution of Attacks

Page 27: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

DoS

Page 28: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

DDoS

Page 29: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Fraud

Page 30: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

If 1 Is Good, Why Not 3?

Page 31: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Geography

Page 32: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Internet LAN

Page 33: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

UC System

Corp  HQ  

Internet Firewall Home Firewall

IP Phone

PC

Home  

Page 34: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

UC System

Corp  HQ  

Internet Firewall WiFi Café

Router

Mobile UC

client

Laptop UC

client

Mobile Data

Network

Page 35: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

IM

Corp  HQ  

Corporate Network

Presence

Call Control

IVR IM

Office  A  

Presence

Call Control

Voicemail IM

Office  B  

Presence

Call Control

PSTN

Conferencing

Internet

Page 36: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Page 37: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Benefits (for us… and for attackers)

Page 38: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

DDoS�(the old-fashioned kind)�

(Asterisk & Amazon EC2, anyone?)

Page 39: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

SPIT�(“SPam for Internet Telephony”)

SPAM

Page 40: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Complexity

Page 41: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Physical Wiring

IP Network

IP-PBX

Voicemail

PSTN Gateways

Mobile Devices

IM Networks

Web Servers

Email Servers

Desktop PCs

Operating Systems

Firewalls

Internet

Directory Servers

VoIP

CRM Systems

Social Networks

Database Servers

Application Servers

Fingerpointing - 2011

Session Border

Controllers

Page 42: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

The Device Formerly�Known As A�

“Phone”

Page 43: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Mobility

Page 44: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

RTCWEB / WebRTC

Page 45: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Complexity

Page 46: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Physical Wiring

IP Network

IP-PBX

Voicemail

PSTN Gateways

Mobile Devices

IM Networks

Web Servers

Email Servers

Desktop PCs

Operating Systems

Firewalls

Internet

Directory Servers

VoIP

CRM Systems

Social Networks

Database Servers

Application Servers

Fingerpointing - 2011

Session Border

Controllers

Page 47: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Interoperability

Page 48: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

“The Hitchiker’s Guide�To SIP”

Page 49: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Forgotten�Simple Things

Page 50: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Biggest Financial Threat?

Page 51: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Toll Fraud

Page 52: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

IT Security 101

Page 53: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

PIN = “1234”

Page 54: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Password = “password”

Page 55: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Default password list

Page 56: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

VoIP = bits

Page 57: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

IT Security 101

Page 58: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Does Anyone Really �Give A _____ About�

VoIP Security?

Page 59: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

WHEN Will They Care?

Page 60: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

EVENT

Page 61: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Identity Theft

Page 62: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Celebrity

Page 63: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Trusted Leader

Page 64: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

“VoIP Is Insecure!!!”

Page 65: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

“VoIP Is Insecure!!!” Stupidly deployed

^

Page 66: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

“VoIP Is Insecure!!!”

Page 67: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Cover Your ____

Page 68: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

SOLUTIONS?

Page 69: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

IT Security 101

Page 70: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Audit, Audit, Audit

Page 71: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Enable What You Have

Page 72: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Interoperability

Page 73: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

www.sipit.net

Page 74: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Identity

Page 75: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Simplicity

Page 76: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Fabric

Page 77: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Air

Page 78: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Page 79: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Secure By Default

Page 80: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Education

Page 81: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

What is the Industry Doing to Help?

Security Vendors

“The Sky Is Falling!” (Buy our products!)

VoIP Vendors

“Don’t Worry, Trust Us!” (Buy our products!)

Page 82: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

www.voipsa.org/Resources/tools.php

Page 83: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Security Links

• VoIP Security Alliance - http://www.voipsa.org/ – Threat Taxonomy - http://www.voipsa.org/Activities/taxonomy.php – VOIPSEC email list - http://www.voipsa.org/VOIPSEC/ – Weblog - http://www.voipsa.org/blog/ – Security Tools list - http://www.voipsa.org/Resources/tools.php – Blue Box: The VoIP Security Podcast - http://www.blueboxpodcast.com

• NIST SP800-58, “Security Considerations for VoIP Systems” –  http://csrc.nist.gov/publications/nistpubs/800-58/SP800-58-final.pdf

• Network Security Tools –  http://sectools.org/

• Hacking Exposed VoIP site and tools –  http://www.hackingvoip.com/

• Seven Deadliest Unified Communications Attacks –  http://www.7ducattacks.com/

Page 84: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Thank You For�Giving A _____

Page 85: The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoIP Security?"

© 2011 VOIPSA

Dan York - [email protected]�+1-802-735-1624 DisruptiveTelephony.com danyork.com�twitter.com/danyork

Thank you! Q & eh?

www.voipsa.org 7ducattacks.com

blueboxpodcast.com