June 6, 2005 1:53 PM PDT

Pharming and other security woes hector VoIP

CHICAGO--There are few clearer signs that an information technology has hit the mainstream than when it becomes the focus of pharming and other security attacks.

Low-cost voice over Internet Protocol (VoIP) phone services now capturing the general public's imagination are indeed being targeted by online attackers, who have been known to eavesdrop on calls, deny customers access to their VoIP service and cause "clipping," or degraded service quality, on some accounts, say executives gathered here for Supercomm 2005, a major phone trade show.

VoIP's security problems only heighten concerns simmering since January, when a Harris Interactive poll found that 60 percent of all adults in the United States who are aware of Internet telephony but not using it believe it could be subject to security and privacy issues.

VoIP's security vulnerabilities both highlight the enormous potential of the service and threaten to derail the success of freely distributed VoIP software, which lets any Internet connection also serve as a home or business phone line. About 7.5 million out of 200 million homes and offices have traded in their traditional phone lines for VoIP. But research firm Gartner predicts there could be as many as 25 million VoIP-connected homes by 2008. Among the big draws: VoIP operators' $20-a-month unlimited calling plans.

One of VoIP's flaws is that it is inherently vulnerable to hackers because, like e-mail, VoIP calls find their way by locating an IP (Internet Protocol) address, a unique set of numbers assigned to each device connected to the Web. Yet while scores of commercial VoIP providers have quickly expanded to take advantage of the growing interest in the service, many have not implemented even basic security measures, such as encrypting phone calls.

While information about attacks on VoIP systems are mostly still the stuff of white papers, some businesses using the service are encountering attacks, according to corporate phone-systems integrator BearingPoint Institute, which didn't provide details.

"Security is crucial to broad acceptance of IP telephony," said Christian Stredicke, founder of Berlin-based Snom Technology and a speaker at a Supercomm security summit.

Time may be running out to completely contain VoIP security threats, however. In January, analysts at Gartner said it will be only two years before organized attacks begin on signaling networks, the portions of telephone networks that carry the routing instructions that ensure calls reach the right place.

"Not surprisingly, as many VoIP operators rush to capture new business, hackers are rushing too--to explore and exploit ways to steal or disrupt these services," Stephen Doty and Fred Hoffmann, two BearingPoint managers, wrote in a recently released white paper.

For their part, many VoIP service providers and equipment makers are turning to the relatively new Voice over IP Security Alliance. The alliance will define security requirements across a variety of VoIP deployments and address issues such as security-technology components, architecture and network design, network management, and end-point access and authentication.

New VoIP security threats seem to come every week, a brisk pace. One that recently surfaced is a VoIP version of pharming, one of the latest security scares for Internet users of all sorts.

Pharming exploits vulnerabilities in a piece of network equipment responsible for translating e-mail and Web addresses into IP addresses. Security experts speaking at Supercomm this week said that, by hijacking a domain-name system (DNS) server--a computer that stores and organizes IP addresses--pharmers get control of VoIP calls.

Without their knowledge, VoIP users' calls could then be redirected to IP addresses completely different from the ones the users dialed, warns Paul Mockapetris, the inventor of the domain name system.

The list of different VoIP attacks is growing and highlights the adaptibility of the attackers.

One of the earlist VoIP threats identified, Caller ID spoofing, substitutes someone else's Caller ID information as your own.

The security problem known as clipping, meanwhile, occurs when a cable modem is targeted with a huge flood of traffic, creating a "clipping" disruption on VoIP phone calls. Another type of attack, called V-bombing, occurs when thousands of voice mails are targeted simultaneously to a single VoIP mailbox.

See more CNET content tagged:
pharming, SuperComm, VoIP, VoIP security, IP

Add a Comment (Log in or register) 3 comments
lol......
by Prndll June 6, 2005 4:14 PM PDT
This article serves no purpous other than putting out certain new words to add to the "hacker vocabulary". I learned NOTHING reading this. All it says is that it is, and that's something we all already knew. This article would have been better if something would have been said as to what could be done.
Reply to this comment View reply
Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' photos

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Outside the Lines

    EIC Squared: Chrome, iPods, and a Dell-Salesforce union

    On this week's EIC Squared podcast CNET's Dan Farber and ZDNet's Larry Dignan discuss Google's latest rocket launch--the Chrome browser--as well as Apple's iPod event next week and a Dell-Salesforce.com union.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    At 10 years old, whither Google?

    Daniel Sieberg of CBS News looks at how the company grew exponentially from start-up to superstar and part of our culture, but what's ahead?

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Webware

    Mozilla releases second Firefox 3.1 alpha

    Added features include support for a new video tag element introduced with the HTML 5 standard, along with some speed enhancements.

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.