{"id":22458,"date":"2018-06-22T12:05:46","date_gmt":"2018-06-22T11:05:46","guid":{"rendered":"http:\/\/www.intelligentcio.com\/eu\/?p=22458"},"modified":"2018-06-22T12:05:46","modified_gmt":"2018-06-22T11:05:46","slug":"expert-opinion-is-sip-trunking-the-weak-link-in-your-armour","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2018\/06\/22\/expert-opinion-is-sip-trunking-the-weak-link-in-your-armour\/","title":{"rendered":"Expert opinion &#8211; is SIP trunking the weak link in your armour?"},"content":{"rendered":"<p><em>By Paul Clarke, UK Manager, <a href=\"https:\/\/www.3cx.com\/\">3CX<\/a><\/em><\/p>\n<p>The advent of IP telephony has not only reduced costs for companies but also enabled the adoption of flexible working conditions \u2013 both in terms of working hours and working location. Unified communications systems that take advantage of IP connections can provide a plethora of business benefits \u2013 but, as with any technology in the 21<sup>st<\/sup> century business, security needs to be managed correctly.<\/p>\n<p>Session Initiation Protocol (SIP) trunking, the key connection between private networks and the wider Internet, forms the foundation of any IP phone system.<\/p>\n<p>However at the same time, it can give an open invitation for hackers to access any IP system and so form a ripe target for attack. Unfortunately, the increased popularity of IP phone systems in the UK has made them a tempting target for cybercriminals, but companies in the digital age can\u2019t simply disconnect from the internet. So how can organisations ensure that they aren\u2019t letting the enemy in through the front door?<\/p>\n<p><strong>Know your weakness<\/strong><strong>\u00a0<\/strong><\/p>\n<p>The greatest vulnerability of SIP trunking comes from its ubiquity. Connectivity, while enabling businesses to communicate with phones and other devices worldwide, also opens the organisation up to anyone listening in. SIP trunk attack tools, such as \u2018SIP vicious\u2019, are also widely available online. Attackers can use these tools to make security teams look pretty vacant, by exploiting vulnerabilities in the SIP trunking structure to enter a network.<\/p>\n<p>These actions may be as direct as a denial of service attack, bringing a business\u2019 communications or other systems down for an undefined period, or until a ransom is paid. The attackers may take sensitive information \u2013 whether intellectual property that can be ransomed or sold on, or personal data that can be used for identity theft.<\/p>\n<p>Or they may even hijack communications themselves, allowing them to constantly dial expensive premium numbers and run up hefty costs for the business \u2013 as well as substantial profits for whoever owns the number. Attackers could even simply listen in to all communications made over the SIP trunk, giving valuable insight into the business and allowing them to gather information they can use for any purpose they wish.<\/p>\n<p><strong>Take steps to protect it<\/strong><\/p>\n<p>Largely, the threats facing SIP trunking are the same as those facing any other Internet connection. As in all these cases, protection means first understanding the level of vulnerability. Is the SIP trunk provided as a dedicated physical connection to your network, with no means of accessing it online? Or is it shared with internet access, meaning there may be a plethora of access points?<\/p>\n<p>There is also the question of whether the SIP trunk has its own security measures, supplied by the provider, or whether additional protection needs to be installed on top. For instance, any solution from the best providers should provide security that not only authenticates traffic that attempts to access the trunk, but also identifies and blacklists known SIP trunking attack tools.<\/p>\n<p>At the same time, connection to the SIP trunk shouldn\u2019t be a free-for-all. To further bolster security, only devices that need to communicate with the outside world should be authorised. Employees\u2019 desk and work smart phones should be able to access the SIP trunk, but personal devices and those used by contractors should be kept well away. By taking this approach, organisations can reduce the SIP trunk\u2019s exposure, so they only have to check and vet approved devices to ensure they don\u2019t harbour security threats.<\/p>\n<p><strong>Hope for the best, prepare for the worst<\/strong><\/p>\n<p>Regardless of what precautions a company takes there is always the possibility that the SIP trunk will be compromised and security breached. Consequently, a successful security programme should include the necessary steps to alleviate the effects of a security breach in the worst-case scenario.<\/p>\n<p>For instance, to prevent the risks of communications being hijacked, it may be shrewd to implement a blacklist of specific telephone numbers or connections that devices are banned from contacting. On top of this, data and communications should be encrypted as best practice, so that any stolen information is worthless. And the business should always be watching for any unusual behaviour by a system that might signify an attack, in order to shut it down before any serious damage is done.<\/p>\n<p>The dangers facing SIP trunks are virtually the same as with any other connection \u2013 ultimately it\u2019s just another angle of attack that companies must defend against. A well thought out security strategy recognises that, like everything else, SIP trunking can be a lucrative target for criminals \u2013 but recognition of the target is no longer enough, it needs to be harder to hit.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Paul Clarke, UK Manager, 3CX The advent of IP telephony has not only reduced costs for companies but also enabled the adoption of flexible working conditions \u2013 both in terms of working hours and working location. Unified communications systems that take advantage of IP connections can provide a plethora of business benefits \u2013 but, [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":22464,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1489,14,248],"tags":[7687,7688,114,474,3598,7689,7690,7691,5204,7692,7693,5186],"class_list":["post-22458","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-insights","category-more-news","category-telecom","tag-3cx","tag-denial-of-service","tag-hackers","tag-internet","tag-ip-telephony","tag-paul-clarke","tag-private-networks","tag-session-initiation-protocol","tag-sip","tag-sip-trunk","tag-uk-manager","tag-unified-communications"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/22458","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=22458"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/22458\/revisions"}],"predecessor-version":[{"id":22463,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/22458\/revisions\/22463"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/22464"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=22458"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=22458"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=22458"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}