• DocumentCode
    936826
  • Title

    Vulnerability analysis and best practices for adopting IP telephony in critical infrastructure sectors

  • Author

    Cao, Feng ; Malik, Saadat

  • Author_Institution
    Cisco Syst., Inc., San Jose, CA, USA
  • Volume
    44
  • Issue
    4
  • fYear
    2006
  • fDate
    4/1/2006 12:00:00 AM
  • Firstpage
    138
  • Lastpage
    145
  • Abstract
    IP telephony has been rapidly introduced to replace the traditional circuit switched infrastructure for telephony services. This change has had an enormous impact on critical-infrastructure (CI) sectors, which are expected to become increasingly dependent on IP telephony services. Reliable and secure telephony service is a key concern confronting most organizations in the critical-infrastructure sector today. With the proliferation of voice over IP (VoIP) services in these organizations, it is important for them to understand the security vulnerabilities and come up with a set of best practices during the evolution of the IP telephony services. This article outlines the potential security issues faced by CI sectors as they transform their traditional phone systems into VoIP systems. Vulnerability analyses are conducted to understand the impact of VoIP security challenges in the new convergent network paradigm. The most common security measures are analyzed to identify their strengths and limitations in combating these new security challenges. A set of recommendations and best practices are offered to address the key issues of VoIP security as IP telephony is being introduced into critical infrastructure.
  • Keywords
    Internet telephony; telecommunication security; IP telephony; VoIP security; critical infrastructure sectors; voice over IP; vulnerability analysis; Best practices; Communication system security; Information security; Intelligent networks; Internet telephony; Java; Protocols; Safety; Voice mail; Web server;
  • fLanguage
    English
  • Journal_Title
    Communications Magazine, IEEE
  • Publisher
    ieee
  • ISSN
    0163-6804
  • Type

    jour

  • DOI
    10.1109/MCOM.2006.1632661
  • Filename
    1632661