My Photo

My Online Status

Technorati

  • Technorati

Blogger.com


« FutureNet thoughts | Main | Sun to port OpenOffice to Mac »

May 07, 2007

Beware the SIP bot

Dan York has a great post today on the VOIPSA blog about the prospect of remote-controlled Zombie attacks on SIP servers.  He lays out a fascinating scenario of companies launching SIP-based attacks on competitors, and he notes the recent release of a VOIP bot for testing automated attacks.

Dan is correct to note that this isn't much of a threat to the enterprise as of yet, as enterprises typically don't accept SIP-based calls from the outside world.  But this is changing as enterprises begin to take advantage of SIP-trunking services for PSTN access, as well as SIP-based "click-to-call" features on enterprise web sites.

I think Dan's analysis is spot-on, and it underscores the need for enterprises to be careful to address security of links to SIP-trunking service providers by deploying SIP-based firewalls and intrusion-detection/prevention systems.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/t/trackback/213986/18290278

Listed below are links to weblogs that reference Beware the SIP bot:

Comments

Post a comment

Comments are moderated, and will not appear on this weblog until the author has approved them.

If you have a TypeKey or TypePad account, please Sign In