Search
 Advanced SearchView Cart   Checkout   
 Location:  Home » Books » General AAS » Voice over IP Security (Networking Technology: IP Communications)January 9, 2009  
Browse
Books
Computers
Electronics
Related Categories
• General AAS
Computer Science
New & Used Textbooks
Custom Stores
Specialty Stores
• General AAS
New & Used Textbooks
Custom Stores
Specialty Stores
Books
• General AAS
Internet
Home Computing
Computers & Internet
Subjects
• Privacy
Business & Culture
Computers & Internet
Subjects
Books
• Security+
Exams
Certification Central
Computers & Internet
Subjects
• Cisco
Publisher
Certification Central
Computers & Internet
Subjects
• General
Data in the Enterprise
Networking
Computers & Internet
Subjects
• General AAS
Data in the Enterprise
Networking
Computers & Internet
Subjects
• General
Networks, Protocols & APIs
Networking
Computers & Internet
Subjects
• General AAS
Networks, Protocols & APIs
Networking
Computers & Internet
Subjects
• Telephony
Networking
Computers & Internet
Subjects
Books
• Network Security
Networking
Computers & Internet
Subjects
Books
• General
Computers & Internet
Subjects
Books
• General AAS
Computers & Internet
Subjects
Books
• Telephone Systems
Telecommunications
Engineering
Professional & Technical
Subjects
• General
Telecommunications
Engineering
Professional & Technical
Subjects
• General AAS
Telecommunications
Engineering
Professional & Technical
Subjects
• Paperback
Binding (binding)
Refinements
Books
• Printed Books
Format (feature_browse-bin)
Refinements
Books
Voice over IP Security (Networking Technology: IP Communications)
Voice over IP Security (Networking Technology: IP Communications)
Author: Patrick Park
Publisher: Cisco Press
Category: Book

List Price: $55.00
Buy New: $16.99
You Save: $38.01 (69%)
Buy New/Used from $16.99

Avg. Customer Rating: 4.0 out of 5 stars(5 reviews)
Sales Rank: 457229

Languages: English (Original Language), English (Unknown), English (Published)
Media: Paperback
Edition: 1
Number Of Items: 1
Pages: 384
Shipping Weight (lbs): 1.5
Dimensions (in): 8.9 x 7.3 x 1

ISBN: 1587054698
Dewey Decimal Number: 004.695
EAN: 9781587054693
ASIN: 1587054698

Publication Date: September 19, 2008
Availability: Usually ships in 1-2 business days

Similar Items:

  • Fax, Modem, and Text for IP Telephony
  • Hacking Exposed VoIP: Voice Over IP Security Secrets & Solutions
  • Implementing Cisco Unified Communications Manager, Part 2 (CIPT2) (Authorized Self-Study Guide)
  • Cisco Voice over IP (CVOICE) (Authorized Self-Study Guide) (3rd Edition)
  • Implementing Cisco Unified Communications Manager, Part 1 (CIPT1) (Authorized Self-Study Guide)

Editorial Reviews:

Product Description

Voice over IP Security

Security best practices derived from deep analysis of the latest VoIP network threats

Patrick Park

VoIP security issues are becoming increasingly serious because voice networks and services cannot be protected from recent intelligent attacks and fraud by traditional systems such as firewalls and NAT alone. After analyzing threats and recent patterns of attacks and fraud, consideration needs to be given to the redesign of secure VoIP architectures with advanced protocols and intelligent products, such as Session Border Controller (SBC). Another type of security issue is how to implement lawful interception within complicated service architectures according to government requirements.

Voice over IP Security focuses on the analysis of current and future threats, the evaluation of security products, the methodologies of protection, and best practices for architecture design and service deployment. This book not only covers technology concepts and issues, but also provides detailed design solutions featuring current products and protocols so that you can deploy a secure VoIP service in the real world with confidence.

Voice over IP Security gives you everything you need to understand the latest security threats and design solutions to protect your VoIP network from fraud and security incidents.

Patrick Park has been working on product design, network architecture design, testing, and consulting for more than 10 years. Currently Patrick works for Cisco as a VoIP test engineer focusing on security and interoperability testing of rich media collaboration gateways. Before Patrick joined Cisco, he worked for Covad Communications as a VoIP security engineer focusing on the design and deployment of secure network architectures and lawful interception (CALEA). Patrick graduated from the Pusan National University in South Korea, where he majored in computer engineering.

Understand the current and emerging threats to VoIP networks

Learn about the security profiles of VoIP protocols, including SIP, H.323, and MGCP

Evaluate well-known cryptographic algorithms such as DES, 3DES, AES, RAS, digital signature (DSA), and hash function (MD5, SHA, HMAC)

Analyze and simulate threats with negative testing tools

Secure VoIP services with SIP and other supplementary protocols

Eliminate security issues on the VoIP network border by deploying an SBC

Configure enterprise devices, including firewalls, Cisco Unified Communications Manager, Cisco Unified Communications Manager Express, IP phones, and multilayer switches to secure VoIP network traffic

Implement lawful interception into VoIP service environments

This IP communications book is part of the Cisco Press Networking Technology Series. IP communications titles from Cisco Press help networking professionals understand voice and IP telephony technologies, plan and design converged

networks, and implement network

solutions for increased productivity.

Category: Networking?IP Communication

Covers: VoIP Security




Customer Reviews:

4 out of 5 stars General VoIP security overview. Best chapters: SBC's and LI.   December 14, 2008
  2 out of 2 found this review helpful

The book provides a good general overview of VoIP security, covering multiple topics involved on securing a VoIP infrastructure, from network devices to VoIP servers, plus secure VoIP protocols. In my opinion, the best chapters are chapter 8 and 10 & 11, Session Border Controllers (SBC's) and Lawful Interception (LI), respectively; it is difficult to find books covering these topics still today, although these are two of the major areas regarding VoIP security nowadays.

SBC's are the VoIP security element by design and therefore a key device in any VoIP infrastructure. The book covers SBC's types, access and peering, expected SBC functionality and capabilities (such as DoS protection, translation and NAT features, LI, high availability and load balancing, etc) and offers a brief introduction to its architecture design concepts.

Lawful Interception (LI) by law enforcement (LE), or LI by LE :), is one of the main VoIP research topics today, especially when strong security features are added, such as signaling and media encryption, that difficult the interception tasks. The last two chapters cover the fundamentals of LI on VoIP networks (following the Cisco model, as there are three other standards), describing the different elements, fucntions, and interfaces involved. It is a theoretical chapter followed by some practical advice to implement LI, very detailed and Cisco-based.

The book starts with an introductory overview of VoIP, its benefits and drawbacks, and some security concerns. Then it provides another VoIP threat taxonomy, a good generic overview that lacks some VoIP threats and complements (or simply provides another perspective to) the IETF draft and VOIPSA VoIP threat taxonomies. Unfortunately, I have not found yet a classification that consolidates all the different VoIP threats from (IMHO) the right perspective.

Chapter 3 offers an interesting summarized analysis of the main VoIP protocols, how they work, and their main security requirements and features. It covers H.323, SIP, and MGCP; I specially liked the SIP section, with descriptive message captures and flow diagrams. Chapter 5 complements the VoIP protocols with the main network devices in a VoIP environment, their role, and key security requirements. Although chapter 7 extends the security analysis of VoIP protocols, covering authentication and signaling and media encryption, it does not cover the latest key exchange solutions, such as DTLS, ZRTP or MickeyV2, as it is focused mainly on S/MIME.

All these chapters provide a lightweight analysis of VoIP security, not going very much in-depth into any of the topics covered. The book is a good overview reference for the VoIP security novice reader, I guess intended for network and system administrators, law enforcement, or security pros new to VoIP.

VoIP threats, including some attack types and tools, are analyzed on chapter 6. This chapter covers in detail a few VoIP attacks, providing simulation, examples and command line options for widely available attack tools. It allows the reader to see some real attacks in action, although it only shows the tip of the iceberg regarding all the tools and attacks that are possible; please, do not get the feeling that this is all you can do.

Chapter 4 covers cryptography, and in my opinion, it doesn't fit on the book; although crypto is a key aspect to protect VoIP infrastructures, the novice reader can get this info from other sources.

As the book is from Cisco Press, chapter 9 focuses on specific Cisco features and syntax, specially for practical sections that provide configuration details for firewalls, access devices, and the Unified Communication Manager (& Express), formerly CallManager. The info is useful to get an overview of the implementation steps, but do not apply to you if you are using equipment from other vendors.

Overall, it is a generic reference book to start getting involved into the VoIP security world, acquire a general understanding of the main VoIP security threats, target network elements, VoIP protocols, and security solutions. Once again, the SBC and LI sections are my favorites.



4 out of 5 stars VoIP security made easy   December 13, 2008

I was really excited to take a look at a book on this topic. It seems to me that while we all knew that there are security issues with this type of technology, no one really wanted to discuss the gritty details in a way that made them easy to understand. I think that `Voice over IP Security' is a great start to understanding just what those details are. Just keep in mind while reading it just who the target audience is.

In the intro section, the `who should read this book' section addresses a very broad audience, everyone from managers to engineers to security people to developers. This is an ambitious lot to try and satisfy in less than 400 pages. However, I think that the book makes a noble attempt to in fact meet the requirements of these various groups. Perhaps not in the depth that each of the groups would want to see, but I think it's a good foundation for anyone trying to learn the technology.

The areas that I most appreciated (being a information security manager type who has to look at technology like this from many dimensions: policy, technical configuration recommendations, audit) were it breaks done the many vulnerable areas, actually specifying the components and their weaknesses in the context of confidentiality, availability and integrity. The book also has a detailed discussion on the protocols of VoIP and how they work. I found the diagrams and other illustrations very useful in these areas.

The last section I wanted to point out was the discussion on lawful interception. I don't think that a lot of organizations consider this issue when they implement this type of system, so I particularly found this helpful and well explained. I will definitely use this as a reference as I prepare to write some policies for a VoIP implementation.

I noticed that the author did very well at taking some very technical topics and made them easy to understand. Well written, I think that `Voice over IP Security' is a great read to better understand the components of a VoIP system, the threats, and how best to protect your organization from such threats.



5 out of 5 stars This provides all the analysis and tools necessary for understanding VoIP threats and system protection   November 10, 2008
VoIP security issues are becoming more and more serious as voice networks grow and intelligence attacks and fraud become more sophisticated, so any library strong in programmer's references including extensive VoIP networking needs VOICE OVER IP SECURITY, an analysis of cryptographic algorithms, threats, and survey of how security issues on networks can be addressed. From configuring firewalls to implementing lawful interception into VoIP services, this provides all the analysis and tools necessary for understanding VoIP threats and system protection.



4 out of 5 stars Best VoIP Threat Discussion I have seen   September 29, 2008
  5 out of 5 found this review helpful

I have been carrying this book around with me for a couple weeks now and had a couple long plane flights as well. This is a difficult book to review. The author clearly knows his stuff and the threat treatment is great. However, the material is all over the map. The subtitle talks about good security practices and the book is short on that to be candid. Bottom line, if you are considering a VoIP deployment or wondering how secure/robust your existing deployment is, this is a must read.

My favorite "I never thought of that" scenario in the book was a simple power outage. What if you have twenty thousand IP phones and the power drops . . . then when it is restored all 20k phones start banging the server causing an outage.



4 out of 5 stars explains security weaknesses in VoIP   September 13, 2008
  4 out of 4 found this review helpful

Voice over Internet Protocol has emerged as a very popular way to do cheap (often free) long distance phone calls. But there is a huge amount of complexity beneath VoIP, that most users and even sysadmins are blissfully unaware of. The authors of this book perform a valuable service by educating the reader about current and, perhaps more importantly, possible future attacks.

A major source of weakness in VoIP is shown to be due to interoperability issues between different underlying protocols or applications. In turn, a major reason for this is that when the protocols were defined, the authors of the defining documents unwittingly left ambiguities in the specifications. Then when vendors implemented VoIP products based on those protocols, different vendors might reasonably have interpreted the documents differently.

Another source of weakness in security, as compared to traditional phone calls, is that tapping the latter often requires physical access to a phone line or a switching exchange. But VoIP at a low enough level is just like anything else that uses the Internet. Packets are routed through arbitrary third parties on the Internet. Those might have been subverted via remote attacks, so the VoIP cracker could be anywhere in the world.

The book then spends most of its time suggesting protective measures. Including, most interestingly, how to simulate current and possibly future threats. This gives you practical hands on experience in role playing the adversary. Something necessary to fully devise technical solutions.

But even if you do not do the latter, the book is useful simply in making you aware of the danger. So that for "sensitive" conversations, you might advise users to minimise the use of VoIP, perhaps by using standard land lines.


Powered by: Dknc, inc. and Amazon.com


For your safety and security, orders are processed through amazon.com