Man-in-the-Middle Attack Underscores Need for VOIP Security

Man-in-the-Middle Attack Underscores Need for VOIP Security

Nemertes Impact Analysis:

Privately held Voice over IP (VOIP) security vendor Sipera Systems’ Viper Labs performed a public demonstration of snooping on VOIP over WiFi. Known as man-in-the-middle (MITM) attacks, all non-encrypted, non-authenticated VOIP communications is susceptible.

VOIP users on Softphones and smartphones connecting over unprotected wifi – at home, the airport or the local coffee shop - face the greatest risk. VOIP softphone and smartphone use is on the rise with 54% of softphone deployments augmenting physical IP phones; many for mobile workers. Transport layer security (TLS) or a virtual private network (VPN) are necessary to secure VOIP communications over WiFi. This is a standard setting for most softphones and some smartphones.

Impacts:

Enterprises: Softphones and smartphones need a VPN or TLS when communicating over open WiFi.

Vendors: VOIP vendors must provide the same level of security to smartphones as softphones.

Investors: Vendors supplying VOIP security include Acme Packet (NASDAQ:APKT), Radware (NASDAQ:RDWR), and privately held BorderWare, Ingate, Newport Networks and Sipera Systems.

By Ted Ritter, Senior Research Analyst

Sign Up To Receive Nemertes Impact Analysis By E-mail

Follow Nemertes Research on Twitter