internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It


  About Us l Contact Us l Privacy
Home News Business Software Hardware Online Marketing Web Management The Basics
Product Watch Buyer's Guide Small Business Essentials Online Forums Glossary Images Events

Search SBC

Search internet.com


Small Business Computing Product of the Year Awards
Winners Announced!


internet.commerce
Be a Commerce Partner
Domain registration
KVM Switches
Laptops
Promotional Gifts
Promos and Premiums
Best Price
Promotional Pens
Imprinted Promotions
PDA Phones & Cases
Desktop Computers
Online Shopping
Corporate Gifts
Imprinted Gifts
Disney World Tickets

Free Newsletters
Small Business Computing

Ecommerce Guide Daily

Webopedia

E-mail Offers

Newsletter Address Changes
Webopedia Glossary
Enter a Term:

internet.com
IT
Developer
Internet News
Small Business
Personal Technology
International

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

Get Started with Oracle on Windows DVD
Learn how Oracle gives you the power to grow by providing a scalable, easy-to-use platform for running your business at a price you can afford. Request your free copy of this DVD, containing Oracle Database 11g software, whitepapers, tutorials, etc. Register now! ;
Guide to Oracle 11g and Database Migration
Oracle Database 11g includes more features for self-management and automation, which makes it easier for customers to cost-effectively manage their data. Download this Internet.com eBook for an overview of some of the new features in 11g and for an overview of the issues you need to consider as you prepare for a database migration. ;
Innovate Faster with Oracle Database 11g
Read this in-depth analysis of 56 customers, which shows significant differences between the value software vendors Oracle and SAP deliver to midsize companies. ;
Oracle Business Intelligence Standard Edition One
Find out how Newport Beach, CA-based Mobilitie is shaking up the telecom industry by leveraging technology to provide an entirely different financial model for deploying, upgrading, and owning wireless and wireline network assets. ;
Business Intelligence and Enterprise Performance Management: Trends for Emerging Businesses
Quickly implementing an ERP software solution can be of tremendous benefit; however, companies often struggle to balance the benefits of reducing implementation time and cost with the risks of an accelerated deployment. Read this white paper to learn about easy-to-follow best practices for achieving a successful accelerated implementation. ;
Making the Case for Oracle Database on Windows
Users benefit as vendors reduce enterprise complexity and deliver integration. ;



Hot Topics
Driving Business from Bloggers
Demystifying Search Engine Optimization: Part 2
Last Call: Vote Today!


Small Business Essentials
Networking Fundamentals
Be it wired or wireless, building a network can take your small business to new heights in Internet communications, real-time collaboration, webhosting and e-commerce — or simply be setup to connect a series of workstations with a shared printer. Learn how to leverage today's networking technologies at your small business.
[ more ]


Related Articles





Is secure, available data a challenge? Symantec Online Backup can help with an easy to use, secure, web-based solution for your business. Sign up and get your first 30 days free.
News & Trends
Don't SPIT on VOIP
By Susan Kuchinskas
August 24, 2004

Internet Telephony, also known as VoIP, is picking up steam, as telcos wise up to the benefits of turning speech into packets and delivering them over the Internet. But some experts say that security efforts have fallen behind. SMBs need to be aware of all the issues before jumping on the VOIP bandwagon.

According to Frost & Sullivan analyst Jon Arnold, denial of service (DoS) attacks against VoIP networks are a real possibility -- and there's even a distant risk of spam over Internet telephony (SPIT).

"The proliferation of Voice over IP is so small right now, it's not the kind of magnet for attacks that e-mail is," Arnold says.

Frost & Sullivan forecasts a 15 percent penetration of VoIP in North America by 2008. That figure is for landlines only; wireless could have a major impact in the numbers, according to Arnold. But VoIP security threats are real.

"Spam is a small piece of the much bigger issue of voice security in the IP world," Arnold says. "It's come on the scene quietly, and the security industry hasn't kept pace."

VoIP providers are already on the lookout for DoS exploits.

"DoS attacks can happen to VoIP providers unless they implement security mechanisms," says Louis Holder, executive vice president of product development for VoIP provider Vonage.

VoIP systems require every customer to have a terminal adapter at their locations.

"Each customer then becomes a node that could help launch a Denial of Service attack on a network," says Brian Fowler, CTO of Voiceglo, a VoIP service provider that monitors its network for nonconforming packets, which are then filtered and extracted. "They can be turned against other networks."

Still, Fowler is aware of the pervasiveness of SPIT. "We worry about it all the time," he says. "We've been lucky at this point."

Arnold says that VoIP hackers could do plenty of evil besides just disrupting networks. "You can find holes and drain financial resources out of companies," he said. "You can start charging phone calls to them and make purchases over the phone. That's the really scary stuff."

More Than a SIP of Trouble
What worries Arnold most is Microsoft's adoption of Session Initiation Protocol (SIP), a signaling protocol for Web conferencing, telephony, presence, events notification and instant messaging.

"Once you're in a SIP environment," he says, "you become vulnerable to the vulnerabilities of the public Internet. And if you're a hacker, what market are you going for?"

In January 2003, CERT warned SIP was vulnerable to remote code execution and other cracks, while the U.K. National Infrastructure Security Co-Ordination Centre advised early this year that the H.323 networking protocol for transmitting audio-visual data supported by many VoIP networks put them at risk for DoS and buffer overflow attacks.

The viability of SPIT is less clear.

"That is not possible to do with Vonage's voice-mail system" Holder said. "In order to get a voice message into our system, you have to stream real-time voice into it."

In other words, if a spammer wanted to send someone a one-minute-long voice message, he would have to stream that message to the voice-mail system for a whole minute; he couldn't just e-mail the message as a file into the system.

Even though the information is carried as data in Vonage's system, Holder says, it starts and ends as voice. "Phones have IP addresses," he says, "but the voice conversation still needs to be played in real time. And it's converted back to voice in real time."

But Qovia, a company that sells enterprise tools for VoIP monitoring and management, recently applied for a patent on technology to broadcast messages via VoIP -- and another one for a method of blocking such broadcasts. The broadcast methodology only works on a pure VoIP network, while most of today's services are hybrids of IP and traditional telephone lines.

"SPIT becomes an issue when you don't have to go out over the traditional telephony lines," says Qovia CEO Richard Tworek. "As soon as my VoIP system touches the Internet cloud, that's when it starts to become interesting. We predict it's going to happen, much as spam e-mail did. We're trying to get ahead of the game."

The company realized pretty quickly that where there's a channel, there's a pitchman, says Pierce Reid, Qovia vice president of marketing. "Someone is going to use VoIP for spam." Since every other medium has been the conduit of unwanted marketing messages, from bulk faxes to telemarketing to IM spam, he says, Qovia engineers began to research whether it was possible to broadcast voice-mail. It was easy.

Qovia insists it would never allow the technology to be used for marketing, let alone spam.

"There are positive uses of the broadcast capability," says Tworek. "And none of us would agree that unsolicited marketing is a positive use; that's not in our future."

However, he sees the broadcast capability being useful for public agencies -- such as Homeland Security -- that might need to reach people with vital messages.

Qovia will incorporate its SPIT-blocking technology in future releases of its security products, while enforcement of its patent on broadcasting, if granted, could be used to shut down VoIP spammers.

Adapted from Internetnews.com.

Do you have a comment or question about this article or other small business topics in general? Speak out in the SmallBusinessComputing.com Forums. Join the discussion today!

Tools:
Add smallbusinesscomputing.com to your favorites
Add smallbusinesscomputing.com to your browser search box
IE 7 | Firefox 2.0 | Firefox 1.5.x
Receive news via our XML/RSS feed

eBook: Evaluating Software as a Service for Your Business. Sponsored by Webroot
Five Trends for Application Development. Download Your Complimentary Report. Exclusive. Act Now.
Five Trends for Application Development & Program Management. Download Complimentary Report Now.
14-Day Qualys Trial: Find Out in Minutes if Your Network is Vulnerable!
Is secure, available data a challenge? Try Symantec Online Backup free for 30 days.



JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Microsoft Article: HyperV-The Killer Feature in WinServer ‘08
Avaya Article: How to Feed Data into the Avaya Event Processor
Microsoft Article: Install What You Need with Win Server ‘08
HP eBook: Putting the Green into IT
Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 1
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 2--The Future of Concurrency
Avaya Article: Setting Up a SIP A/S Development Environment
IBM Article: How Cool Is Your Data Center?
Microsoft Article: Managing Virtual Machines with Microsoft System Center
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Video: Are Multi-core Processors Here to Stay?
On-Demand Webcast: Five Virtualization Trends to Watch
HP Video: Page Cost Calculator
Intel Video: APIs for Parallel Programming
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Sun Download: Solaris 8 Migration Assistant
Sybase Download: SQL Anywhere Developer Edition
Red Gate Download: SQL Backup Pro and free DBA Best Practices eBook
Red Gate Download: SQL Compare Pro 6
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
How-to-Article: Preparing for Hyper-Threading Technology and Dual Core Technology
eTouch PDF: Conquering the Tyranny of E-Mail and Word Processors
IBM Article: Collaborating in the High-Performance Workplace
HP Demo: StorageWorks EVA4400
Intel Featured Algorhythm: Intel Threading Building Blocks--The Pipeline Class
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES