Commentary - Channel Insider
Empowering the next generation Channel
 

Bull’s Eye Awards
Nominations Open for Channel Insider 2009 Bull’s Eye Awards
Nominations are now open for the Channel Insider 2009 Bull’s Eye Awards, which recognize excellence in customer service, technology prowess, business acumen, channel leadership, communications and community building, and innovation among vendors, solution providers, distributors and channel services companies.



Sponsored Links
  • Control VM Sprawl, What You Don’t Know Can Hurt You
  • FREE Sophos Encryption Tool: Encrypt, compress and share files easily
  • LSI 6Gb/s Portfolio Expands to Include SATA+SAS HBAs
  • Reduce the cost of managing your mobile workers.
  • Find out 7 Ways to Drive Data Center Efficiency
  • SonicWALL breaks through network and email gridlock
  • Save up to 40% on calling costs with Avaya Aura™



  •  

    IOS Theft and Telephony: Something New to Worry About

    in Commentary


    Article Rating:starstarstarstarstar / 0
    Article Views: 1159

    Rate This Article:
    Add This Article To:
    Should VOIP resellers be worried about the IOS theft? According to Christopher King, information security practice director at Principal Security Group, "Hell, yes."

    I assured readers with my first column that my job here is to report on VOIP, not to praise it. Which is why I'm just as eager as anyone to get a read on the potential seriousness of the Cisco IOS source code theft and its implications for the reliability of IP-based communications.

    As reported by a Russian security Web site and confirmed by Cisco, hackers broke into the switching and routing giant's network and stole 800MB of source code for IOS 12.3 and 12.3t. The IOS 12.3 operating system powers Cisco's networking product suite, including routers used in homes and small businesses and the 7000 series that makes up the Internet backbone. All of Cisco's infrastructure products—switches and routers—are exposed.

    I wrote five days ago that an IP voice application inherits the security of the data network. If someone can hack into your network infrastructure (typically composed of a Cisco router and switches) and bring it down, obviously, that's not a good inheritance. If your voice traffic is using voice over IP, it relies on the network infrastructure being robust. Whether it's Cisco's Call Manager or anyone else's IP PBX you're using, a router ם and very likely that's a Cisco router — fronts the system.

    Resource Library:
    Click here to read Ellen Muraskin's column "VOIP Is as Secure as You Make It."

    That router faces an IP WAN—a managed network—and as such is probably not the first of the hacker's targets. But that's not long-term good news, according to my security maven. The first to be targeted may be the wholesale ISPs—the Sprints and MCIs and AT&Ts—whose lines and infrastructure of routers and switches form enterprises' WANs as well as the Internet. Bring that network infrastructure down, and your phone and data system goes down with it. That scenario is the reason why many IP PBXs come with PSTN (traditional Public Switched Telephone Network) lifelines.

    Three days after the announcement of the theft, Cisco itself has no immediate assurance to offer the press. They officially reply:

      "Cisco is aware that a potential compromise of its proprietary information occurred and was reported on a public website just prior to the weekend. Cisco is fully investigating what happened. As a matter of policy, we take security very seriously and we continue to take every measure to protect our intellectual property, employee and customer information. Cisco will remain focused on its customers' success and will continue to monitor the situation."

    I've also contacted major Cisco VOIP systems integrators, none of whom is willing to comment on the potential breach. I finally turned to Christopher King, CCISP, of Principal Security Group and former information security practice director at Greenwich Technology Partners, a major Cisco VAR with an active VOIP practice. I asked him if telecom or IT managers have something new to worry about here. His reply: "Hell, yes."

    He described the situation as a waiting game, while hackers study the IOS source for vulnerabilities, manually code attacks to bring down routers and then automate the exploit (the attack) so that it proliferates throughout the Internet.

    For the complete story, click here.



    Discuss IOS Theft and Telephony: Something New to Worry About
     
    >>> Be the FIRST to comment on this article!
     

     
     
    >>> More Commentary Articles          >>> More By Ellen Muraskin
     


     


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.

     


    CHANNEL RESOURCE CENTER
     
     
    Enterprise Mobility Zone
    The Enterprise Mobility Zone (EMZ) blog is a tool designed to help senior IT executives discuss, create and deploy next-generation mobile strategies in their organizations.
    Go beyond yesterday's tactical approach to mobility!
     
    Build A More Efficient Data Center
    Demands are growing but budgets are not. Solve your pressing IT issues using the resources you already have. Determine which technologies can help you drive efficiencies and how they are applied. Gain a quick ROI on new initiatives
    Find out how
    Let Enterprise TechBrief do the work for you. Aggregated content, tech news, product reviews, vendor updates, how-to’s—all you need to boost your efficiencies and cut costs, all from one place.
    enterprisetechbrief.com