Protecting Against Eavesdropping Attacks

Eavesdropping attacks are also known as phone tapping attacks. The main goal is for an attacker to listen, copy, or record a conversation. An example of an eavesdropping attack is an incident reported back in 2006. The phones of about 100 Greek politicians and offices (including the U.S. embassy in Athens and the Greek prime minister) were compromised by a malicious code embedded in Vodafone mobile phone software. The attackers tapped into their conference call system. Basically, by using several prepaid mobile phones, the attackers "joined the conference call" and recorded their conversations.

The Cisco ASA, Cisco PIX, and IOS Firewalls provide several features that support the stateful processing of signaling protocols, H.323, and SIP. These devices monitor the specific connection request and required resources and permit only what is specifically necessary for the operation of the system, thereby protecting against session hijacking and spoofing.

The Cisco ASA and Cisco PIX security appliances support H.323 inspection by making sure that only compliant transactions are allowed between IP telephony devices, such as Cisco CallManager and other non-Cisco products. Cisco ASA and Cisco PIX support H.323 Versions 3 and 4. They also support multiple calls on the same call signaling channel. Example 9-5 demonstrates how you can configure an H.323 inspection policy map on a Cisco ASA or Cisco PIX security appliance running Version 7.2 or later.

Example 9-5 Dynamic Port-Security my_asa(config)# regex phonel "5551234567" my_asa(config)# regex phone2 "5553213212"

my_asa(config)# class-map type inspect h323 match-all voice-traffic my_asa(config-pmap-c)# match called-party regex phonel my_asa(config-pmap-c)# match calling-party regex phone2 my_asa(config)# policy-map type inspect h323 h323-policy-map my_asa(config-pmap)# parameters my_asa(config-pmap-p)# class voice_traffic my_asa(config-pmap-p)# rtp-conformance enforce-payloadtype my_asa(config-pmap-c)# drop ciscoasa(config)# service-policy h323-policy-map interface inside

In Example 9-5, two regular expression entries are configured for two specific phone numbers (5551234567 and 5553213212). This is an optional step, but it gives you the flexibility to inspect traffic based on a specific caller or called party. A class map called voice-traffic is configured to inspect all traffic between the two previously defined phone numbers. The class map is applied to a policy map called h323-policy-map. All noncompliant traffic is dropped. The rtp-conformance enforce-payloadtype parameter is used to ensure that all transit RTP packets comply with protocol specifications. Finally, the policy map is applied to the inside interface using the service-policy command.

IPS and IDS devices can also be placed in strategic areas within the network to detect unusual traffic, such as an attempt to execute an unusual command, or a malformed packet indicating some form of protocol manipulation.

A good way to protect your voice traffic in untrusted environments is by the use of the voice- and video-enabled VPN (V3PN) solution. V3PN provides secure site-to-site connectivity to transport voice, video, and data. With V3PN, you can enable remote branch offices and teleworkers to use IP telephony services while reducing business operations costs.

NOTE The following white paper includes detailed information about V3PN design and implementation:

http://www.cisco.com/application/pdf/en/us/guest/netsol/ns171/c649/ ccmigration_09186a008074f2d8.pdf

Media encryption using Secure Real-Time Transport Protocol (SRTP) delivers protection by encrypting the voice conversation, rendering it unintelligible to internal or external eavesdroppers who have gained access to the voice domain. Designed for voice packets, SRTP supports the AES encryption algorithm and is an Internet Engineering Task Force (IETF) RFC 3711 standard. Media encryption on Cisco access routers works with both Cisco CallManager and the media encryption feature on Cisco IP phones, enabling customers to place secure analog phone or fax calls between an IP phone and the PSTN gateway depending on the gateway interface type. The SRTP-encrypted voice packets are almost indistinguishable from RTP voice packets, allowing features like QoS and compression to be implemented without additional development or manipulation. Voice encryption keys derived by Cisco Unified CallManager are securely sent by encrypted signaling path to Cisco Unified IP phones through the use of Transport Layer Security (TLS) and to gateways over IPsec-protected links.

Continue reading here: SYN Cookies in Firewalls and Load Balancers

Was this article helpful?

0 0