Are We Paying Enough Attention to Unified Communications Security?
Securing unified communications is a bigger task than simply protecting each of its composite elements, since entry through one application can lead to problems for another. The reality is that the benefits of the platform are synergistic -- and so are the dangers.
The article, at Help-Net Security, is well-written and a worthwhile read. At the highest level, it can be summed up by the point that each new platform by definition opens up new avenues – both social and technical – for bad people to try to exploit. The situation is even more daunting because, as Boone writes, unified communications “mingles traffic from a host of applications that previously were segregated.”
For example, a successful attack against the VoIP element of a unified communications platform could impact IM, telepresence and whatever other application the organization invited to the party.
A defect in IM, VoIP, conferencing or anything else suddenly becomes an across-the-board threat and challenge. The main point of Boone's article is that unified communications security should be considered as something new. He also suggests that its characteristics – it operates in real time, converges applications, runs across untrusted networks and supports all the new end points employees are using – makes securing it a demanding task.
Every aspect of this innovation involves a multitude of new security concerns. As is the case in all technical innovations, the true security risks that really matter do not become apparent until the technology has been in use for some time.