IT Security - Tips, Trends, News

Wednesday, December 28, 2005

Back to VoIP - Some Excellent Resources

I found these resources for VoIP at www.voip-info.org - it's a really excellent resource.

Debugging and troubleshooting VOIP problems. (SIP, MGCP, H.323, Skinny etc.) One of the primary techniques is to view what is actually getting sent and received by VOIP devices. There are several ways to do this:
Monitor Ethernet Traffic
Debugging displays from a VOIP program It helps to understand whats supposed to be happening. Studying the relevant RFCs and other protocol documents and tutorials is helpful.
Ethernet Monitoring Tools
Ethereal (Available for Linux, Windows, Apple, BSD, etc.)
Support for decoding many VOIP protocols is included (including IAX)
tcpdump (standard utility in most Linux distributions)
WinDump - tcpdump for Windows
ngrep (Available for Linux, Windows, Apple, BSD, etc.)
Dumps only the ASCII portion of packets, excellent for ASCII based protocols
Packetyzer: User-friendly packet sniffer for Windows, supports SIP
List of Monitoring and sniffing software
Rate which provides real time packet-per-second and data transfer rates
many other tools available for this function, add your favorite to this list!
Built-in Debug Tools
xten The x-lite and x-pro SIP soft phones have a buit-in display and decoding of received and sent SIP packets (Hit F9 to activate)
Asterisk Use the sip debug command
linphone Outputs useful diagnostics to the console as it uses the oSIP library
Traffic generators
Candela Technologies LANForge FIRE VOIP/RTP/PESQ call generator
Empirix Signaling and Media load and feature testing
GL Communications
PacketGen - generates SIP calls with or without RTP traffic
PacketScan - monitor, collect, and analyze QoS statistics on VOIP traffic
Integrated Research Prognosis will simulate, record and analyze VOIP traffic in real time.
Iperf creates network traffic and measures performance
Can be used to test a network to see how it might perform with increased VOIP traffic
Ixia VOIP traffic generators and Network assessment tools
Sipp SIP Performance Test Tool - Performance tester for SIP
Touchstone 100% software-based VoIP and video verification tools.
WinSIP - SIP signaling and Audio/Video media generator
Win323 - H.323 signaling and Audio/Video media generator
Monitoring and Test Tools
ACQUA: VoIP Speech Quality Analysis System
Agilent Technologies DNA MX and TNA software
Brix Networks real-time VoIP performance management and service assurance solutions
ClearSight Networks ClearSite Analyzer
Consultronics
Empirix monitoring and analysis
Fluke Networks OptiView VoIP, ProtocolExpert Plus and Link Analyzer
Inet GeoProbe IP
Hammer Call Analyzer
Malden
Minacom QOS monitoring and testing
NetTest monitoring of QOS and network performance
NetIQ monitoring of QOS and network performance
Packet Data Systems Clarinet Protocol Test System
Simulation and analysis of SIP, SIP-T & H.323. QOS measurement, recording, replay etc.
Psytechnics monitoring of QOS
Qovia monitoring of QOS
Rochelle Analog QOS products - can be used with an ATA
Sage Instruments VOIP test equipment and systems
Telchemy monitoring of QOS
Their technology appears in numerous other products list
Touchstone WinEyeQ
100% software-based
monitors/analyzes/records/replays SIP and H.323 traffic, audio/video media and QOS.
Viola Networks NetAlly RealTime and VoIP Assessment
WildPackets EtherPeek VX - monitor QOS, packet loss, voice quality, etc.
See Also:
Call Quality Metrics
Network World Review of 7 VOIP Analysis Tools
Network Impairment Simulators
Apposite Technologies Linktropy 4500 hardware appliance to emulate WAN bandwidth, delay, and loss up to 155 Mbps.
Candela Technologies LANForge ICE Network Emulator
UDP Packet Reflector and Forwarder open source tool that can drop packets, duplicate packets, and add jitter on a per port basis.
IPWave simulates many types of network impairments
NIST Net allows a single Linux PC set up as a router to emulate a wide variety of network conditions
Simena Network Emulator hardware appliance can simulate just about any possible network condition including latency, bandwidth, congestion, packet loss, etc. Test where your VoIP will break!
Decoding VOIP audio streams There are several approaches to converting an RTP stream of packets into a playable audio. See: Converting RTP to audio
SIP Debug
Callflow - creates a diagram of SIP flows
Sipsak Command line utility for testing SIP devices and Programs
SIP Scenario - creates a diagram of SIP flow
siptest a command line test tool for sending and receiving SIP messages
sipviewer a visual SIP message trace tool
SIPFlow Standard - Java tool for displaying SIP traffic captured in real-time, or imported from Ethereal or tcpdump
Distributed SIPFlow - Distributed application for capturing and displaying SIP callflows.
Protocol Debug
Protocol Verification and Testing
Other Sites
http://www.voiptroubleshooter.com/ Entire site focused on VOIP troubleshooting
http://www.broadbandreports.com/tools Diagnostic, testing, and monitoring tools
http://www.testyourvoip.com/ Test your connection performance to one of serveral locations.
See also
Asterisk debugging

All the best,
Gary

Wednesday, December 21, 2005

NetClarity Files Patent Application for Proactive Network Security Using RSS

Method Leverages XML-based Vulnerability Tests, Alerts and News Feeds to Dynamically Reconfigure Countermeasures to Block Threats in Real Time


BEDFORD, Mass.--(BUSINESS WIRE)--Dec. 21, 2005--NetClarity, a leading provider of network vulnerability products and services, has filed a patent application with the United States Patent and Trademark Office (USPTO) for preemptive, proactive protection of networks using non-traditional and untapped RSS and XML sources, such as the Open Vulnerability Assessment Language (OVAL), an international standard managed by MITRE and funded by the U.S. Department of Homeland Security. The patent application, titled "Proactive Network Security using Really Simple Syndication (RSS) Feeds," includes unique methodologies to better protect networks, quarantine untrusted network equipment and malicious insiders, and bolster the security of trusted but weak network assets against attack and downtime.

More can be found here at http://www.netclarity.net/

Sunday, December 18, 2005

I just wrote a White Paper on Visa (PCI) and MasterCard (SDP) Compliance

Self-assessment for Payment Card Industry (PCI) Standard - December 2005

To view the White Paper, please visit http://www.netclarity.net/ or click the link below:

Visa, MasterCard and other payment card companies have collaborated.... Click here for the full Whitepaper. Download as a PDF....

Feel free to comment. Thanks - Gary

Wednesday, December 07, 2005

I will be speaking on VoIP Security at HSNI2006 and ITExpo - Two Upcoming Tradeshows in January 2006

Links and Excerpts - Hope to see you there :-)

http://www.tmcnet.com/voip/conference/voip-06/fl-06-conferences.aspx?t=S#S-01

Back To School With VoIP Security(S-01)Friday - 01/27/06, 8:30-9:15am
This panel discussion featuring the Associate Director, Enterprise Communication Systems at the University of Cincinnati, will address what is required for a robust, secure IP telephony network. The panel will be able to discuss and answer the following: • What are the steps in having a secure, IP telephony network? • What does an enterprise need to be aware of before rolling out a converged network? • How can an enterprise protect itself against the growing number of vulnerabilities that may attack the VoIP infrastructure? The University of Cincinnati recently installed a secure, converged network that in one month blocked more than 1.5 million assaults. Come hear this compelling tale of a real life deployment and what the University went through to achieve secure scalable VoIP.

http://www.hsni2006.com/Agenda.htm
Securing Your Voice over IP"

Monday, December 05, 2005

NetClarity VoIP Security Patent Filing Today

NetClarity Files Patent Application for Proactive Network Security for Voice over IP (VoIP) Networks

NetClarity CTO to Discuss VoIP Security at the Homeland Security for Networked Industries 2006 Conference & Expo

BEDFORD, Mass.--(BUSINESS WIRE)--Dec. 5, 2005--NetClarity, a leading provider of vulnerability and intrusion management appliances, announced today that is has filed a patent application with the United States Patent and Trademark Office (USPTO) for preemptive, proactive protection of VoIP networks. The patent application, titled "Proactive Network Security for Voice over Internet Protocol (VoIP) Networks," includes unique methodologies to harden VoIP networks against attacks, quarantine untrusted VoIP equipment being used for eavesdropping or by malicious insiders and bolster the security of trusted but weak VoIP equipment against attack and downtime....read on at http://www.netclarity.net/