Monday, February 10, 2014

VoIP Quality and Security

The day and age of analog landline phones are going to the wayside and becoming a nice to have but not necessary staple of today's society. Cell phones and now VoIP appears to emerging in today's technology and becoming more popular. VoIP or Voice over Internet Protocol is a method for taking analog audio signals and turning them into digital data that can be transmitted over the internet. VoIP has been around for a while, but has recently made waves in today's market with it's enticing cost savings. However, with VoIP, quality and security can be a major task to ensure it's availability, integrity, and confidentiality in today's cyber driven world.


When dealing with the internet in general, quality of service is vital for businesses. VoIP is not immune to problems and is subject to latency, jitter and packet loss. As you can imagine getting choppy messages and/or bits and pieces of a conversation is not ideal and is not, by any means, an accepted practice at any level using VoIP. Let's discuss latency, jitter and packet loss. Latency is essentially the time it takes the data to get from the source to the destination. Latency will vary depending on the speed of the network, what components are used, and how secure you want your VoIP communication. Security is often sacrificed some for better quality to decrease latency. When packets of data have different latencies and arrive at different times, this is called jitter. Sometimes jitter can cause packet loss if the delay is so great. As you can imagine finding the right balance of network eqipment, security and network service will be key for a successful VoIP deployment.


As we mentioned above security is sometimes sacrificed to improve quality of VoIP. However, if you have less security, a business or your home could be subject to hackers and denial of service (DoS) attacks. With any internet related services protocols are utilized. There are 2 most common of protocols with VoIP. These 2 types of protocols are H.323 and Session Initiation Protocol (SIP). H.323 is a standard foundation for multimedia communications across IP-based networks and is an umbrella recommendation by the International Telecommunications Union (ITU). SIP is structurally a faster protocol than H.323. The use of the H.323 protocol presents a huge security concern as it uses random ports thus leaving ports in a firewall open and susceptible to other traffic. So a stateful firewall and/or application firewall is required to ensure consistency of the characteristics of the connections. Also, just like with any IP related information and voice conversations it is susceptible to hijacking, cyber attacks, and tampering. Just like H.323, SIP presents the same attacks and vulnerabilities with using random ports thus leaving holes in the firewall. In order to protect SIP networks, the use of TLS or Transport Layer Security which is an upgrade from the known SSL or Secure Sockets Layer. What TLS does is it provides an encrypted channel that allows SIP messages to be sent. TLS encryption relies on digital certificates by use of the public key cryptography. When using SIP, make the firewall you choose or use is SIP-aware



VoIP is an emerging market and at some point will probably replace the old analog phone system. With that in mind, VoIP will continue to evolve and security will improve as well as quality. The key to a successful deployment and implementation of VoIP especially in businesses is to find a happy medium between quality and security. As what was said earlier, to improve quality you have to sacrifice security. With this concept in mind, defense-in-depth concept of security should be utilized to ensure a company's network safe from outside threats.

Friday, January 31, 2014

Backup and Security Settings in Windows XP

Windows XP has been the mainstream operating system for years and is still used quite frequently in today’s workflow. However, all things must come to an end and the time for Windows XP is evaporating quickly. With this in mind, I thought I would rehash on a topic that has been discussed. This topic is backup and security settings in Microsoft Windows XP.


In this day and age with all the hacker, cyberthreats, viruses, malware, rootkits, adware doing a regular backup is always a good practice. Windows XP comes with a backup utility that usually is sufficient for most users. Some prefer third party backup solutions that offer more robust options in sophistication and flexibility, but the native backup utility is fairly sound and does a good job. A few notes with the backup utility to be aware of and take advantage of is the type of backups, using the wizards and using the advanced options. There are several types of backups to choose from and these include normal, copy, incremental, differential and daily. Choose one that best suits your needs. Incremental should be your ideal backup as it backups files only if they were created or modified since the last backup operation completed and marks them as backed up. Another good tool is using the wizard to accomplish your backup task. The wizard makes the complex tasks into a simpler task going through step by step so you don't oversee a key setting. Last there is the advanced options to consider. These include important settings such as do you want the backup to append or replace older backups and whether a backup is scheduled to run on a regular basis.


Security settings are very important with such such an older operating system and with Windows XP almost on it's way out you better make sure everything is in order. Some of these settings include account types, passwords, firewalls, antivirus software and software patches. This isn't just a Windows XP setting, but goes for all Windows operating systems, is to make normal users have basic rights and not have administrator rights. Also USE PASSWORDS to log into a computer and have your screensaver password protected as well. Passwords are key and make them complex. Passwords that originate from words should not be used and use combinations of numbers, upper case letters, lower case letters, and special characters to help lessen hackers cracking your passwords. Another way to make you computer more secure is to keep you computer updated and patched through Windows Update. As new vulnerabilities arise, Microsoft pushes out updates and ready for you to install. Also employ a firewall and antivirus as a way to mitigate threats. Windows XP offers a free antivirus program with Microsoft Essentials and a firewall is built in on Windows XP. However do your homework and compare antivirus programs. There some better than others so choose wisely if you want to keep Windows XP running flawlessly.


These are just a few tips on the backup utility and security settings Windows XP has to offer. Spend some time and make your computer more secure. It will save you in the long run. However, my advice is spend some money and upgrade to at least Windows 7. Windows 7 offers a solid operating system with tons of features and is more secure.  

Wednesday, January 8, 2014

Windows 8 Security


There are some that dislike the new Windows 8, some like Windows 8 and some that are neutral. Windows 8 has some advantages and disadvantages over Windows 7 and XP. Windows is no longer supporting XP so any security holes in that operating system won’t get fixed. Windows 7 is great, but still has it’s flaws. Windows 8 is emerging, but still has question marks. However, before you make some rash decisions on discounting Windows 8 and their features let’s talk about the security Windows 8 provides in the ever so changing cyber security world. 

Windows 8 provides some great features not offered from Windows 7. One of the newest security feature includes a new boot system called the Unified Extensible Firmware Interface (UEFI). This replaces the old Basic Input/Output System (BIOS) as we have been accustomed to in the past. UEFI adds new boot features and as well speeds up the startup process (something we all would like). One of the features with the new UEFI is the Secure Boot. This feature helps prevent and reduce unauthorized operating systems and malware from running at startup. The potential of Secure Boot would make it more difficult for outsiders to access your files by way of bootable discs or thumb drives and having root kits infecting your computer. If you have an older computer that had Windows 7 installed or an earlier version chances are you still have the BIOS architecture with no option for UEFI, so you maybe have to dig into your wallet and by a newer machine to take advantage of Secure Boot.

Another interesting feature recently implemented is the Early Launch Anti-malware (ELAM). ELAM is basically a driver that launches first before other boot start drivers. This driver helps evaluate those boot drivers and helps the Windows kernel determine whether or not they should be loaded and initializes, thus preventing such malware to infect your computer. System administrators also can manipulate it’s effectiveness by using custom policies which is extremely helpful for businesses.

Also with Windows 8 there is no need to install Windows Security Essentials, Microsoft’s free anti-virus software if you plan on staying free and using that service. Why? That’s because Windows 8 has antivirus already integrated into the operating system with Windows Defender. However, if you buy a new computer and have a third-party antivirus program installed, Windows Defender could be disabled already so just be aware. However, don’t think your computer is completely safe from attacks. Be proactive. Be informed. Compare anti-virus programs and weigh the pros and cons of each. Most important of all make sure you have some sort of anti-virus and make sure it is active.

There are a couple more added security features included with Windows 8 such as Sandboxing with AppContainer and the Portable Enterprise Security. The sandboxing with AppContainer is an added feature due to the ability to install apps and containing those apps if they potentially are infected malicious apps. The portable enterprise security uses a feature called Windows To Go. This feature if adopted by a business allows a pre-configured installation of Windows 8 can be installed to a approved USB thumb drive and be launched from it. 


All in all Windows 8 has plenty of great security features that are better than Windows 7 as a base package. Honestly, I am pleasantly pleased with Windows 8 and it’s security despite all the negative comments around saying it is too much change. As times are changing and the cyber threats continue to manifest, I accept these changes and Windows 8.