Voice over Internet Protocol (VoIP) Security and over 360,000 other books are available for Amazon Kindle – Amazon’s new wireless reading device. Learn more

 

or
Sign in to turn on 1-Click ordering.
 
 
More Buying Choices
38 used & new from $22.72

Have one to sell? Sell yours here
 
   
Express Checkout with PayPhrase
What's this? | Create PayPhrase
Sorry!
Voice over Internet Protocol (VoIP) Security
 
 
Start reading Voice over Internet Protocol (VoIP) Security on your Kindle in under a minute.

Don’t have a Kindle? Get your Kindle here.
 
  

Voice over Internet Protocol (VoIP) Security (Paperback)

~ James F. Ransome PhD CISM CISSP (Author), John Rittinghouse PhD CISM (Author) "Have you ever thought to yourself "Why should we do this VoIP thing?" or "What value will voice over Internet provide my company?" or even..." (more)
Key Phrases: signature security profile, baseline security profile, telephone firewalls, Retrieved July, Retrieved August, United States (more...)
3.0 out of 5 stars  See all reviews (9 customer reviews)

Price: $61.95 & this item ships for FREE with Super Saver Shipping. Details
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
Upgrade this book for $11.19 more, and you can read, search, and annotate every page online. See details
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.

Only 2 left in stock--order soon (more on the way).

Want it delivered Tuesday, November 10? Choose One-Day Shipping at checkout. Details
22 new from $35.48 16 used from $22.72

Formats

Amazon Price New from Used from
  Kindle Edition $42.36 -- --
  Paperback $61.95 $35.48 $22.72

Frequently Bought Together

Customers buy this book with Switching to VoIP by Theodore Wallingford

Voice over Internet Protocol (VoIP) Security + Switching to VoIP
  • This item: Voice over Internet Protocol (VoIP) Security by James F. Ransome PhD CISM CISSP

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details

  • Switching to VoIP by Theodore Wallingford

    In Stock.
    Ships from and sold by Amazon.com.
    Eligible for FREE Super Saver Shipping on orders over $25. Details


Customers Who Bought This Item Also Bought

Carrier Grade Voice Over IP (second edition)

Carrier Grade Voice Over IP (second edition)

by Daniel Collins
4.6 out of 5 stars (10)  $33.21
Internet Communications Using SIP: Delivering VoIP and Multimedia Services with Session Initiation Protocol (Networking Council)

Internet Communications Using SIP: Delivering VoIP and Multimedia Services with Session Initiation Protocol (Networking Council)

by Henry Sinnreich
4.3 out of 5 stars (12)  $62.18
Securing VoIP Networks: Threats, Vulnerabilities, and Countermeasures

Securing VoIP Networks: Threats, Vulnerabilities, and Countermeasures

by Peter Thermos
4.3 out of 5 stars (3)  $40.49
Asterisk Hacking

Asterisk Hacking

by Ben Jackson
3.0 out of 5 stars (2)  $37.87
Hacking Exposed VoIP: Voice Over IP Security Secrets & Solutions

Hacking Exposed VoIP: Voice Over IP Security Secrets & Solutions

by David Endler
4.3 out of 5 stars (3)  $34.99
Explore similar items

Editorial Reviews

Review

"Voice Over Internet Protocol Security is both unique and timely. Ransome and Rittinghouse expertly describe the technical fundamentals, salient business drivers, and converged network infrastructure security risks and challenges IT and security professionals encounter when implementing enterprise-level VoIP systems." - William M. Hancock, Ph.D., CISSP, CISM, CSO, Savvis Communications.

"This book should be required reading for anyone contemplating a VoIP implementation for three reasons: first, it deals with telecom technology and standards from Alexander Graham Bell onward. This puts VoIP in its proper context as an integral, evolved part of a global system that is potentially vulnerable. Second, it provides a detailed tutorial on all of the major aspects of VoIP implementation from a pragmatic point of view. Finally, it addresses the very real security issues that could put the global telephone system at risk if not dealt with professionally. I would heartily recommend your entire project team buy this book and read it carefully!"- John Milner, MIS Director, Cambridge University


Book Description

First book to focus exclusively on VoIP Security the fastest growing portion of telecom/CS Communications

Product Details

  • Paperback: 432 pages
  • Publisher: Digital Press (December 3, 2004)
  • Language: English
  • ISBN-10: 1555583326
  • ISBN-13: 978-1555583323
  • Product Dimensions: 9.1 x 7.3 x 1.1 inches
  • Shipping Weight: 1.9 pounds (View shipping rates and policies)
  • Average Customer Review: 3.0 out of 5 stars  See all reviews (9 customer reviews)
  • Amazon.com Sales Rank: #1,526,732 in Books (See Bestsellers in Books)

More About the Author

James F. Ransome
Discover books, learn about writers, read author blogs, and more.

Visit Amazon's James F. Ransome Page

Inside This Book (learn more)
First Sentence:
Have you ever thought to yourself "Why should we do this VoIP thing?" or "What value will voice over Internet provide my company?" or even "What is all this VoIP craze?" Read the first page
Key Phrases - Statistically Improbable Phrases (SIPs): (learn more)
signature security profile, baseline security profile, telephone firewalls, call setup performance, call setup protocols, call control server, telephone scanners, gateway control protocol, call setup process, supervisory signaling, reconstructed speech, toll fraud, traffic flow confidentiality, telephony server, wiretap statute, voice gateway, redirect server, reconstruction levels, converged network, infrastructure risks, switch hook, protected computer, security gateway, silence suppression, jitter buffer
Key Phrases - Capitalized Phrases (CAPs): (learn more)
Retrieved July, Retrieved August, United States, General References, Session Initiation Protocol, Infrastructure Risks, Security Considerations, Authentication Header, Cable Act, Cisco Press, Executive Order, Attorney General, Stream Control Transmission Protocol, Free World Dial-Up, Internet Protocol, Media Gateway Control Protocol, Multiprotocol Label Switching, Next Header, North America, Session Description Protocol, User Datagram Protocol, Virtual Private Networks, Address Resolution Protocol, Computer-Related Laws, Coordination Center
New!
Books on Related Topics | Concordance | Text Stats
Browse Sample Pages:
Front Cover | Table of Contents | First Pages | Index | Surprise Me!
Search Inside This Book:




What Do Customers Ultimately Buy After Viewing This Item?


Tag this product

 (What's this?)
Think of a tag as a keyword or label you consider is strongly related to this product.
Tags will help all customers organize and find favorite items.
Your tags: Add your first tag
 

 

Customer Reviews

9 Reviews
5 star:
 (4)
4 star:    (0)
3 star:
 (1)
2 star:    (0)
1 star:
 (4)
 
 
 
 
 
Average Customer Review
3.0 out of 5 stars (9 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
21 of 23 people found the following review helpful:
1.0 out of 5 stars I am IP_Geek, July 15, 2005
By VoIP_Geek (Boston, MA) - See all my reviews
[note: I am the same reviewer IP_Geek, but Amazon only lets you review once, so this is follow up]
Despite what Dr. Michael G. Mathews may believe, I really wanted to use my real name, and I have never worked for Exodus (although they may have been a customer of one of the companies I worked for, unknown to me). I have worked at 4 networking vendor/manufacturer companies, of which 2 were data vendors (routers/switches) and 2 VoIP companies. I currently work at a vendor who makes VoIP security products, and thus I felt it a bit unfair/dangerous to my employer to critique any book in a public forum. (because you can google my name and find out where I work)
I still feel that way, so I will try to convince you I have no agenda as easily as I can as follows:
1) My argument was simply that you should VERY carefully read the table of contents, including the page numbers. Dr. Mathews is quite right that this type of book will appeal to some people, just that in my humble opinion I hope those people are not put in charge of securing VoIP, because this book doesn't do it. (see below why)
2) I did not slam the authors in person or capabilities - I slammed the book they wrote. This book was published fairly recently (6 months ago), and this book is written from a VoIP perspective of several years ago, in my opinion. It is missing tons, and contains lots of frankly irrelevant content to the subject. If the title of the book "VoIP Security" is not meant to actually mean this is a book about VoIP Security, then I guess I don't understand what book titles are for. The back cover even says "This book will teach you how to plan for and implement VoIP security solutions...". I am taking issue with that statement, not the authors personally.
3) I think some people may like the book, because they are not already experts in VoIP security and thus don't know what they're missing. I believe I am pretty close to an expert. I was looking for a book I could recommend to my customers and colleagues who are not.
4) Dr. Mathews says "It addresses the protocol specifics, the technical issues, and the security options surrounding the protocol." I think that it addresses them if you don't know what they really are. I will tell you what I know is missing from this book:
a) TLS. Much of the VoIP industry believes TLS to be the future panacea for VoIP service security. (it's not used much today, but many are moving that way) That belief is true for eavesdropping protection/privacy, and server-side authentication. It is not true for DoS/DDoS attack protection, or user-side authentication. It is also not true for fraud prevention, and it adds many scalability/performance issues. The reasons for that, how SIP over TLS works at a protocol level, and more interestingly the security issues around it are not addressed in this book. That should be a whole chapter. As a side note, they say TLS requires TCP, which was true until the draft for DTLS came out for TLS over UDP, which has received much publicity in the VoIP security world. It came out in 2003 - long before this book was finished.
b) IPSec. The 3GPP/IMS world and some inter-carrier VoIP peering uses IPSec to secure VoIP, which like TLS only provides some security features/benefits but not others. Used by enterprises it also adds latency to RTP (because they use it in tunnel mode over TCP). I give the authors some credit - they did spend 10 pages on the VPN issues with IPsec (but it's not exactly how 3GPP uses it). I still think this topic should be a whole chapter.
c) SRTP. How SRTP is performed, from a protocol level and hardware/software level, leaves much to be desired. There is in fact much debate in the industry if it is needed at all, how it can be managed, how CALEA can be supported with it, etc. SRTP also does not protect the gateways/phones, and the implementation of it is the critical piece as to whether it's any good at all. The authors spend a couple pages on it - I would probably spend at least half a chapter on it - perhaps by removing the big section on how codecs work (which has virtually no relevance to VoIP security compared to this list). The fact there are different codecs is important, but not the formulas for the plot curves of A-law and u-LAw!
d) S/MIME. Some voip products do it, but most don't, and it breaks some things. Again, the protocol and security issues with S/MIME are not covered in much detail in this book. (although it's covered over at least a few pages, just not enough I think)
e) VoIP Firewalls. One simply cannot lump that into one group. The differences in feature/architecture/functionality between categories of friewalls (not to mention models/brands), and how you use VoIP with them, is so critical I'm literally shocked there isn't a ton more detail on this. Look at other security books for data. There are entire books about just a particular firewall brand. (not that this book should get to that level of detail)
f) STUN/TURN/ICE. They are mentioned briefly, but really these technologies/protocols are another pandora's box of security issues, and should be addressed if crossing NAT's is at all useful for you. Likewise, Session Border Controllers are mentioned briefly in this book, but they are considered by most to be one of the fundamental pieces in VoIP security.

ok, enough time spent. I'm sorry for the length of this reply. Again, this book may appeal to you (to each his own), I just caution you that there is a lot more under the Voip security hood than is mentioned in this book.
I'm sure the authors are good guys - perhaps they wrote this book a long time ago and printing/publishing books is just too much delay to keep up with technology.
(although I'm still struggling to understand how 30 pages of codec waveform detail helps any voip security person)
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
22 of 25 people found the following review helpful:
3.0 out of 5 stars Did not live up to expectations, April 30, 2005
I decided to read 'VoIP Security' because I thought it would describe VoIP protocols and ways to secure them. The table of contents looked very strong and the preface seemed to meet my goals: "For one to truly understand Internet telephony, the reader must have a solid understanding of digital voice, telephony, networking, Internet protocols, and, most important of all, how all of these technologies are put together." Unfortunately, the book is confusing at times and is not an improvement over earlier VoIP security books. So-called 'reviewers' who write that this book 'goes heavily into explaining the low level mechanics of VoIP' reveal they don't read the books they purport to review.

Chapters 1, 2, and 3 discuss reasons to use VoIP, how voice is encoding into digital form, and telephony history. I found the wire pair discussions in ch 3 confusing; additional diagrams might have helped. Some text in the existing figures is so small as to be nearly illegible. Ch 4, on 'packet technologies,' is the worst in the book. Many of the 'functional activities by layer' in figure 4.1 are wrong (e.g., routing at layer 2). Page 89 says 'the IP identification number is mainly useful for identifying anomalous signatures.' While IP fragmentation is mentioned, that correct function of the IP ID seems played down.

The most frustrating part of ch 4 is the sudden discussion of the H.235 protocol, with absolutely no introduction to its purpose or what it is. This is especially unfortunate as the preceding 20 pages were wasted describing basic IP networking. H.235 is not explained until ch 8. Similarly, p. 102 and elsewhere compares SIP to H.323, without explaining H.323 or SIP! H.323 is tangentially covered in ch 8, and SIP makes an appearance in ch 5. A chapter that should have been the core of the book -- explaining VoIP protocols -- is its weakest. At the very best, this shows the book is poorly organized.

After presenting generic VoIP deployment issues in ch 6, ch 7 catalogs various VoIP security risks and ch 8 offers VoIP security best practices. I was surprised to realize that chs 7 and 8 are the only sections that really mention security at all, in a book called 'VoIP Security.' I did not find this material compelling, as much of it delivered generic security guidance -- some of it wrong. On p. 192 we read that 'Linux can be crashed with one pair' of fragmented IP datagrams (wrong). On p. 193 we read 'each broadcast address can support up to 255 hosts' (wrong, only true for /24 netblocks). On p. 263 we read 'rather than looking at one frame at a time, as with firewalls, NIDS usually don't add delay because they look across a broad collection of frames flowing in either direction' (what?). I got the impression this book suffered due to lack of digital security experience on the part of the authors and editors; they seemed much more like telecom practitioners.

Ch 9 presents legal issues in security (not really related to VoIP), and ch 10 concludes with a short 'future of VoIP.' I finished this book not much more informed about VoIP security than when I started. In fact, I turned to the older 2001 SAMS book 'Voice and Data Security' by Archer, et al, and found it covered protocols and security issues much better than 'VoIP Security.'

If Elsevier decides to print a new edition of this book, they should encourage the authors to take a hard look at what they discuss and where they discuss it. They should also consider what they omit. I think a real VoIP security book should explain how to configure and deploy the open source PBX Asterix and a VoIP proxy like siproxd for SIP. The new edition should do more than mention tools like 'voice over misconfigured internet telephones'; show them and others in action. Avoid the generic network and security discussions and concentrate on the topic at hand.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
3 of 4 people found the following review helpful:
1.0 out of 5 stars Worst tech book I have ever read., April 16, 2006
This will end up being the worst tech book I have every read. The book starts off with lofty goals and ends up achieving none. None of the topics are presented properly. As pointed out in various reviews, chapter 4 is where the nightmare begins. That is not to say that the first three chapters are good, because there's really nothing worth reading in those first few pages.

The authors do NOT do justice to VoIP, to security, and to VoIP security.

Don't waste your money on this book.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews

1.0 out of 5 stars False advertising
BAsed on some good and some bad reviews, I bought the book to see for myself. Let's just say I gave the book away for free, because it's not worth the bookshelf space. Read more
Published on October 11, 2005 by Mike Alborn

5.0 out of 5 stars SOAKING IN THE HOW AND WHY OF VOIP SECURITY
There are many unanswered questions about VoIP security as there are solutions. Authors James F. Ransome and John Rittinghouse have done an outstanding job of making sure that you... Read more
Published on August 12, 2005 by John R. Vacca

5.0 out of 5 stars Emotional Reviews versus Technical Reviews
After reading this book completely (including the pages before the number "1"), I must say that I find this book to address the intended audience quite well. Read more
Published on July 4, 2005 by Dr. Michael G. Mathews

5.0 out of 5 stars Sure to be a dog-eared reference for Managers/Executives
IP based telephony is hear to stay exposing yet another technology to IT teams. This book is a great reference for this new technology. Read more
Published on June 27, 2005 by Terry L. Dalby

5.0 out of 5 stars excellent reference
This is a valuable reference for the "non-VoIP" person. It delves into the fundamentals as well as security. Probably more geared to the InfoSec Manager. Read more
Published on May 18, 2005 by Vern A. Duebendorf

1.0 out of 5 stars Not a Voip Security book
This book shows one of those rare times when reading the table of contents tells you a lot if you're careful. Unfortunately, I wasn't being careful when reading them. Read more
Published on May 3, 2005 by IP_Geek

Only search this product's reviews



Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 


Active discussions in related forums
Discussion Replies Latest Post
Textbooks for Kindle DX? 61 23 hours ago
textbook scam 66 5 days ago
Amazon is a great place to buy textbooks! 35 17 days ago
Search Customer Discussions
Search all Amazon discussions
   
Related forums



So You'd Like to...


Create a guide

Product Information from the Amapedia Community

Beta (What's this?)


Look for Similar Items by Category


Look for Similar Items by Subject

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.


Your Recent History

 (What's this?)

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.