Security Considerations: Difference between revisions

From Integrics Wiki
Jump to navigation Jump to search
Content deleted Content added
No edit summary
No edit summary
Line 1: Line 1:
Technical:
* Disallow routes to countries that customers don't need, especially high fraud countries.
* Disallow routes to countries that customers don't need, especially high fraud countries.
* Set a daily spending limit and maximum concurrent calls limit for all customers.
* Set a daily spending limit and maximum concurrent calls limit for all customers.
* Requiring long password lengths for phones and people.
* Requiring long password lengths for phones and people.
* Educate customers on choosing good passwords.
* Have contracts to make sure the right person pays if they are hacked and run up a huge bill.
* Change the SSH port from 22 to something non standard.
* Change the SSH port from 22 to something non standard.
* Use iptables to lock out countries where you do not have customers.
* Use iptables to lock out countries where you do not have customers.
* Set Asterisk servers to use non default ports for SIP like 5065 instead of 5060.
* Set Asterisk servers to use non default ports for SIP like 5065 instead of 5060.
* Make sure all handsets have a username and password which are not the devices default.
* Make sure all handsets have a username and password which are not the devices default.
* Monitor servers with a tool like Nagios and or Cacti where there is an alert if there is more than X calls per customer, system etc.
* Monitor servers with a tool like Zabbix, Nagios, or Cacti to alert if there are more calls than expected.


Some systems have easySysAdmin or fail2ban (for example) automatically block brute force SSH or SIP registration attacks.
Some systems have tools like SIPSentry to automatically block brute-force SIP attacks.

Secure provisioning with a solution such as:
* Use the source IP setting in Enswitch telephones
* Restrict access by user-agent
* Restrict access to a privately used domain
* Use HTTP basic authentication

Non-technical:
* Educate customers on choosing good passwords.
* Have contracts to make sure the right person pays if they are hacked and run up a huge bill.

Revision as of 22:45, 14 September 2018

Technical:

  • Disallow routes to countries that customers don't need, especially high fraud countries.
  • Set a daily spending limit and maximum concurrent calls limit for all customers.
  • Requiring long password lengths for phones and people.
  • Change the SSH port from 22 to something non standard.
  • Use iptables to lock out countries where you do not have customers.
  • Set Asterisk servers to use non default ports for SIP like 5065 instead of 5060.
  • Make sure all handsets have a username and password which are not the devices default.
  • Monitor servers with a tool like Zabbix, Nagios, or Cacti to alert if there are more calls than expected.

Some systems have tools like SIPSentry to automatically block brute-force SIP attacks.

Secure provisioning with a solution such as:

  • Use the source IP setting in Enswitch telephones
  • Restrict access by user-agent
  • Restrict access to a privately used domain
  • Use HTTP basic authentication

Non-technical:

  • Educate customers on choosing good passwords.
  • Have contracts to make sure the right person pays if they are hacked and run up a huge bill.