Cataleya's Orchid Link SBC recently underwent thorough SIP security testing and was granted a SIP Security Certification by Velona Systems Limited.
I chatted with Cataleya CEO, Andreas Hipp, to understand the meaning of the new certification and discuss the importance of SIP security for SBCs.
Why is SIP Security Important for SBCs?
SIP, standing for Session Initiation Protocol, is a signaling protocol used to initiate, maintain, and terminate real-time communication sessions like VoIP (Voice over IP) calls.
In the early days of VoIP networks, when network elements and endpoints (i.e., phones) suddenly became accessible via the public internet, the initial task of an SBC was to protect IP communications sessions, acting as an intermediary between the internal network and external networks and fending off attacks and access from illegitimate sources.
As fraudsters and hackers are getting more sophisticated, using the SIP protocol to harm business networks – by inserting malformed packets, for example, which can lead to security breaches, unauthorized access, or service disruptions – the SIP-related defense capabilities of SBCs need to be extremely sturdy.
"Very often, if attackers hide the malformed packets and the fraud attacks in the SIP signaling – firewalls will not pick it up," Hipp notes.
"This means fraudulent traffic will transit through the company's firewall and go through the SBC, finally ending up at the endpoints. That's where enterprise customers' PBXs are often hacked, and they then have to pay the telco bill for that fraudulent traffic."
What Does a SIP Security Certification Check?
Simply put, achieving a SIP Security Certification for an SBC involves assessing the level of security and protection it provides within a VoIP network.
"The primary function of a core network SBC is to protect the core network servers from deliberate or accidental attacks that could lead to Denial of Service (DoS), fraud, or damage to the business's privacy," Hipp explains.




