When Cloud technology first burst onto the scene, there was one major question mark which made business users hesitant to jump straight in - security.
As was true in most technology sectors, the benefits of the Cloud were quickly apparent in telecoms. Flexible, hassle-free deployment, high levels of scalability, increased mobility, reduced costs and speedier access to upgrades and new platforms all made a strong case to adopt cloud communications.
But concerns over security were genuine and enduring. With compliance issues over data protection and privacy high on the agenda of customer-facing operations, many enterprises felt uneasy about passing control of their critical communications infrastructure to a third party.
And how secure was the Cloud, anyway? Being built on the internet was hardly a ringing endorsement, not with the multi-billion dollar cybercrime industry which feeds on the web's vulnerabilities achieving such a high profile. Surely moving your communications onto the Cloud would just expose you to the risks of hacking, identity theft, DDoS attacks, malware and eavesdropping?
Cloud communications has come a long way since those early days, and one of its most significant areas of technological development has been in devising enterprise-class security protections designed to counter those risks. Nowadays, most analysts agree that a hosted cloud service is just as secure, if not more so, than any private IT and comms network linked to the internet.
As part of our Technology Track series, we thought we'd take a closer look at how far /unified-communications/ucaas has come, and what technologies keep cloud communications secure these days.
Session Border Control
One of the main security challenges cloud communications vendors had to overcome was the fact that the standard buffers used to protect a networked system - firewalls - were not designed for communications data. This meant if you wanted to use a cloud-based UC solution for external communications, for example a hosted PBX, you had a problem - it would create vulnerabilities in your entire network.
This goes back to something fundamental about the way the internet was designed. The internet works by breaking data down into manageable packets at source and then reconfiguring them in their original form at destination. There is always a slight delay in this process, barely perceptible with a good CPU, but a delay nonetheless.
For the data the internet was designed to carry - text, images - this slight delay does not matter. But for real-time voice and video communication, it becomes noticeable. It affects the quality of audio and picture definition, and if it builds up can cause buffering.
The answer came in the form of Session Initiation Protocol (SIP), which sits on top of standard IP and allows real-time communication to happen fluidly and with no loss in quality. However, the arrival of SIP created a security problem. Standard firewalls are not designed to work with it.
So in a modern, integrated UCaaS system, where you run your business comms through your main IP network and connect to external telephone lines via a SIP trunk, a standard firewall would not keep your system safe. In fact, as UCaaS systems usually use multiple ports to share multiple types of communication via multiple types of network connection, you actually create numerous holes in your network security.
The answer is Session Border Control. Designed to work with SIP, a Session Border Controller (SBC) manages the flow of all types of communication on an IP network, and therefore everything on a UCaaS solution. It effectively acts as a SIP firewall, controlling what comes in and out of your network, and therefore resolving many of the early security issues surrounding cloud communications.
SBCs should be added at every individual site within a network to provide comprehensive security.




