Light Reading

Covergence Banks on SIP Risks

Light Reading
News Analysis
Light Reading
8/22/2005
50%
50%

Massachusetts-based startup Covergence Inc. believes it has cooked up a cure for some of the risks associated with implementing new SIP-based applications (see SIP Guide).

With new session initiation protocol (SIP) applications like VOIP, instant messaging, and audio/video conferencing taking root at service providers, the operators need a way to secure and provide quality of service (QOS) for those applications, according to the startup, which was founded in 2003 and has raised $16 million in venture funding. Covergence is set to introduce a carrier-grade security and management solution (see Tekelec Reports Q2, Buys SIP Vendor). The product will serve as an early response system for SIP threats like hacking, spying, eavesdropping, spamming, hijacking, viruses, and denial-of-service attacks.

While Covergence isn’t letting go of many details prior to the launch, Light Reading has learned that the product consists of a series of network appliances that report SIP security and service availability problems to a central monitoring and control point (see Cisco IOS Hole Points to VOIP Threat).

The company and its VC backers believe many service providers and Fortune 2000 companies have bought into the SIP concept, but didn’t anticipate the new risk exposure. One investor says that as the SIP boom takes hold, security may have been overlooked.

"As SIP has become the de facto for messaging and other real-time applications, it has opened up a bunch of quality assurance, security, and administration issues,” says Sean Dalton, a partner at Highland Capital Partners, an investor in Covergence. “For companies that are just starting to implement IP, the issues of security and management just kind of go right over them... and then they call back six months later and say, ‘Now I get it.' "

SIP apps work differently than circuit-switched ones, explains Heavy Reading analyst at large Tim Hills. SIP uses in-band signaling, meaning that the signaling messages that control the system are transported by the same mechanism (IP packets) that transports the service media (like the voice channel for VOIP), Hills says in a recent Heavy Reading report (see SIP Guide).



The separation between signaling and media streams is logical, Hills says, not physical. This makes for an open architecture -- high on flexibility, but not inherently secure.

As such, Covergence's VP of marketing Rod Hodgman says, managing the risk isn’t easy. “It’s a hard road; you’ve got to look at interoperability, quality assurance, high availability, and confidentiality,” he says. “You’ve got internally launched virus attacks and even alleged attempts at corporate espionage." And all that, he notes, can happen behind the firewall.

Hodgman says attacks against SIP applications are not widespread today but will increase as the protocol becomes more established. For example, Hodgman says Microsoft Corp.'s (Nasdaq: MSFT) new, SIP-based Live Communications Server, is “extremely attractive” to Fortune 2000 companies, but security issues are hindering deployments.

“There are those that I know are sitting in the labs and trying to figure out how to deploy the solution,” Hodgman says. “What’s preventing that is the security and compliance officer." (See Microsoft Intros FMC Solution.) Asked if Covergence is in discussions to partner with Microsoft on the product, Hodgman pleads the Fifth.

So if this SIP security thing is such a glaring problem, new companies must be lining up to provide the fix for it, right?

“I suspect there are a lot of smaller companies flying under the radar right now -- Borderware has a product," Hodgman says. ’s product, SIPassure, is billed as a "SIP firewall." Others involved in the space include Radware Ltd. (Nasdaq: RDWR) and M5T.

Covergence's funding is led by Highland Capital and North Bridge Venture Partners. The company got a $6 million first round of funding in January 2004 and a second round worth $10 million in June 2005.

— Mark Sullivan, Reporter, Light Reading

(2)  | 
Comment  | 
Print  | 
Newest First  |  Oldest First  |  Threaded View        ADD A COMMENT
Mark Sullivan
50%
50%
Mark Sullivan,
User Rank: Light Beer
12/5/2012 | 3:04:46 AM
re: Covergence Banks on SIP Risks
Hey friends, what do you think about this company? Are security issues really preventing the deployment of new SIP apps? Please post any insights you may have. Thanks. -Mark
Mark Sullivan
50%
50%
Mark Sullivan,
User Rank: Light Beer
12/5/2012 | 3:04:46 AM
re: Covergence Banks on SIP Risks
Hey friends, what do you think about this company. Are security issues really preventing the deployment of new SIP apps? -Mark
Flash Poll
From The Founder
Network architects aiming to upgrade their networks to support agile, open, virtualized services in the 21st century need to consider new criteria when choosing between technology suppliers.
Live Streaming Video
BTE 2015 Sponsor Keynote: HP
Dr. Prodip Sen, CTO, Network Functions Virtualization, HP
LRTV Documentaries
IoT in Action

6|30|15   |   1:39   |   (5) comments


Two co-workers discuss the benefits of IoT technology.
LRTV Interviews
Ericsson Opens Up on OPNFV

6|30|15   |   14:16   |   (0) comments


Martin Bäckström, VP and head of industry area Datacom at Ericsson, talks to Light Reading founder and CEO Steve Saunders about the emergence of OPNFV, the importance of standards and Ericsson's OPNFV plans.
LRTV Custom TV
NetNumber Founder Discusses NFV/SDN Impact on SP Networks

6|26|15   |   4:15   |   (0) comments


NetNumber Founder Doug Ranalli examines why SPs need a new network infrastructure for service agility. While NFV and SDN are the tools, the old ways of thinking about signaling control are inhibitors. Doug provides his recommendations.
LRTV Custom TV
Orchestrating NFV vCPE Services Across Multivendor Networks

6|26|15   |   5:46   |   (0) comments


Nirav Modi provides an overview of vCPE, the fastest-growing NFV use case, showing how Cyan's Blue Planet orchestrates vCPE services across a multivendor infrastructure to rapidly deliver new managed services for business customers.
LRTV Custom TV
ZTE at LTE Summit Amsterdam 2015

6|26|15   |     |   (0) comments


As one of the leading global telecommunications providers, ZTE presented its cutting-edge technology at LTE World Summit 2015 in Amsterdam. On display at ZTE's booth were the latest R&D achievements in wireless, 5G development, HetNet, deep convergence of FDD and TDD, and RCS/IMD/iSDN/vCN.
LRTV Documentaries
OPNFV Director Opens Up on Women in Tech

6|25|15   |   3:25   |   (0) comments


Heather Kirksey, the director of the OPNFV, gets real about the gender disparity in open source and standards and discusses how we can change both the conversation and the gender dynamics.
LRTV Custom TV
Symantec's Service Provider Security Strategy

6|24|15   |   7:06   |   (0) comments


Didi Dayton explores Symantec's emerging enterprise security strategies for service providers. Highlights include 'killing the password,' self-defense, advanced analytics and adaptive response in a service provider architecture.
Between the CEOs
Debating Network Evolution With Cisco's Cedrik Neike

6|23|15   |   12:54   |   (2) comments


Cedrik Neike, SVP of Global Service Provider, Service Delivery, at Cisco, talks to Light Reading founder and CEO Steve Saunders about solving service provider customer problems in a virtualized, DevOps world, including multivendor support and the future of network procurement.
LRTV Documentaries
Vodafone: What's Good for Moms Is Good for Business

6|23|15   |   3:04   |   (3) comments


Megan Doberneck, the general counsel for Vodafone Americas, discusses her company's progressive maternity policy, explains why promoting women in tech is good business and offers some some good advice for any women in the industry.
LRTV Interviews
NFV: Ready for Prime Time

6|23|15   |   05:09   |   (1) comment


At BTE 2015, Vip mobile CTO Dejan Kastelic talks about how NFV is ready for the real world and how Telekom Austria is introducing centralized resources for its group operations.
LRTV Documentaries
Tykes Talk Tech

6|22|15   |   02:30   |   (9) comments


What does optical fiber look like? When will 5G arrive? What's the WiFi password at Ikea? Light Reading sat down with three 8-year-olds to answer some of the communications industry's most burning questions...
LRTV Huawei Video Resource Center
Huawei Partners With TDC for World's First Early DOCSIS 3.1 Field Test

6|22|15   |   3:06   |   (0) comments


In a move to enhance user experience, Denmark's TDC aims to become an early adopter of DOCSIS 3.1. In partnership with Huawei, TDC recently ran the world's first field tests on its coax network that reached speeds nearing 1 Gbit/s.
Upcoming Live Events
September 16-17, 2015, The Westin Galleria Dallas, Dallas, TX
September 29-30, 2015, The Westin Grand Müchen, Munich, Germany
October 6, 2015, The Westin Peachtree Plaza, Atlanta, GA
October 6, 2015, Westin Peachtree Plaza, Atlanta, GA
October 14-15, 2015, New Orleans Ernest N. Morial Convention Center, New Orleans, LA
All Upcoming Live Events
Infographics
Hot Topics
Staying Productive With My Office-in-a-Bag
Mitch Wagner, West Coast Bureau Chief, Light Reading, 6/25/2015
Who's Feeding Fiber to LinkNYC Hotspots?
Mari Silbey, Senior Editor, Cable/Video, 6/29/2015
Eurobites: Activist Investor Takes Stake in AlcaLu
Paul Rainford, Assistant Editor, Europe, 6/30/2015
What's in Your Office-in-a-Bag?
Mitch Wagner, West Coast Bureau Chief, Light Reading, 6/26/2015
Like Us on Facebook
Twitter Feed
Webinar Archive
BETWEEN THE CEOs - Executive Interviews
Casa Systems has been going from strength to strength over the last couple of years. In 2013, it became the first vendor to ship an integrated CCAP device -- the ...
Cedrik Neike, SVP of Global Service Provider, Service Delivery, at Cisco, talks to Light Reading founder and CEO Steve Saunders about solving service provider customer problems in a virtualized, DevOps world, including multivendor support and the future of network procurement.
Cats with Phones