Light Reading

Covergence Banks on SIP Risks

Light Reading
News Analysis
Light Reading

Massachusetts-based startup Covergence Inc. believes it has cooked up a cure for some of the risks associated with implementing new SIP-based applications (see SIP Guide).

With new session initiation protocol (SIP) applications like VOIP, instant messaging, and audio/video conferencing taking root at service providers, the operators need a way to secure and provide quality of service (QOS) for those applications, according to the startup, which was founded in 2003 and has raised $16 million in venture funding. Covergence is set to introduce a carrier-grade security and management solution (see Tekelec Reports Q2, Buys SIP Vendor). The product will serve as an early response system for SIP threats like hacking, spying, eavesdropping, spamming, hijacking, viruses, and denial-of-service attacks.

While Covergence isn’t letting go of many details prior to the launch, Light Reading has learned that the product consists of a series of network appliances that report SIP security and service availability problems to a central monitoring and control point (see Cisco IOS Hole Points to VOIP Threat).

The company and its VC backers believe many service providers and Fortune 2000 companies have bought into the SIP concept, but didn’t anticipate the new risk exposure. One investor says that as the SIP boom takes hold, security may have been overlooked.

"As SIP has become the de facto for messaging and other real-time applications, it has opened up a bunch of quality assurance, security, and administration issues,” says Sean Dalton, a partner at Highland Capital Partners, an investor in Covergence. “For companies that are just starting to implement IP, the issues of security and management just kind of go right over them... and then they call back six months later and say, ‘Now I get it.' "

SIP apps work differently than circuit-switched ones, explains Heavy Reading analyst at large Tim Hills. SIP uses in-band signaling, meaning that the signaling messages that control the system are transported by the same mechanism (IP packets) that transports the service media (like the voice channel for VOIP), Hills says in a recent Heavy Reading report (see SIP Guide).

The separation between signaling and media streams is logical, Hills says, not physical. This makes for an open architecture -- high on flexibility, but not inherently secure.

As such, Covergence's VP of marketing Rod Hodgman says, managing the risk isn’t easy. “It’s a hard road; you’ve got to look at interoperability, quality assurance, high availability, and confidentiality,” he says. “You’ve got internally launched virus attacks and even alleged attempts at corporate espionage." And all that, he notes, can happen behind the firewall.

Hodgman says attacks against SIP applications are not widespread today but will increase as the protocol becomes more established. For example, Hodgman says Microsoft Corp.'s (Nasdaq: MSFT) new, SIP-based Live Communications Server, is “extremely attractive” to Fortune 2000 companies, but security issues are hindering deployments.

“There are those that I know are sitting in the labs and trying to figure out how to deploy the solution,” Hodgman says. “What’s preventing that is the security and compliance officer." (See Microsoft Intros FMC Solution.) Asked if Covergence is in discussions to partner with Microsoft on the product, Hodgman pleads the Fifth.

So if this SIP security thing is such a glaring problem, new companies must be lining up to provide the fix for it, right?

“I suspect there are a lot of smaller companies flying under the radar right now -- Borderware has a product," Hodgman says. ’s product, SIPassure, is billed as a "SIP firewall." Others involved in the space include Radware Ltd. (Nasdaq: RDWR) and M5T.

Covergence's funding is led by Highland Capital and North Bridge Venture Partners. The company got a $6 million first round of funding in January 2004 and a second round worth $10 million in June 2005.

— Mark Sullivan, Reporter, Light Reading

(2)  | 
Comment  | 
Print  | 
Newest First  |  Oldest First  |  Threaded View        ADD A COMMENT
Mark Sullivan
Mark Sullivan,
User Rank: Light Beer
12/5/2012 | 3:04:46 AM
re: Covergence Banks on SIP Risks
Hey friends, what do you think about this company? Are security issues really preventing the deployment of new SIP apps? Please post any insights you may have. Thanks. -Mark
Mark Sullivan
Mark Sullivan,
User Rank: Light Beer
12/5/2012 | 3:04:46 AM
re: Covergence Banks on SIP Risks
Hey friends, what do you think about this company. Are security issues really preventing the deployment of new SIP apps? -Mark
From The Founder
Light Reading's conference in November will attempt to answer all of the big questions around white box networks. No pressure...
Flash Poll
Live Streaming Video
CLOUD / MANAGED SERVICES: Prepping Ethernet for the Cloud
Moderator: Ray LeMaistre Panelists: Jeremy Bye, Leonard Sheahan
Telecom Innovators Video Showcase
Close-up on ConfD

10|12|15   |   10.21   |   (0) comments

Tail-f's Renée Robinson-Stromberg tells Steve Saunders about the powerful ConfD management interface.
Women in Comms Introduction Videos
Women in Comms: Highlights From Dallas

10|12|15   |   2:23   |   (1) comment

The best soundbites, quotes and words of wisdom from leading women from Intel, AT&T, Verizon and Genband at our recent WiC breakfast in Dallas.
Telecom Innovators Video Showcase
NetNumber Founder on Managing Signaling Control

10|12|15   |   6:36   |   (0) comments

NetNumber Founder and Chief Strategy Officer Doug Ranalli describes the essential complexity of real-world signaling-control and how NetNumber enables carriers to bring signaling-control "under-control". Learn why virtualization alone isn't the answer.
LRTV Documentaries
Verizon Gets Proactive on App Performance

10|12|15   |   04:50   |   (0) comments

SDN is turning traditional service models around to allow Verizon to measure and deliver performance at the application layer. As Shawn Hakl, VP of enterprise networking and managed solutions for Verizon, explains, the carrier had to develop new skill sets and change some of its internal operations, but the payoff was happier enterprise customers.
Telecom Innovators Video Showcase
Tail-f, Cisco & What the Future Holds

10|9|15   |   8:17   |   (0) comments

Steve Saunders meets with Tail-f's Director of Technology, Carl Moberg, in Stockholm to discuss becoming part of Cisco, ETSI MANO, virtualization and the need to combine science and business in order to create opportunities for service providers.
LRTV Interviews
Broadband Forum Embraces SDN & NFV

10|9|15   |   02:42   |   (1) comment

At Gigabit Europe 2015, Robin Mersh and Kevin Foster from the Broadband Forum explain how the industry body is adapting to meet the SDN, NFV and cloud needs of the access network sector.
LRTV Interviews
Top Tips for FTTH Operators

10|8|15   |   02:26   |   (0) comments

At Gigabit Europe 2015, Ventura Team co-founder Richard Jones talks about some of the key business case considerations for FTTH network operators.
LRTV Interviews
M-net Calls for FTTx Unity

10|8|15   |   03:45   |   (0) comments

At the Gigabit Europe event, Jörn Schoof from M-net, the Munich city network operator, calls for industry collaboration on fiber broadband access rollouts.
LRTV Documentaries
The Business Case Challenge for NFV

10|7|15   |   03:47   |   (0) comments

Virtual CPE is one of the early success stories for network functions virtualization, as service providers are finding flexible, programmable CPE solves a lot of logistics problems and reduces their cost. But even here, Masergy Communications faced a business case challenge, says CTO Tim Naramore.
LRTV Interviews
JT Offers Some Gigabit Lessons

10|7|15   |   4:08   |   (1) comment

Barna Kutvolgyi, managing director, Global Consumer, at JT, the incumbent operator on the island of Jersey, talks about how other service providers can learn from his company's gigabit broadband rollout experiences.
LRTV Interviews
AT&T's Chiosi on the Potential of Open Source

10|6|15   |   06:27   |   (0) comments

AT&T Distinguished Network Architect Margaret T. Chiosi talks to Light Reading's Carol Wilson about the potential for open source technology to liberate communications service providers.
LRTV Interviews
Network Security in a Gigabit World

10|6|15   |   05:52   |   (0) comments

Masergy's James Harrison talks about some of the network security and data center issues network operators need to consider as they expand their broadband services portfolios.
Upcoming Live Events
October 14-15, 2015, New Orleans Ernest N. Morial Convention Center, New Orleans, LA
November 5, 2015, Hilton Santa Clara, Santa Clara, CA
November 17, 2015, Santa Clara, California
December 1, 2015, The Westin Times Square, New York City
December 2, 2015, The Westin Times Square, New York City
All Upcoming Live Events
Network appliances have a strong value proposition in today's networks and will continue to do so in the NFV and SDN-enabled networks of tomorrow.
Hot Topics
Dell Buys EMC for $67B in Biggest Tech Deal Ever
Mari Silbey, Senior Editor, Cable/Video, 10/12/2015
M&A Speculation Swirls Around Juniper
Ray Le Maistre, Editor-in-chief, 10/6/2015
Cord Cutting? 'Fraid so.
Brett Sappington, 10/7/2015
Cisco Makes 'Martian' Connection
Mitch Wagner, West Coast Bureau Chief, Light Reading, 10/9/2015
Like Us on Facebook
Twitter Feed
Webinar Archive
BETWEEN THE CEOs - Executive Interviews
With so many new and exciting communications technologies now under development, it's easy to get caught up in the industry's escalating hype cycle. That's why the ...
Last week saw a big day in the 15-year history of Light Reading when Editor-in-Chief Ray Le Maistre and I were invited to interview the Deputy Chairman and Rotating ...
Cats with Phones
"What?! I'm on with Finisar about their stock price tanking" Click Here
Live Digital Audio

Think NFV is just about virtualization? Think again!

Network architects are learning that there's a lot more to the technology than first thought – more complexity, that is; but also, more potential benefits.

On May 29th 1 PM ET, Steve Saunders, founder and CEO of Light Reading, will be drilling into the "pains and gains" of NFV with Saar Gillai, SVP & GM, HP Communications Solutions Business at Hewlett-Packard Co. (NYSE: HPQ) (HP). He has defined a four-step NFV model describing a sequence of technology innovation. It's a must-read doc for any network architect looking to get to grips with their NFV migration strategy. Join us for the interview, and the chance to ask Saar your NFV questions directly!