Audio/Video Systems and Information Security
Jari Korvakangas · Theseus (Ammattikorkeakoulujen) · 2016
The purpose of this thesis was to investigate presentation technology systems and their potential security holes. Three different areas in audio/video were chosen for this. These were Video Conferencing, Audio over Ethernet and IP announcement systems. This study was carried out for Mission Critical Network team of Pöyry Finland Oy. The first part of this thesis covers Video Conferencing on a general level and potential security breaches it has following different solutions for these problems. The second part deals with Audio over Ethernet and current transformation from analogue to digital systems. Dante AVB/TSN, Ravenna and various other presentation technology systems are covered. Lastly, IP announcement systems are explained. The analysis offered some solutions for Video Conferencing systems regarding how to avoid security breaches, but no obvious fix for all situations was found that would be easy to implement. The most important thing is to put the devices behind a firewall and configure the firewall according to the situation. This is not as easy as it sounds though. This will prevent some, if not most threats and there are also other ways to improve security like H.323 proxy and/or gatekeeper possibly together acting as middle ground in the call. Upon analysing Audio over Ethernet, no major security threat unique to it was found. Dante, AVB and others often operate behind firewall avoiding the worst threats. Thus the focus was more on systems on a general level and less on the security perspective. The same can be said for IP announcement systems. Audio/video devices have been moving to a digitalized form more and more recently. This makes the knowledge of these systems necessary for network engineers when designing networks. In future this progress only increases while systems evolve to take advantage of IP protocols.