Call attack handling

WO2026165931A1PCT designated stage Publication Date: 2026-08-13NOKIA SOLUTIONS & NETWORKS OY +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2026-08-13

Smart Images

  • Figure CN2025076622_13082026_PF_FP_ABST
    Figure CN2025076622_13082026_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to call attack handling. In one aspect, based on a call state machine, a network device determines whether a first terminal device is performing a call attack on a second terminal device. The network device blocks at least one call initiated by the first terminal device based on determining that the first terminal device is performing the call attack. The network device then transmits indication information of the call attack determined by the network device to at least one of the second terminal device and an operator device.
Need to check novelty before this filing date? Find Prior Art

Description

CALL ATTACK HANDLINGFIELD

[0001] Various example embodiments relate to the field of communication and in particular, to devices, methods, apparatuses and a computer readable storage medium for call attack handling.BACKGROUND

[0002] A communication network can be seen as a facility that enables communications between two or more communication devices, or provides communication devices access to a data network. A mobile or wireless communication network is one example of a communication network.

[0003] Such communication networks operate in accordance with standards, such as those promulgated by Third Generation Partnership Project (3GPP) or European Telecommunications Standards Institute (ETSI) . Examples of such standards include the so-called 5th generation (5G) standard, 6th generation (6G) or other standards promulgated by 3GPP.SUMMARY

[0004] In general, example embodiments of the present disclosure provide a solution for call attack handling.

[0005] In a first aspect, there is provided a network device. The network device comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the network device at least to: determine, based on a call state machine, whether a first terminal device is performing a call attack on a second terminal device, block at least one call initiated by the first terminal device based on determining that the first terminal device is performing the call attack, and transmit, to at least one of the second terminal device and an operator device, indication information of the call attack determined by the network device.

[0006] In a second aspect, there is provided a second terminal device. The second terminal device comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the second terminal device at least to: receive, from a network device, an invite message supporting a reliable provisional response, wherein the invite message is initiated by a first terminal device and forwarded by the network device, transmit, to the network device, a session progress message requesting the reliable provisional response, and receive, from the network device, indication information of a call attack performed by the first terminal device.

[0007] In a third aspect, there is provided a method. The method comprises determining, at a network device based on a call state machine, whether a first terminal device is performing a call attack on a second terminal device, blocking at least one call initiated by the first terminal device based on determining that the first terminal device is performing the call attack, and transmitting, to at least one of the second terminal device and an operator device, indication information of the call attack determined by the network device.

[0008] In a third aspect, there is provided a method. The method comprises receiving, at a second terminal device and from a network device, an invite message supporting a reliable provisional response, wherein the invite message is initiated by a first terminal device and forwarded by the network device, transmitting, to the network device, a session progress message requesting the reliable provisional response, and receiving, from the network device, indication information of a call attack performed by the first terminal device.

[0009] In a fifth aspect, there is provided an apparatus. The apparatus comprises means for determining, at a network device based on a call state machine, whether a first terminal device is performing a call attack on a second terminal device, means for blocking at least one call initiated by the first terminal device based on determining that the first terminal device is performing the call attack, and means for transmitting, to at least one of the second terminal device and an operator device, indication information of the call attack determined by the network device.

[0010] In a sixth aspect, there is provided an apparatus. The apparatus comprises means for receiving, at a second terminal device and from a network device, an invite message supporting a reliable provisional response, wherein the invite message is initiated by a first terminal device and forwarded by the network device, means for transmitting, to the network device, a session progress message requesting the reliable provisional response, and means for receiving, from the network device, indication information of a call attack performed by the first terminal device.

[0011] In a seventh aspect, there is provided a non-transitory computer readable medium comprising program instructions for causing an apparatus to perform at least the method according to any one of the above third to fourth aspect.

[0012] In an eighth aspect, there is provided a computer program comprising instructions, which, when executed by an apparatus, cause the apparatus to perform at least the method according to any one of the above third to fourth aspect.

[0013] In a ninth aspect, there is provided a network device. The network device comprises determining circuitry configured to determine, based on a call state machine, whether a first terminal device is performing a call attack on a second terminal device, blocking circuitry configured to block at least one call initiated by the first terminal device based on determining that the first terminal device is performing the call attack, and transmitting circuitry configured to transmit, to at least one of the second terminal device and an operator device, indication information of the call attack determined by the network device.

[0014] In a tenth aspect, there is provided a terminal device. The terminal device comprises receiving circuitry configured to receive, from a network device, an invite message supporting a reliable provisional response, wherein the invite message is initiated by a first terminal device and forwarded by the network device, transmitting circuitry configured to transmit, to the network device, a session progress message requesting the reliable provisional response, and receiving circuitry configured to receive, from the network device, indication information of a call attack performed by the first terminal device.

[0015] It is to be understood that the summary section is not intended to identify key or essential features of embodiments of the present disclosure, nor is it intended to be used to limit the scope of the present disclosure. Other features of the present disclosure will become easily comprehensible through the following description.BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Some example embodiments will now be described with reference to the accompanying drawings, in which:

[0017] Fig. 1A illustrates an example network environment in which example embodiments of the present disclosure may be implemented;

[0018] Fig. 1B illustrates an example of VoWi-Fi call setup procedure;

[0019] Fig. 1C illustrates an example of stealthy Call DoS attack procedure;

[0020] Fig. 2 illustrates an example signaling chart illustrating an example process according to some embodiments of the present disclosure;

[0021] Fig. 3 illustrates an example of a state machine for detecting a call attack in a single call according to some embodiments of the present disclosure;

[0022] Fig. 4 illustrates an example process for detecting a call attack in a single call according to some embodiments of the present disclosure;

[0023] Fig. 5 illustrates an example data structure of a block list according to some embodiments of the present disclosure;

[0024] Fig. 6 illustrates an example data structure of a candidate list according to some embodiments of the present disclosure;

[0025] Fig. 7 illustrates an example architecture of the call attack handling.

[0026] Fig. 8 illustrates a flowchart of a method implemented at a network device according to some example embodiments of the present disclosure;

[0027] Fig. 9 illustrates a flowchart of a method implemented at a terminal device according to some example embodiments of the present disclosure;

[0028] Fig. 10 illustrates a simplified block diagram of an apparatus that is suitable for implementing embodiments of the present disclosure; and

[0029] Fig. 11 illustrates a block diagram of an example computer readable medium in accordance with some embodiments of the present disclosure.

[0030] Throughout the drawings, the same or similar reference numerals represent the same or similar element.DETAILED DESCRIPTION

[0031] Principles of the present disclosure will now be described with reference to some example embodiments. It is to be understood that these embodiments are described only for the purpose of illustration and help those skilled in the art to understand and implement example embodiments of the present disclosure, without suggesting any limitation as to the scope of the disclosure. The example embodiments of the present disclosure described herein can be implemented in various manners other than the ones described below.

[0032] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skills in the art to which this disclosure belongs.

[0033] References in the present disclosure to “one embodiment, ” “an embodiment, ” “an example embodiment, ” and the like indicate that the embodiment described may include a particular feature, structure, or characteristic, but it is not necessary that every embodiment includes the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the knowledge of one skilled in the art to affect such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described.

[0034] It shall be understood that although the terms “first” and “second” etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first element could be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of example embodiments. As used herein, the term “and / or” includes any and all combinations of one or more of the listed terms.

[0035] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of example embodiments. As used herein, the singular forms “a” , “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises” , “comprising” , “has” , “having” , “includes” and / or “including” , when used herein, specify the presence of stated features, elements, and / or components etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof. As used herein, “at least one of the following: <a list of two or more elements>” and “at least one of <a list of two or more elements>” and similar wording, where the list of two or more elements are joined by “and” or “or” , mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.

[0036] As used in this application, the term “circuitry” may refer to one or more or all of the following: (a) hardware-only circuit implementations (such as implementations in only analog  and / or digital circuitry) and (b) combinations of hardware circuits and software, such as (as applicable) : (i) a combination of analog and / or digital hardware circuit (s) with  software / firmware and (ii) any portions of hardware processor (s) with software (including digital signal  processor (s) ) , software, and memory (ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and (c) hardware circuit (s) and or processor (s) , such as a microprocessor (s) or a portion  of a microprocessor (s) , that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.

[0037] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.

[0038] As used herein, the term “communication network” refers to a network following any suitable communication standards, such as long term evolution (LTE) , LTE-advanced (LTE-A) , wideband code division multiple access (WCDMA) , high-speed packet access (HSPA) , narrow band internet of things (NB-IoT) and so on. Furthermore, the communications between a terminal device and a network device in the communication network may be performed according to any suitable generation communication protocols, including, but not limited to, the first generation (1G) , the second generation (2G) , 2.5G, 2.75G, the third generation (3G) , the fourth generation (4G) , 4.5G, the future fifth generation (5G) communication protocols, and / or any other protocols either currently known or to be developed in the future. Embodiments of the present disclosure may be applied in various communication systems. Given the rapid development in communications, there will of course also be future type communication technologies and systems with which example embodiments of the present disclosure may be embodied. It should not be seen as limiting the scope of the present disclosure to only the aforementioned system.

[0039] As used herein, the term “network device” refers to a node in a communication network via which a terminal device accesses the network and receives services therefrom. The network device may refer to a base station (BS) or an access point (AP) , for example, a node B (NodeB or NB) , an evolved NodeB (eNodeB or eNB) , a new radio (NR) NB (also referred to as a gNB) , a remote radio unit (RRU) , a radio header (RH) , a remote radio head (RRH) , a relay, a low power node such as a femto, a pico, and so forth, depending on the applied terminology and technology.

[0040] The term “terminal device” refers to any end device that may be capable of wireless communication. By way of example rather than limitation, a terminal device may also be referred to as a communication device, user equipment (UE) , a subscriber station (SS) , a portable subscriber station, a mobile station (MS) , or an access terminal (AT) . The terminal device may include, but not limited to, a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones, a tablet, a wearable terminal device, a personal digital assistant (PDA) , portable computers, desktop computer, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, vehicle-mounted wireless terminal devices, wireless endpoints, mobile stations, laptop-embedded equipment (LEE) , laptop-mounted equipment (LME) , USB dongles, smart devices, wireless customer-premises equipment (CPE) , an internet of things (loT) device, a watch or other wearable, a head-mounted display (HMD) , a vehicle, a drone, a medical device and applications (e.g., remote surgery) , an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts) , a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like. In the following description, the terms “terminal device” , “communication device” , “terminal” , “user equipment” and “UE” may be used interchangeably.

[0041] Fig. 1A illustrates an example network environment 100 in which example embodiments of the present disclosure may be implemented. The environment or communication system 100, which may be a part of a communication network, comprises terminal devices and network devices.

[0042] As illustrated in Fig. 1A, the communication system 100 may comprise a network device 110 (hereinafter may also be referred to as network device 110) , a terminal device 120 (hereinafter may also be referred to as first terminal device 120 or UE 120) , a terminal device 130 (hereinafter may also be referred to as second terminal device 130 or UE 130) , and a base station 140. The network device 110 may be a network element (NE) or a network function in core network, e.g., the IP multimedia subsystem (IMS) core network. The base station 140 can manage a cell 101. The terminal device 120 or the terminal device 130 can communicate with the base station 140 within the coverage of the cell 101. The base station 140 connects to the network device 120. The terminal device 120 can communicate with the terminal device 130 via the network device 120 and the base station 140.

[0043] It is to be understood that the number of devices is only for the purpose of illustration without suggesting any limitations. The system 100 may include any suitable number of terminal devices or network devices adapted for implementing embodiments of the present disclosure. Although not shown, it would be appreciated that one or more terminal devices or network devices may be located in the system 100.

[0044] Communications in the communication system 100 may be implemented according to any proper communication protocol (s) , comprising, but not limited to, cellular communication protocols of the first generation (1G) , the second generation (2G) , the third generation (3G) , the fourth generation (4G) and the fifth generation (5G) and on the like, wireless local network communication protocols such as Institute for Electrical and Electronics Engineers (IEEE) 802.11 and the like, and / or any other protocols currently known or to be developed in the future. Moreover, the communication may utilize any proper wireless communication technology, comprising but not limited to: code division multiple access (CDMA) , frequency division multiple access (FDMA) , time division multiple access (TDMA) , frequency division duplex (FDD) , time division duplex (TDD) , multiple-input multiple-output (MIMO) , orthogonal frequency division multiple (OFDM) , discrete Fourier transform spread OFDM (DFT-s-OFDM) and / or any other technologies currently known or to be developed in the future.

[0045] Nowadays, all the 4G / 5G voice solutions are offered by the IP multimedia subsystem (IMS) system. The 4G / 5G voice solutions include 4G voice over LTE (VoLTE) and 5G voice over new radio (VoNR) for 4G and 5G networks. Respectively, voice over WiFi (VoWiFi) is introduced for non-3GPP access networks (i.e., WiFi) to cover the areas with poor 3GPP access signal and has been supported since the 4G.

[0046] Since VoWiFi is implemented on mobile operating system (OS) , instead of the modem with hardware security for VoLTE and VoNR, it can be a vulnerability of the IMS system. Given a phone with root privilege, its VoWiFi session connecting to the core network may be hijacked for malicious users to send fabricated messages to the IMS system. It has been exposed that due to vulnerable VoWiFi sessions, several IMS vulnerabilities are discovered and the smartphones with IMS-based call services may suffer from call attack, e.g., a stealthy call denial of service (DoS) attack. In this attack, the affected smartphones are unable to make or receive calls, and no ringtones or notifications appearing during the attack.

[0047] An adversary can easily initiate ghost calls to carry out a stealthy call DoS attack against specific cellular users, requiring only the victims’ phone numbers-no malware or network information is needed. This advanced attack exploits a design flaw in the IMS call state machine with session initial protocol (SIP) , rather than relying on flooding or crash triggers.

[0048] The caller’s user agent client (UAC) may indicate support for reliable provisional responses in the initial INVITE request by including the “100 reliable provisional response (100rel) ” parameter in the Require header (e.g., “Require: 100rel” ) . If the caller requests reliable provisional responses, the “183 Session Progress” response from the callee’s user agent server (UAS) also includes the “100rel” parameter, ensuring the caller acknowledges the response using provisional response acknowledgement (PRACK) . After receiving the “183 Session Progress” response, the caller replies to the callee with PRACK. If the callee does not receive a corresponding PRACK, it will repeatedly retransmit the “183 Session Progress” response.

[0049] Fig. 1B illustrates the normal scenario, where the caller successfully initiates a call by exchanging SIP messages, including the correct “183 Session Progress” response and PRACK.

[0050] In the case of a phone with root privileges, its VoWiFi SIP session connecting to the core network may be hijacked, allowing malicious users to send fabricated messages to the IMS system. The compromised caller UE sends frequent INVITE requests with 100rel, but never replies with PRACK to the “183 Session Progress” responses. For reliability, the callee retransmits the “183 Session Progress” responses with an exponential backoff timer. When the maximum number of retransmissions is reached, the IMS cancels the session by sending a CANCEL message to the callee. The number of retransmissions and the initial timeout are carrier-specific. As a result, the callee UE remains stuck waiting for PRACK and is unable to receive calls from other users.

[0051] Fig. 1C depicts the abnormal scenario, where the caller initiates a call but doesn’ t reply with PRACK. The callee, as the victim, continuously retransmits the “183 Session Progress” message for a set period and suffering from a call DoS. This prevents the victim from making or receiving calls during the attack. Notably, this DoS attack is silent, with no ringtone or notification appearing on the victim UE.

[0052] A solution named Delay call binding proposes a delay call binding mechanism to solve the call attack. It delays the call binding to the arrival of the PRACK instead of the INVITE. Even though many attack INVITE messages may arrive at the callee, it can bind the call to the earliest one which returns the PRACK and start to play ringtone. Such mechanism can prevent the callee from getting stuck with a specific INVITE. Both the callee and the IMS core consider the sessions without the PRACK as pending ones. When seeing an INVITE without any pending sessions, they reserve resource for a call but do not bind it to the INVITE. The callee follows the same call setup procedure to serve it. Afterwards, no new resources are allocated for further INVITE messages. Whenever a PRACK message is returned, both the callee and the IMS core bind the call resource to its corresponding session and dismiss the other pending sessions. The call resource for the callee will be released once no pending sessions exist.

[0053] Above solution offers a way to mitigate the stealthy call DoS attack by modifying the session setup process in IMS. However, there are some disadvantages in this solution, e.g., potential for resource waste, increased complexity in call setup and no attack detection and defense.

[0054] Although resources are not fully committed until the PRACK is received, they are still reserved upon receiving the INVITE. If a large number of malicious INVITEs are sent, this reservation could result in resource wastage, particularly in networks with limited capacity or heavy traffic. While this mechanism prevents call DoS for the callee, it may still cause resource exhaustion in the IMS core if attackers flood the system with INVITE messages that lead to resource reservations without final bindings.

[0055] The system tracks multiple “pending” sessions and ensure that resources are appropriately allocated when a PRACK arrives. This adds complexity to both the UE and the IMS core network.

[0056] The solution cannot fully detect or prevent the stealthy call DoS attack. It only prevents the victim UE from getting stuck in a blocked state. In reality, the attack continues within the IMS network, as the attacker can target multiple UEs simultaneously. Even if one UE's call setup succeeds, the attacker can still disrupt other UEs.

[0057] As described above, a long-term solution is required to address both resource exhaustion and the added complexity. In addition, a more effective approach would be to detect and identify the attacker, then block the malicious UE from continuing to attack other users.

[0058] Another point is that the owner of the attacking phone may be unaware that his device has been hijacked by hackers and is being used to launch attacks. The users of the attacked phones also do not know that their devices are in a stuck state. Additionally, the network operators are unaware that a hacking attack is taking place within their network. Since neither the network operators nor the phone users can detect the ongoing attacks, they are unable to take any defensive measures. Therefore, it is crucial to notify both the operators and the users as soon as abnormal attack behavior is detected. This will help speed up the identification and resolution of the issue.

[0059] According to some embodiments of the present disclosure, a solution is provided for the call attack handling. In one aspect of this solution, based on a call state machine, a network device determines whether a first terminal device is performing a call attack on a second terminal device. The network device blocks at least one call initiated by the first terminal device based on determining that the first terminal device is performing the call attack. The network device then transmits indication information of the call attack determined by the network device to at least one of the second terminal device and an operator device. In this way, real-time detection of attack behaviors is performed, and overall network vulnerability and prevents escalation of attacks is reduced. Therefore, the communication performance is enhanced. Principles and implementations of embodiments of the present disclosure will be described in detail below with reference to Figs. 2-10.

[0060] Fig. 2 illustrates a signaling chart illustrating an example process 200 according to some embodiments of the present disclosure. For the purpose of discussion, the process 200 will be described with reference to Fig. 1A. The process 200 may involve the network device 110, the first terminal device 120 and the second terminal device 130. It would be appreciated that although the process 200 has been described in relation to the communication system 100 of Fig. 1A, this process may be likewise applied to other communication scenarios with similar issues.

[0061] In the process 200, a new call arrives, the second terminal device 130 receives 235 an invite message 230 supporting a reliable provisional response from the network device 110. The invite message is initiated by the first terminal device 120 and forwarded by the network device 110. As shown in the Fig. 2, the first terminal device 120 may transmit 210 the invite message 215 to the network device 110. After receiving 220 the invite message 215, the network device 110 may transmit 225 the invite message 230 to the second terminal device 130. In addition, the reliable provisional response may comprise a 100rel.

[0062] In some embodiments, the first terminal device 120 may be a caller UE, and the second terminal device 130 may be a callee UE. In addition, the network device 110 may comprise a network function or a NE in an IP IMS network.

[0063] Additionally, the network function may be a serving call session control function (S-CSCF) , an interrogating call session control function (I-CSCF) , a proxy call session control function (PCSCF) , or telephony application server (TAS) . For the case that a new subsystem is introduced into the NE of the IMS core network, the preferred NE may be the S-CSCF, other NEs can also be used, as long as they are involved in the IMS call message flow.

[0064] Continuing with reference to Fig. 2, the second terminal device 130 transmits 240 a session progress message 245 requesting the reliable provisional response to the network device 110. Correspondingly, the network device 110 may receive 250 the session progress message 245 from the second terminal device 130. In some embodiments, the session progress message may comprise a 183 session progress message.

[0065] On the other side of the communication, the network device 110 determines 255 whether the first terminal device 120 is performing a call attack on the second terminal device 130 based on a call state machine. In some embodiments, the call attack may comprise a stealthy call DoS attack. In other words, the network device 110 may detect the call attack based on a call state machine. For instance, a SIP call state machine based method is introduced to detect stealthy call DoS attacks, which may identify whether an individual call is part of a stealthy call DoS attack.

[0066] For determining whether the first terminal device 120 is performing the call attack based on the call state machine, if the network device 110 is in a first state indicating a normal call and the network device 110 receives an invite message supporting a reliable provisional response, it may transition from the first state to a second state. If the network device 110 receives an invite message not supporting the reliable provisional response, it may remain in the first state.

[0067] Alternatively or additionally, in the case of the network device 110 is in the second state, if the network device 110 receives a session progress message not requesting a reliable provisional response, a ringing message (e.g., 183 ringing) , an acknowledge response message (e.g., 200OK) , or any combination of two or more of the above-mentioned items, it may transition from the second state to the first state. If the network device 110 receives a session progress message requesting the reliable provisional response, it may transition from the second state to a third state.

[0068] In addition, in the case of the network device 110 is in the third state, if the network device 110 receives a provisional response acknowledgement (PRACK) message, a ringing message, an acknowledge response message, an error response message other than a request terminated response message, or any combination of two or more of the above-mentioned items, it may transition from the third state to the first state. If the network device 110 receives a cancel message, a bye message, a request terminated response message, or any combination of two or more of the above-mentioned items, it may transition from the third state to a fourth state indicating the call attack.

[0069] In some embodiments, the error response message may comprise a 4xx response message. In some embodiments, the request terminated response message may comprise a 487 response message.

[0070] Fig. 3 illustrates an example of a state machine for detecting a call attack in a single call according to some embodiments of the present disclosure. In the state machine, four states are defined. State 0 corresponds to the first state in the process 200, State 1 corresponds to the second state in the process 200, State 2 corresponds to the third state in the process 200, and State 3 corresponds to the fourth state in the process 200.

[0071] State 0 indicates that the call is initialized. If an INVITE is received without support 100rel, the state still in State 0. If an INVITE with support 100rel is received, the state transitions to State 1.

[0072] State 1 indicates that an INVITE with support 100rel is received. If a 183 without request 100rel, 180 Ringing, or 200 OK is received, the state transitions to State 0 indicating a normal call. If a 183 with request 100rel is received, the state transitions to State 2.

[0073] State 2 indicates that a 183 with request 100rel is received. If a PRACK, 180 Ringing, 200 OK, or a non-487 4xx response from the callee UE is received, the state reverts to State 0, indicating a normal call. If a CANCEL / BYE or a 487 response is received, the state transitions to State 3, indicating a call attack. State 3 indicates that a call attack has been detected.

[0074] Fig. 4 illustrates an example process for detecting a call attack in a single call according to some embodiments of the present disclosure. The caller UE 401 of Fig. 4 may represent for example the first terminal device 120, the IMS core 402 of Fig. 4 may represent for example the network device 110, and the callee UE 403 of Fig. 4 may represent for example the second terminal device 130.

[0075] In the process 400, at 410, the caller UE 401 transmits an INVITE with support 100rel to the IMS core 402, and the state transitions to State 1. At 415, the IMS core 402 forwards the INVITE with support 100rel to the callee UE 403.

[0076] At 420, the callee UE 403 transmits a 183 with request 100rel to the IMS core 402, and the state transitions from State 1 to State 2. At 430, if a timeout occurs and no PRACK is received from the caller UE 401, the state transitions from State 2 to State 3.

[0077] AT 435, the IMS core 402 receives a CANCEL / BYE from the caller UE 401, the state transitions from State 2 to State 3. At 440, the IMS core 402 transmits a session timeout cancel message to the callee UE 401.

[0078] At 445, the callee UE 401 transmits a 487 response terminated to the IMS core 402, the state transitions from State 2 to State 3. At 450, the IMS core 402 transmits s a 487 request terminated message to the caller UE 401.

[0079] Reference is made back to Fig. 2, the network device 110 blocks 260 at least one call initiated by the first terminal device 120 based on determining that the first terminal device 120 is performing the call attack.

[0080] Alternatively or additionally, if an identity (ID) of the first terminal device 120 is in a block list, the network device 110 may determine that the first terminal device 120 is performing the call attack. Once the ID of the first terminal device 120 is added to the block list, it is blocked from initiating calls to the second terminal device 130 for a specified interval.

[0081] In some embodiments, if the first terminal device 120 is performing the call attack and that the ID of the first terminal device 120 is not in the block list, the network device 110 may add an ID of the first terminal device 120 into a block list.

[0082] For adding the ID of the first terminal device 120 into the block list, the network device 110 may add the ID of the first terminal device 120 into the block list for a duration, and remove the ID of the first terminal device 120 from the block list after the duration expires. For instance, a blocking interval may be defined for the block list, i.e., the duration for which a caller ID is blocked once added to the block list is defined. After the Blocking Interval expires, the caller ID is removed from the block list and may initiate calls again.

[0083] In some embodiments, if the number of call attacks performed by the first terminal device 120 is greater than a threshold, the network device 110 may add the ID of the first terminal device 120 into the block list. In other words, a detection threshold may be defined for the block list, e.g., the number of call attacks allowed before action is taken. To avoid false positives, the attack is allowed to occur fewer than the detection threshold times. Once this detection threshold is exceeded, the caller ID is added to the block list and blocked from initiating further calls for a set interval.

[0084] Alternatively or additionally, if the number of call attacks performed by the first terminal device120 is greater than a threshold within a first interval, the network device 110 may add the ID of the first terminal device 120 into the block list. In other words, a measure interval may be defined for the block list, e.g., the time window for counting call attacks. The caller ID be added to the block list when the number of attacks within one measure interval exceeds the detection threshold.

[0085] In addition, if a number of call attacks performed by the first terminal device 120 is less than a threshold, the network device 110 may add the ID of the first terminal device 120 into a candidate list.

[0086] A blacklist module contains two lists: the candidate list and the block list. The candidate list stores caller IDs that have been detected as part of call attacks but have not yet exceeded the detection threshold. When an attacker's caller ID is added to the blacklist module, it is first placed in the candidate List. The system then counts all records of this caller ID within the measure interval in the candidate list. If the count exceeds the detection threshold, the caller ID is moved to the block list and removed from the candidate list. The expiration time for the caller ID in the block list is set based on the blocking interval and the current time.

[0087] In some embodiments, the block list may comprise at least one ID of at least one terminal device performing the call attack, a number of the call attacks performed by a terminal device, a timestamp of a first call attack performed by a terminal device, a timestamp of a last call attack performed by a terminal device, a duration after which a terminal device is removed from the block list, or any combination of two or more of the above-mentioned items.

[0088] In other words, the block list contains caller IDs that have been identified as call attackers and have exceeded the detection threshold. Any calls originating from a caller ID in the block list should be blocked. Fig. 5 illustrates an example data structure of a block list according to some embodiments of the present disclosure. The block list comprises the caller ID, the attack count, the start time, end time, expire Time. Table 1 shows the detailed explanation of each field in the block list. Table1: Block List description

[0089] In some embodiments, the candidate list may comprise at least one ID of at least one terminal device performing the call attack, and at least one timestamp of at least one call attack performed by the at least one terminal device. Fig. 6 illustrates an example data structure of a candidate list according to some embodiments of the present disclosure. Table 2 shows the detailed explanation of each field in the candidate list. Table2: Candidate List description

[0090] Continuing with reference to Fig. 2, the network device 110 transmits 265 indication information of the call attack determined by the network device 270 to at least one of the second terminal device 130 and an operator device. The operator device is not shown in the Fig. 2.

[0091] In some embodiments, the indication information may comprise an ID of the first terminal device 120, an ID of the second terminal device 130, the number of the call attacks performed by the first terminal device 120, a timestamp of a first call attack performed by the first terminal device, a timestamp of a last call attack performed by the first terminal device 120, or any combination of two or more of the above-mentioned items.

[0092] In an example, if the callee UE is stuck in a stealthy call DoS attack, it will be unable to receive any other calls. However, since the short message service (SMS) can operate concurrently with voice calls, the SMS may be used to notify the callee UE that it is under attack. When an attacker's caller ID is added to the block list in the blacklist module, an alarm and an SMS are sent. These notifications include details such as the caller ID, callee ID, attack count, start time, and end time.

[0093] On the other side of the communication, the second terminal device 130 receives 275 the indication information 270 of a call attack performed by the first terminal device 120 from the network device 110.

[0094] In some embodiments, the second terminal device 130 may reboot the second terminal device based on receiving the indication information 270. Alternatively or additionally, the second terminal device 130 may report the call attack to a network device providing a service for the second terminal device 130 based on receiving the indication information 270.

[0095] Fig. 7 illustrates an example architecture 700 of the call attack handling. As shown in Fig. 7, the call attack handling subsystem includes four modules: the control logic module 710, the attack detection module 720, the blacklist module 730 and the notification module 740.

[0096] The control logic module 710 is the core module. It receives incoming SIP requests / responses and coordinates the functions of the other three modules to manage the workflow for handling call attacks.

[0097] The attack detection module 720 is responsible for detecting call attacks. It analyzes the SIP call state machine to determine whether a UE is under attack.

[0098] The blacklist module 730 stores the caller IDs involved in call attacks. It provides Add / Delete / Update / Query APIs to the control logic module 710. Once a caller ID is added to the block list of this module, it is blocked from initiating calls to the callee UE for a specified interval.

[0099] The notification module 740 sends alarms to the operator and SMS notifications to the callee UE when an attack is detected.

[0100] When a new call arrives, the SIP messages are processed by the control logic module 710. The procedure is as follows:

[0101] At step 1: the control logic module 710 retrieves the caller ID from the message and check the blacklist module 730. If the caller ID is in the block list of the blacklist module 730, block the call and terminate it. If the caller ID is not in the block list of the blacklist module 730, proceed to step 2.

[0102] At step 2, the control logic module 710 passes the call information to the attack detection module 720 to determine if it is a call attack. If it is identified as an attack, add the caller ID to the blacklist module 730. The blacklist module 730 will handle the caller ID. The handling details are shown in process 200 and will not be repeated here. If it is not an attack, proceed to step 5.

[0103] At step 3: the control logic module 710 rechecks the blacklist module 730. If the caller ID is in the block list of the blacklist module 730, block the call and proceed to step 4. If the caller ID is not in the block list of the blacklist module 730, proceed to step 5.

[0104] At step 4: the control logic module 710 sends the caller ID, callee ID, and timestamp information to the notification module 740. The notification module 740 will raise an alarm for operators and send an SMS to the callee UE to alert them of the attack.

[0105] At step 5: the subsystem is exited and normal call processing is continued.

[0106] As described above, example embodiments of the present disclosure proposes an approach for detecting and mitigating call attacks in IMS networks, particularly in VoWiFi scenarios. The key challenge in Stealthy Call DoS attacks is that they exploit the SIP protocol’s state machine, leaving both the victim and the network operator unaware of the attack while the attacker disrupts the normal functioning of User Equipment (UE) .

[0107] Example embodiments of the present disclosure solve the problem by introducing attack detection and identification, blacklist mechanism and real-time notification system. The attack detection and identification mechanism actively monitors abnormal SIP behavior, such as repeated INVITE requests without corresponding PRACK responses, which are characteristic of stealthy call DoS attacks. It analyzes traffic patterns to detect anomalies and identify the attacker based on specific network behaviors, such as failure to acknowledge provisional responses.

[0108] Upon detecting an attack, the system automatically adds the malicious caller’s ID to a blacklist. This ensures that the identified attacker is blocked from initiating further attacks on other UEs. By preventing the same attacker from targeting multiple devices, this feature significantly reduces the risk of widespread disruption within the IMS network.

[0109] The real-time notification system alerts both network operators and affected users as soon as an abnormal attack behavior is detected. This immediate notification allows operators to take corrective actions, such as isolating the affected traffic or adjusting system configurations to further mitigate the impact. Users are also informed, enabling them to take proactive steps like rebooting their devices or reporting issues to their service providers.

[0110] Conventional solutions focus primarily on mitigating the effects of the attack (e.g., preventing UE from getting stuck in a call DoS state) , but they do not actively detect or identify the source of the attack. Example embodiments of the present disclosure goes beyond reactive solutions by providing real-time detection of attack behaviors with a comprehensive detection mechanism, which is a significant advancement over current methods that rely on traditional SIP session handling.

[0111] Unlike conventional approaches that allow the attack to continue undetected, the ability of immediately adding the attacking UE to blacklist ensures that the attacker cannot target additional users. Proactive attack mitigation reduces overall network vulnerability and prevents escalation of attacks.

[0112] While traditional systems may take time to diagnose issues caused by DoS attacks, real-time operator and user alerts speed up response times and reduce the potential for prolonged service disruptions.

[0113] Fig. 8 shows a flowchart of an example method 800 implemented at a network device in accordance with some embodiments of the present disclosure. For the purpose of discussion, the method 800 will be described from the perspective of the network device 110 with reference to Fig. 1A.

[0114] At block 810, the network device 110 determines, based on a call state machine, whether a first terminal device is performing a call attack on a second terminal device. At block 820, the network device 110 blocks at least one call initiated by the first terminal device based on determining that the first terminal device is performing the call attack. At block 830, the network device 110 transmits, to at least one of the second terminal device and an operator device, indication information of the call attack determined by the network device.

[0115] In some embodiments, in order to determine whether the first terminal device is performing the call attack based on the call state machine, the network device 110 may transition from a first state indicating a normal call to a second state based on receiving an invite message supporting a reliable provisional response, and remain in the first state based on receiving an invite message not supporting the reliable provisional response.

[0116] In some embodiments, in order to determine whether the first terminal device is performing the call attack based on the call state machine, the network device 110 may transition from a second state to a first state indicating a normal call based on receiving at least one of a session progress message not requesting a reliable provisional response, a ringing message, or an acknowledge response message, and transition from the second state to a third state based on receiving a session progress message requesting the reliable provisional response.

[0117] In some embodiments, in order to determine whether the first terminal device is performing the call attack based on the call state machine, the network device 110 may transition from a third state to a first state indicating a normal call based on receiving at least one of a provisional response acknowledgement (PRACK) message, a ringing message, an acknowledge response message, or an error response message other than a request terminated response message, and transition from the third state to a fourth state indicating the call attack based on receiving at least one of a cancel message, a bye message or a request terminated response message.

[0118] In some embodiments, in order to determine that the first terminal device is performing the call attack, the network device 110 may determine that an identity (ID) of the first terminal device is in a block list.

[0119] In some embodiments, the network device 110 may further add an ID of the first terminal device into a block list based on determining that the first terminal device is performing the call attack and that the ID of the first terminal device is not in the block list.

[0120] In some embodiments, in order to add the ID of the first terminal device into the block list, the network device 110 may add the ID of the first terminal device into the block list for a duration, and remove the ID of the first terminal device from the block list after the duration expires.

[0121] In some embodiments, the network device 110 may add the ID of the first terminal device into the block list based on one of the following: determining that a number of call attacks performed by the first terminal device is greater than a threshold, or determining that a number of call attacks performed by the first terminal device is greater than a threshold within a first interval.

[0122] In some embodiments, the network device 110 may further add the ID of the first terminal device into the block list based on determining that a number of call attacks performed by the first terminal device is less than a threshold.

[0123] In some embodiments, the block list may comprise at least one of the following: at least one ID of at least one terminal device performing the call attack, a number of the call attacks performed by a terminal device, a timestamp of a first call attack performed by a terminal device, a timestamp of a last call attack performed by a terminal device, or a duration after which a terminal device is removed from the block list.

[0124] In some embodiments, the candidate list may comprise: at least one ID of at least one terminal device performing the call attack, and at least one timestamp of at least one call attack performed by the at least one terminal device.

[0125] In some embodiments, the indication information may comprise at least one of the following: an ID of the first terminal device, an ID of the second terminal device, the number of the call attacks performed by the first terminal device, a timestamp of a first call attack performed by the first terminal device, or a timestamp of a last call attack performed by the first terminal device.

[0126] In some embodiments, the call attack may comprise a stealthy call denial of service (DoS) attack. In some embodiments, the reliable provisional response may comprise a 100 reliable provisional response (100rel) . In some embodiments, the session progress message may comprise a 183 session progress message. In some embodiments, the ringing message may comprise a 183 ringing message. In some embodiments, the acknowledge response message may comprise a 200OK message. In some embodiments, the error response message may comprise a 4xx response message. In some embodiments, the request terminated response message may comprise a 487 response message.

[0127] In some embodiments, the network device 110 may comprise a network function in an Internet protocol (IP) multimedia subsystem (IMS) network. In some embodiments, the network function may comprise one of the following: a serving call session control function (S-CSCF) , an interrogating call session control function (I-CSCF) , a proxy call session control function (PCSCF) , or telephony application server (TAS) .

[0128] Fig. 9 shows a flowchart of an example method 900 implemented at a second terminal device in accordance with some embodiments of the present disclosure. For the purpose of discussion, the method 900 will be described from the perspective of the second terminal device 130 with reference to Fig. 1A.

[0129] At block 910, the second terminal device 130 receives, from a network device, an invite message supporting a reliable provisional response, wherein the reliable provisional response is initiated by a first terminal device and forwarded by the network device. At block 920, the second terminal device 130 transmits, to the network device, a session progress message requesting the reliable provisional response. At block 930, the second terminal device 130 receives, from the network device, indication information of a call attack performed by the first terminal device.

[0130] In some embodiments, the indication information may comprise at least one of the following: an ID of a first terminal device performing the call attack, an ID of the second terminal device, the number of the call attacks performed by the first terminal device, a timestamp of a first call attack performed by the first terminal device, or a timestamp of a last call attack performed by the first terminal device.

[0131] In some embodiments, the second terminal device 130 may further reboot the second terminal device based on receiving the indication information.

[0132] In some embodiments, the second terminal device 130 may further report the call attack to a network device providing a service for the second terminal device based on receiving the indication information.

[0133] In some embodiments, the call attack may comprise a stealthy call denial of service (DoS) attack. In some embodiments, the reliable provisional response may comprise a 100 reliable provisional response (100rel) . In some embodiments, the session progress message may comprise a 183 session progress message. In some embodiments, the ringing message may comprise a 183 ringing message. In some embodiments, the acknowledge response message may comprise a 200OK message. In some embodiments, the error response message may comprise a 4xx response message. In some embodiments, the request terminated response message may comprise a 487 response message.

[0134] In some embodiments, the network device may comprise a network function in an Internet protocol (IP) multimedia subsystem (IMS) network. In some embodiments, the network function may comprise one of the following: a serving call session control function (S-CSCF) , an interrogating call session control function (I-CSCF) , a proxy call session control function (PCSCF) , or telephony application server (TAS) .

[0135] In some embodiments, an apparatus capable of performing any of the method 800 (for example, the network device 110) is provided. The apparatus may comprise means for performing the respective steps of the method 800. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.

[0136] In some embodiments, the apparatus comprises means for determining, based on a call state machine, whether a first terminal device is performing a call attack on a second terminal device, means for blocking at least one call initiated by the first terminal device based on determining that the first terminal device is performing the call attack, and means for transmitting, to at least one of the second terminal device and an operator device, indication information of the call attack determined by the network device.

[0137] In some embodiments, means for determining whether the first terminal device is performing the call attack based on the call state machine may comprise means for transitioning from a first state indicating a normal call to a second state based on receiving an invite message supporting a reliable provisional response, and means for remaining in the first state based on receiving an invite message not supporting the reliable provisional response.

[0138] In some embodiments, means for determining whether the first terminal device is performing the call attack based on the call state machine may comprise means for transitioning from a second state to a first state indicating a normal call based on receiving at least one of a session progress message not requesting a reliable provisional response, a ringing message, or an acknowledge response message, and means for transitioning from the second state to a third state based on receiving a session progress message requesting the reliable provisional response.

[0139] In some embodiments, means for determining whether the first terminal device is performing the call attack based on the call state machine may comprise means for transitioning from a third state to a first state indicating a normal call based on receiving at least one of a provisional response acknowledgement (PRACK) message, a ringing message, an acknowledge response message, or an error response message other than a request terminated response message, and means for transitioning from the third state to a fourth state indicating the call attack based on receiving at least one of a cancel message, a bye message or a request terminated response message.

[0140] In some embodiments, means for determining that the first terminal device is performing the call attack may further comprise means for determining that an identity (ID) of the first terminal device is in a block list.

[0141] In some embodiments, the apparatus may further comprise means for adding an ID of the first terminal device into a block list based on determining that the first terminal device is performing the call attack and that the ID of the first terminal device is not in the block list.

[0142] In some embodiments, means for adding the ID of the first terminal device into the block list may comprise means for adding the ID of the first terminal device into the block list for a duration, and means for removing the ID of the first terminal device from the block list after the duration expires.

[0143] In some embodiments, the apparatus may further comprise means for adding ad the ID of the first terminal device into the block list based on one of the following: determining that a number of call attacks performed by the first terminal device is greater than a threshold, or means for determining that a number of call attacks performed by the first terminal device is greater than a threshold within a first interval.

[0144] In some embodiments, the apparatus may further comprise means for adding the ID of the first terminal device into a candidate list based on determining that a number of call attacks performed by the first terminal device is less than a threshold.

[0145] In some embodiments, the block list may comprise at least one of the following: at least one ID of at least one terminal device performing the call attack, a number of the call attacks performed by a terminal device, a timestamp of a first call attack performed by a terminal device, a timestamp of a last call attack performed by a terminal device, or a duration after which a terminal device is removed from the block list.

[0146] In some embodiments, the candidate list may comprise: at least one ID of at least one terminal device performing the call attack, and at least one timestamp of at least one call attack performed by the at least one terminal device.

[0147] In some embodiments, the indication information may comprise at least one of the following: an ID of the first terminal device, an ID of the second terminal device, the number of the call attacks performed by the first terminal device, a timestamp of a first call attack performed by the first terminal device, or a timestamp of a last call attack performed by the first terminal device.

[0148] In some embodiments, the call attack may comprise a stealthy call denial of service (DoS) attack, the reliable provisional response may comprise a 100 reliable provisional response (100rel) , the session progress message may comprise a 183 session progress message, the ringing message may comprise a 183 ringing message, the acknowledge response message may comprise a 200OK message, the error response message may comprise a 4xx response message, or the request terminated response message may comprise a 487 response message.

[0149] In some embodiments, the network device may comprise a network function in an Internet protocol (IP) multimedia subsystem (IMS) network.

[0150] In some embodiments, the network function may comprise one of the following: a serving call session control function (S-CSCF) , an interrogating call session control function (I-CSCF) , a proxy call session control function (PCSCF) , or telephony application server (TAS) .

[0151] In some embodiments, the apparatus may further comprise means for performing other steps in some embodiments of the method 800. In some embodiments, the means comprises at least one processor and at least one memory including computer program code, the at least one memory and computer program code configured to, with the at least one processor, cause the performance of the apparatus.

[0152] In some embodiments, an apparatus capable of performing any of the method 900 (for example, the second terminal device 130) is provided. The apparatus may comprise means for performing the respective steps of the method 900. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.

[0153] In some embodiments, the apparatus comprises means for receiving, from a network device, an invite message supporting a reliable provisional response, wherein the invite message is initiated by a first terminal device and forwarded by the network device; means for transmitting, to the network device, a session progress message requesting the reliable provisional response; and means for receiving, from the network device, indication information of a call attack performed by the first terminal device.

[0154] In some embodiments, the indication information may comprise at least one of the following: an ID of a first terminal device performing the call attack, an ID of the second terminal device, the number of the call attacks performed by the first terminal device, a timestamp of a first call attack performed by the first terminal device, or a timestamp of a last call attack performed by the first terminal device.

[0155] In some embodiments, the apparatus may further reboot the second terminal device based on receiving the indication information. In some embodiments, the apparatus may further report the call attack to a network device providing a service for the second terminal device based on receiving the indication information.

[0156] In some embodiments, the call attack may comprise a stealthy call denial of service (DoS) attack, the reliable provisional response may comprise a 100 reliable provisional response (100rel) , the session progress message may comprise a 183 session progress message, the ringing message may comprise a 183 ringing message, the acknowledge response message may comprise a 200OK message, the error response message may comprise a 4xx response message, or the request terminated response message may comprise a 487 response message.

[0157] In some embodiments, the network device may comprise a network function in an Internet protocol (IP) multimedia subsystem (IMS) network.

[0158] In some embodiments, the network function may comprise one of the following: a serving call session control function (S-CSCF) , an interrogating call session control function (I-CSCF) , a proxy call session control function (PCSCF) , or telephony application server (TAS) .

[0159] In some embodiments, the apparatus may further comprise means for performing other steps in some embodiments of the method 900. In some embodiments, the means comprises at least one processor and at least one memory including computer program code, the at least one memory and computer program code configured to, with the at least one processor, cause the performance of the apparatus.

[0160] FIG. 10 is a simplified block diagram of a device 1000 that is suitable for implementing embodiments of the present disclosure. The device 1000 may be provided to implement the communication device, for example the network device 110 or the second terminal device 130 as shown in Fig. 1. As shown, the device 1000 includes one or more processors 1010, one or more memories 1020 coupled to the processor 1010, and one or more communication modules 1040 coupled to the processor 1010.

[0161] The communication modules 1040 are for bidirectional communications. The communication modules 1040 has at least one antenna to facilitate communication. The communication interface may represent any interface that is necessary for communication with other network elements.

[0162] The processor 1010 may be of any type suitable to the local technical network and may include one or more of the following: general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) and processors based on multicore processor architecture, as non-limiting examples. The device 1000 may have multiple processors, such as an application specific integrated circuit chip that is slaved in time to a clock which synchronizes the main processor.

[0163] The memory 1020 may include one or more non-volatile memories and one or more volatile memories. Examples of the non-volatile memories include, but are not limited to, a read only memory (ROM) 1024, an electrically programmable read only memory (EPROM) , a flash memory, a hard disk, a compact disc (CD) , a digital video disk (DVD) , and other magnetic storage and / or optical storage. Examples of the volatile memories include, but are not limited to, a random access memory (RAM) 1022 and other volatile memories that will not last in the power-down duration.

[0164] A computer program 1030 includes computer executable instructions that are executed by the associated processor 1010. The program 1030 may be stored in the ROM 1024. The processor 1010 may perform any suitable actions and processing by loading the program 1030 into the RAM 1022.

[0165] The embodiments of the present disclosure may be implemented by means of the program 1030 so that the device 1000 may perform any process of example embodiments of the disclosure as discussed with reference to Figs. 2 to 3. The embodiments of the present disclosure may also be implemented by hardware or by a combination of software and hardware.

[0166] In some embodiments, the program 1030 may be tangibly contained in a computer readable medium which may be included in the device 1000 (such as in the memory 1020) or other storage devices that are accessible by the device 1000. The device 1000 may load the program 1030 from the computer readable medium to the RAM 1022 for execution. The computer readable medium may include any types of tangible non-volatile storage, such as ROM, EPROM, a flash memory, a hard disk, CD, DVD, and the like. Fig. 11 shows an example of the computer readable medium 1100 in form of CD or DVD. The computer readable medium has the program 1030 stored thereon.

[0167] Generally, various embodiments of the present disclosure may be implemented in hardware or special purpose circuits, software, logic or any combination thereof. Some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device. While various aspects of embodiments of the present disclosure are illustrated and described as block diagrams, flowcharts, or using some other pictorial representations, it is to be understood that the block, apparatus, system, technique or method described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.

[0168] Example embodiments of the present disclosure also provides at least one computer program product tangibly stored on a non-transitory computer readable storage medium. The computer program product includes computer-executable instructions, such as those included in program modules, being executed in a device on a target real or virtual processor, to carry out the methods 800 and 900 as described above with reference to Figs. 8-9. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, or the like that perform particular tasks or implement particular abstract data types. The functionality of the program modules may be combined or split between program modules as desired in various embodiments. Machine-executable instructions for program modules may be executed within a local or distributed device. In a distributed device, program modules may be located in both local and remote storage media.

[0169] Program code for carrying out methods of example embodiments of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the program codes, when executed by the processor or controller, cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may execute entirely on a machine, partly on the machine, as a stand-alone software package, partly on the machine and partly on a remote machine or entirely on the remote machine or server.

[0170] In the context of the present disclosure, the computer program codes or related data may be carried by any suitable carrier to enable the device, apparatus or processor to perform various processes and operations as described above. Examples of the carrier include a signal, computer readable medium, and the like.

[0171] The computer readable medium may be a computer readable signal medium or a computer readable storage medium. A computer readable medium may include but not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the computer readable storage medium would include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM) , a read-only memory (ROM) , an erasable programmable read-only memory (EPROM or Flash memory) , an optical fiber, a portable compact disc read-only memory (CD-ROM) , an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. The term “non-transitory, ” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM) .

[0172] Further, while operations are depicted in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Likewise, while several specific implementation details are contained in the above discussions, these should not be construed as limitations on the scope of the present disclosure, but rather as descriptions of features that may be specific to particular embodiments. Certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment may also be implemented in multiple embodiments separately or in any suitable sub-combination.

[0173] Although example embodiments of the present disclosure have been described in languages specific to structural features and / or methodological acts, it is to be understood that the example embodiments of the present disclosure defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.

Claims

1.A network device comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the network device at least to:determine, based on a call state machine, whether a first terminal device is performing a call attack on a second terminal device;block at least one call initiated by the first terminal device based on determining that the first terminal device is performing the call attack; andtransmit, to at least one of the second terminal device and an operator device, indication information of the call attack determined by the network device.2.The network device of claim 1, wherein the network device is caused to determine whether the first terminal device is performing the call attack based on the call state machine by:transitioning from a first state indicating a normal call to a second state based on receiving an invite message supporting a reliable provisional response; andremaining in the first state based on receiving an invite message not supporting the reliable provisional response.3.The network device of claim 1 or 2, wherein the network device is caused to determine whether the first terminal device is performing the call attack based on the call state machine by:transitioning from a second state to a first state indicating a normal call based on receiving at least one of a session progress message not requesting a reliable provisional response, a ringing message, or an acknowledge response message; andtransitioning from the second state to a third state based on receiving a session progress message requesting the reliable provisional response.4.The network device of any of claims 1-3, wherein the network device is caused to determine whether the first terminal device is performing the call attack based on the call state machine by:transitioning from a third state to a first state indicating a normal call based on receiving at least one of a provisional response acknowledgement (PRACK) message, a ringing message, an acknowledge response message, or an error response message other than a request terminated response message; andtransitioning from the third state to a fourth state indicating the call attack based on receiving at least one of a cancel message, a bye message or a request terminated response message.5.The network device of any of claims 1-4, wherein the network device is further caused to determine that the first terminal device is performing the call attack by:determining that an identity (ID) of the first terminal device is in a block list.6.The network device of any of claims 1-5, wherein the network device is further caused to:add an ID of the first terminal device into a block list based on determining that the first terminal device is performing the call attack and that the ID of the first terminal device is not in the block list.7.The network device of claim 6, wherein the network device is further caused to add the ID of the first terminal device into the block list by:adding the ID of the first terminal device into the block list for a duration; andremoving the ID of the first terminal device from the block list after the duration expires.8.The network device of claim 6 or 7, wherein the network device is caused to add the ID of the first terminal device into the block list based on one of the following:determining that a number of call attacks performed by the first terminal device is greater than a threshold; ordetermining that a number of call attacks performed by the first terminal device is greater than a threshold within a first interval.9.The network device of claim any of claims 6-8, wherein the network device is further caused to:add the ID of the first terminal device into a candidate list based on determining that a number of call attacks performed by the first terminal device is less than a threshold.10.The network device of any of claims 5-8, wherein the block list comprises at least one of the following:at least one ID of at least one terminal device performing the call attack;a number of the call attacks performed by a terminal device;a timestamp of a first call attack performed by a terminal device;a timestamp of a last call attack performed by a terminal device; ora duration after which a terminal device is removed from the block list.11.The network device of claim 9, wherein the candidate list comprises:at least one ID of at least one terminal device performing the call attack; andat least one timestamp of at least one call attack performed by the at least one terminal device.12.The network device of any of claims 1-11, wherein the indication information comprises at least one of the following:an ID of the first terminal device;an ID of the second terminal device;the number of the call attacks performed by the first terminal device;a timestamp of a first call attack performed by the first terminal device; ora timestamp of a last call attack performed by the first terminal device.13.The network device of any of claims 1-12, wherein at least one of the following:the call attack comprises a stealthy call denial of service (DoS) attack;the reliable provisional response comprises a 100 reliable provisional response (100rel) ;the session progress message comprises a 183 session progress message;the ringing message comprises a 183 ringing message;the acknowledge response message comprises a 200OK message;the error response message comprises a 4xx response message; orthe request terminated response message comprises a 487 response message.14.The network device of any of claims 1-13, wherein the network device comprises a network function in an Internet protocol (IP) multimedia subsystem (IMS) network.15.The network device of claim 14, wherein the network function comprises one of the following:a serving call session control function (S-CSCF) ;an interrogating call session control function (I-CSCF) ;a proxy call session control function (PCSCF) ; ortelephony application server (TAS) .16.A second terminal device comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the second terminal device at least to:receive, from a network device, an invite message supporting a reliable provisional response, wherein the invite message is initiated by a first terminal device and forwarded by the network device;transmit, to the network device, a session progress message requesting the reliable provisional response; andreceive, from the network device, indication information of a call attack performed by the first terminal device.17.The second terminal device of claim 16, wherein the indication information comprises at least one of the following:an ID of a first terminal device performing the call attack;an ID of the second terminal device;the number of the call attacks performed by the first terminal device;a timestamp of a first call attack performed by the first terminal device; ora timestamp of a last call attack performed by the first terminal device.18.The second terminal device of claim 16 or 17, wherein the second terminal device is further caused to:rebooting the second terminal device based on receiving the indication information.19.The second terminal device any of claims 16-18, wherein the second terminal device is further caused to:reporting the call attack to a network device providing a service for the second terminal device based on receiving the indication information.20.The second terminal device any of claims 16-19, wherein at least one of the following:the call attack comprises a stealthy call denial of service (DoS) attack;the reliable provisional response comprises a 100 reliable provisional response (100rel) ;the session progress message comprises a 183 session progress message;the ringing message comprises a 183 ringing message;the acknowledge response message comprises a 200OK message;the error response message comprises a 4xx response message; orthe request terminated response message comprises a 487 response message.