Central Analysis System for Voice Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current telecommunications network security systems are ineffective against various types of attacks, such as Distributed Denial of Service (DDOS) and penetration attacks, and often fail to detect fraudulent activities, especially when attacks occur from geographically diverse locations.
Innovation Solution
A telecommunications network architecture that includes a central analysis system collecting and comparing Layer 3 through Layer 7 signaling message transmission information from multiple devices to detect security attacks and generate mitigating instructions, which are then transmitted to routing devices to reroute or deny malicious communications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If local detection methods are used for security attacks, then detection simplicity is maintained, but detection coverage is limited and attacks from geographically diverse locations cannot be effectively detected
Solution Approach 1:
The patent combines multiple geographically distributed detection locations into a unified cloud-based security system. Transmission information from multiple locations is merged and analyzed centrally in the cloud, enabling comprehensive detection of attacks from diverse locations while maintaining manageable system complexity through virtualized processing.
Solution Approach 2:
The patent adds a cloud-based dimension to traditional local detection systems. By moving analysis from the network edge to the cloud, the system gains global visibility across multiple geographic locations without proportionally increasing on-premises device complexity.
2Measurement precision
If comprehensive transmission information (Layer 3-7) is analyzed for all communications, then attack detection accuracy is improved, but processing time and computational resources increase
Solution Approach 1:
The patent performs preliminary analysis by extracting and analyzing transmission fingerprints from Layer 3-7 information in real-time as communications pass through the network. This preliminary fingerprinting enables rapid identification of known attack patterns without requiring complete deep inspection of every packet, reducing processing time while maintaining detection accuracy.
Solution Approach 2:
The patent changes the analysis parameter from comprehensive packet inspection to fingerprint matching. By comparing extracted transmission fingerprints against a database of known attack signatures, the system achieves high detection accuracy with significantly reduced processing time compared to analyzing all transmission data in detail.
3Reliability
If centralized cloud-based analysis is implemented for all network traffic, then detection capability across geographically diverse locations is improved, but network infrastructure complexity increases
Solution Approach 1:
The patent introduces a cloud-based intermediary system that sits between distributed network locations and the central analysis platform. This intermediary collects transmission information locally and forwards relevant data to the cloud, enabling centralized analysis without requiring direct complex connections between all network elements, thus improving detection capability while managing infrastructure complexity.
Data Source
AI summary
Aspects of the present disclosure involve systems, methods, computer program products, and the like, for identifying and mitigating attacks on a voice component of a telecommunications network. In general, the process includes obtaining Layer 3 through Layer 7 transmission information from one or more edge devices to the telecommunications network. In one particular embodiment, a plurality of edge devices (also referred to herein as “session border controllers” or SBCs) is included in the telecommunications network in disparate geographical locations. Each SBC may provide Layer 3 through Layer 7 transmission information for each packet or communication transmitted through the SBC to a local database, which in turn may provide the information to a Central Analysis System or database. In one particular embodiment, the Layer 3 through Layer 7 information includes Session Initiation Protocol routing information for the communications sent to each of the SBCs of the network.


