CSCF Server Traffic Detection for IMS Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The Evolved Packet System (EPS) is vulnerable to harmful traffic and electronic attacks due to direct communication between the IMS core and user devices, which can lead to protocol errors, malicious software transmission, and denial of service attacks, compromising the Call Session Control Function (CSCF) server performance.

Innovation Solution

Implementing a Call Session Control Function (CSCF) server that detects conditions such as protocol errors, malicious software, and electronic attacks by analyzing traffic severity and dynamically mitigates or remedies these issues through off-board devices, such as an analytics server, to prevent damage and maintain system performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If the IMS core initiates and establishes calls directly with user devices, then call establishment speed and system simplicity are improved, but vulnerability to harmful traffic and electronic attacks increases

Engineering Contradiction:
Improvecall establishment speedVSAvoidvulnerability to harmful traffic
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary security detection mechanism between the IMS core and user devices. This intermediary analyzes traffic for harmful content (malicious software, viruses, worms, spy ware) and electronic attacks (spoofing, denial of service attacks) before allowing direct communication, thus maintaining call establishment speed while reducing vulnerability to harmful traffic

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the CSCF device processes all traffic analysis and security checks itself, then security detection capability is improved, but device complexity and processing load increase

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidCSCF device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security detection function from the CSCF device by introducing an off-board analytics server. The CSCF device retains core call control functions while the analytics server handles complex traffic analysis and security checks. This segmentation improves security detection capability without increasing CSCF device complexity, as the analytics server is a separate component

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If the system terminates communications with user devices when conditions are detected, then protection against harmful traffic is improved, but loss of legitimate communications increases

Engineering Contradiction:
Improveprotection against harmful trafficVSAvoidloss of legitimate communications
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent implements a feedback mechanism where the analytics server continuously monitors traffic conditions and provides real-time feedback to the CSCF device. When harmful traffic is detected, the system dynamically adjusts communication handling (termination, mitigation, or remediation) based on the specific condition detected. This feedback loop ensures protection against harmful traffic while minimizing loss of legitimate communications through intelligent, context-aware decisions

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8958336B2Condition detection by a call session control function (CSCF)
Publication Date: 2015.02.17 VERIZON PATENT & LICENSING INC
  • US8958336B2 patent drawing
  • US8958336B2 patent drawing
  • US8958336B2 patent drawing

AI summary

A system configured to receive, from a user device, traffic associated with a request to initiate a call session; detect a condition associated with the traffic; determine whether to establish the call session based on whether the condition, associated with the traffic, is a particular type of condition; send, to a server device, a notification to perform an operation to remedy the condition when the condition does not correspond to the particular type of condition, where sending the notification enables the server device to identify a type of condition, identify an operation that remedies the condition based on the type of condition, or initiate the operation to remedy the condition; and establish the call session when the type of condition corresponds to the particular type of condition, where establishing the call session enables a call, placed by the user device, to be processed as a normal call.