Distributed FSM VoIP Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Intrusion-detection systems for Voice over Internet Protocol (VoIP) systems often rely on attack signature databases, which require frequent updates and can be inadequate against VoIP-based intrusions, posing challenges in maintaining security and detecting potential threats.

Innovation Solution

The implementation of a finite-state machine (FSM) system that represents VoIP protocols and maintains both individual and global FSMs to detect intrusions by monitoring state transitions and generating alerts for potential threats without relying on attack signature databases.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If attack signature databases are used for intrusion detection in VoIP systems, then detection capability against known attacks is improved, but system complexity and maintenance burden increase due to frequent updates required

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical system of manually updating attack signature databases with an automated model-based detection system. Instead of relying on curated signature databases that require continuous maintenance, the system automatically generates behavioral models from network traffic and detects intrusions by comparing actual traffic against these dynamically created models, eliminating the need for manual database updates while maintaining high detection capability

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The intrusion detection system performs self-service by automatically generating its own detection models from observed network traffic patterns. The system learns normal VoIP protocol behavior autonomously and uses this learned behavior to detect deviations indicating intrusions, without requiring external intervention for database updates or signature maintenance

Inventive Principle:
Principle #25Self-service

2Reliability

If attack signature databases are used for intrusion detection, then detection of known attacks is improved, but adaptability to new and unknown VoIP-based intrusions deteriorates

Engineering Contradiction:
Improvedetection capabilityVSAvoidadaptability to new attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamics by making the intrusion detection system adaptive rather than static. Instead of relying on fixed attack signatures, the system continuously learns from network traffic and dynamically updates its behavioral models. This allows the system to automatically adapt to new attack patterns and unknown intrusions by comparing actual traffic against evolving models of normal behavior, providing both reliability for known attacks and adaptability for new threats

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If attack signature databases are maintained with frequent updates, then detection accuracy is improved, but time and resources required for maintenance increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidmaintenance time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces the manual maintenance process with an automated model-generation system. Detection accuracy is maintained through continuous automatic learning from network traffic, eliminating the need for human operators to spend time updating databases. The system autonomously generates and updates behavioral models in real-time, preserving high detection accuracy while eliminating maintenance time losses

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9178898B2Distributed stateful intrusion detection for voice over IP
Publication Date: 2015.11.03 AVAYA INC
  • US9178898B2 patent drawing
  • US9178898B2 patent drawing
  • US9178898B2 patent drawing

AI summary

An apparatus and method for detecting intrusions in Voice over Internet Protocol systems with distributed stateful intrusion detection. When a Session Initiation Protocol (SIP) signal is received as an application-layer protocol signal, the received application-layer protocol signal is distributed to a first finite-state machine and to a second finite-state machine. A data processing system detects that the application-layer protocol enters a first application-layer protocol state S1 at a first node at a first time, determines whether the application-layer protocol fails to enter a second application-layer protocol state S2 at a second node within δ seconds, a positive real number, and generates a signal that indicates a potential intrusion in response to the determination.