Emergency Call Filtering via Internet Activity Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

It is challenging for 911 answering centers to differentiate between legitimate emergency calls and denial-of-service attacks, as resources are often misallocated, potentially delaying genuine emergency responses.

Innovation Solution

A communication system comprising a mobile device, Internet Activities Pattern Determination Server, and Emergency Answering Center that analyzes recent internet activities of callers to identify patterns, determining if calls are part of a denial-of-service attack by comparing visited websites and internet usage patterns, thereby prioritizing legitimate calls and alerting public safety agencies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If resources are utilized on a bogus caller, then legitimate callers are being delayed in getting a response to their emergency situation

Engineering Contradiction:
Improveresponse accuracyVSAvoidemergency response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary analysis of caller behavior patterns, internet activity, and call characteristics before allocating resources. By pre-screening calls for signs of DoS attacks (such as analyzing internet browsing history, call timing patterns, and behavioral anomalies), the system identifies malicious calls in advance and prevents resource allocation to bogus callers, thereby avoiding delays to legitimate emergencies.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary analysis layer between call reception and resource allocation. This intermediary system evaluates multiple data sources (internet activity logs, caller ID patterns, behavioral analysis) to determine call legitimacy before routing to emergency services. The intermediary acts as a filter that protects the resource allocation system from malicious calls while allowing legitimate calls to pass through unchanged.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If a call is a legitimate emergency call and is treated like a denial-of-service attack call, then a legitimate emergency may be delayed or ignored

Engineering Contradiction:
Improveattack mitigation efficiencyVSAvoidemergency call reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system applies different analysis criteria and scrutiny levels to different calls based on their individual characteristics. Rather than treating all calls uniformly, the system identifies specific local qualities in caller behavior (such as unusual internet activity patterns, atypical call timing, or suspicious metadata) that indicate DoS attacks. Legitimate calls with normal characteristics receive standard processing, while only calls exhibiting specific malicious indicators undergo enhanced scrutiny or blocking.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent dynamically adjusts detection parameters and thresholds based on contextual information. The system monitors multiple parameters (call frequency, internet activity patterns, time of day, caller location) and changes its detection sensitivity accordingly. When legitimate emergency patterns are detected, the system reduces false positive thresholds; when DoS attack patterns emerge, it increases scrutiny on specific parameters while maintaining normal processing for calls that don't match attack profiles.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If internet activity data is collected and analyzed for all callers, then call verification accuracy is improved, but system complexity and processing requirements increase

Engineering Contradiction:
Improvecaller verification accuracyVSAvoidsystem processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system extracts only the essential and most discriminative features from internet activity data rather than analyzing complete datasets. Instead of processing all internet browsing history, the system identifies and extracts key indicators such as specific website categories visited, time spent on suspicious sites, or patterns of rapid page loading. This extraction approach maintains verification accuracy while dramatically reducing processing complexity and data storage requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements partial analysis where internet activity data is collected and analyzed only for calls that exhibit certain risk indicators or during periods when DoS attacks are detected. Rather than continuously analyzing all caller data, the system applies intensive analysis selectively to suspicious calls while using lighter-weight verification for normal calls. This partial action approach achieves high verification accuracy for critical cases without the overhead of universal intensive analysis.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11095681B2Method to handle the distributed denial-of-service attacks 911 answering centers
Publication Date: 2021.08.17 MOTOROLA SOLUTIONS INC
  • US11095681B2 patent drawing
  • US11095681B2 patent drawing
  • US11095681B2 patent drawing

AI summary

An emergency answering center and a method of handling a distributed denial of service attack on an emergency answering center are provided. The emergency answering center receives an emergency call from a current caller. The emergency answering center determines websites visited by the current caller prior to calling the emergency answering center. If the number of calls received at the emergency answering center within a predetermined time period exceeds a predetermined threshold, the emergency answering center compares the websites visited by the current caller prior to calling the emergency answering center to a list of websites visited by other callers within the predetermined time period. If the websites visited by the current caller match at least a subset of the list of websites visited by other callers within the predetermined time period, the emergency answering center processes the emergency call in an alternate manner that is different from the regular manner of processing emergency calls.