Endpoint Embedded Firewall for VoIP Malicious Packet Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Telecommunications endpoints in VoIP networks are vulnerable to malicious packet attacks due to the imbalance between networking capacity and processing power, and existing network-edge firewalls are inadequate in monitoring and filtering traffic within the network, lacking the specific knowledge required to effectively filter out malicious packets.

Innovation Solution

An embedded firewall is implemented at the telecommunications endpoint, where the application directly communicates with the co-resident firewall engine through local message passing, shares memory, and uses a middleware layer to dynamically modify packet-classification rules, allowing for efficient filtering of ingress packets based on predetermined characteristics and socket calls.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an embedded firewall is implemented at the telecommunications endpoint, then the ability to filter malicious packets is improved, but the device complexity increases

Engineering Contradiction:
Improvepacket filtering capabilityVSAvoidendpoint system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the firewall functionality directly into the telecommunications endpoint by integrating a firewall engine and packet-classification rules database into the endpoint's existing architecture. This consolidation allows the endpoint to filter malicious packets while maintaining a unified system structure, resolving the contradiction by combining security functions with the core endpoint operations.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The embedded firewall engine is designed to perform multiple functions: filtering ingress packets, blocking malicious traffic, allowing legitimate traffic, and dynamically updating rules. By making the firewall engine multi-functional and integral to the endpoint's operation, the system achieves improved packet filtering capability without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Object-affected harmful factors

If network-edge firewalls are used to filter traffic, then the filtering function is provided, but the effectiveness in monitoring and filtering internal traffic is insufficient

Engineering Contradiction:
Improvemalicious packet protectionVSAvoidtraffic monitoring effectiveness
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

Instead of placing the firewall at the network edge as in traditional architectures, the patent inverts the approach by embedding the firewall directly at the telecommunications endpoint. This inversion allows the firewall to monitor and filter traffic at the source, providing both protection against malicious packets and effective monitoring of internal traffic, thereby resolving the contradiction.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The endpoint performs its own security functions by executing a local firewall engine that autonomously filters incoming packets based on stored rules. This self-service approach eliminates the need for external network-edge firewalls to effectively monitor internal traffic, as the endpoint itself conducts the filtering and monitoring, achieving both protection and monitoring effectiveness.

Inventive Principle:
Principle #25Self-service

3Productivity

If the application directly communicates with the firewall engine through local message passing and shared memory, then the filtering efficiency is improved, but the system complexity increases

Engineering Contradiction:
Improvepacket filtering efficiencyVSAvoidcommunication mechanism complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the firewall system into distinct functional components: the application layer, the firewall engine, and the rules database. The application communicates with the firewall engine through defined interfaces (local message passing and shared memory), allowing efficient packet filtering while managing complexity through clear separation of concerns and standardized communication protocols.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2141885B1Embedded firewall at a telecommunications endpoint
Publication Date: 2015.04.22 AVAYA INC
  • EP2141885B1 patent drawingFigure 1
  • EP2141885B1 patent drawingFigure 2
  • EP2141885B1 patent drawingFigure 3

AI summary

A method is disclosed that enables the implementation of an embedded firewall at a telecommunications endpoint. In particular, the illustrative embodiment of the present invention addresses the relationship between the application, firewall engine, and packet-classification rules database that are all resident at the endpoint. In the variations of the illustrative embodiment that are described herein, the application: (i) directly communicates with the co-resident firewall engine such as through local message passing, (ii) shares memory with the firewall engine, and (iii) makes socket calls to the operating system that are intercepted by a middleware layer that subsequently modifies the rules database, depending on the socket call. The common thread to these techniques is that the application, firewall engine, and rules database are co-resident at the endpoint, which is advantageous in the implementation of the embedded firewall.