IMS Application Server Overload Protection via Per-User Request Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems are ineffective in protecting Internet Protocol Multimedia Subsystem (IMS) network elements, such as application servers, from Denial of Service (DoS) attacks, which overload network resources and disrupt regular traffic by not being able to detect and counter such attacks at the interconnection border level.

Innovation Solution

A control system that receives and filters requests to contact an end point in an IMS network, using initial filter criteria to limit the number of requests within a predetermined time frame, allowing only a defined number of requests to proceed to an application server, thereby protecting it from overload and enabling per-user basis protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If interconnection border nodes limit traffic based on total traffic values, then network element occupancy rate is controlled, but per-user DoS attacks cannot be detected when they stay below interface thresholds

Engineering Contradiction:
Improveservice availabilityVSAvoidprotection mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the traffic protection mechanism into two layers: (1) interconnection border level with total traffic occupancy rate monitoring, and (2) application server level with per-user request rate limiting. This segmentation allows each layer to address specific aspects of the problem without requiring complete redesign of the existing border protection mechanism.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The application server acts as an intermediary protection layer between the interconnection border and the end user. It receives requests from the border, monitors per-user request rates, and selectively forwards or rejects requests based on configured rate limits, thus protecting against DoS attacks that bypass border-level controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If network elements limit traffic load based on total traffic values, then overall network capacity is protected, but individual user attacks remain undetected

Engineering Contradiction:
Improvenetwork throughputVSAvoidattack detection precision
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent divides traffic monitoring and control into two granularity levels: aggregate traffic monitoring at the interconnection border and per-user request rate monitoring at the application server. This segmentation enables precise detection of individual user attacks while maintaining overall network throughput management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The application server implements localized per-user rate limiting with configurable thresholds specific to each user or service. This allows precise control over individual user traffic patterns without affecting the overall network capacity management performed at the border level.

Inventive Principle:
Principle #3Local quality

3Reliability

If SIP request throttling is implemented only at P-CSCF on per-user basis, then user-level protection is provided, but application servers remain vulnerable in terminating use cases

Engineering Contradiction:
Improveuser-level protectionVSAvoidprotection architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The application server is configured to act as an additional intermediary protection layer in the terminating use case. It receives SIP requests from the P-CSCF, independently monitors per-user request rates according to its own configured thresholds, and provides a second layer of filtering before requests reach the end user, thus protecting against attacks that exceed P-CSCF thresholds or bypass it entirely.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The application server performs preliminary rate limiting checks on incoming SIP requests before processing them further. By configuring rate thresholds and monitoring per-user request patterns in advance, it can reject malicious requests early in the processing chain, preventing application server overload before resources are consumed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3544254B1IMS application server overload protection
Publication Date: 2024.09.11 DEUTSCHE TELEKOM AG
  • EP3544254B1 patent drawingFigure 1
  • EP3544254B1 patent drawingFigure 2

AI summary

The invention refers to a control system (1) for controlling requests to contact an end point (5) of a network (6), particularly of an Internet Protocol Multimedia Subsystem network, comprising receiving means being configured to receive requests from a sender (2) via the network (6) to contact an end point (5), control means being configured to limit a number of requests to contact the end point (5) according to initial filter criteria, iFC, defining a predetermined number of allowed requests in a predetermined period of time T1, and transmitting means being configured to transmit a request to an application server (4) if the request fulfills the iFC, wherein the application server (4) is configured to host at least one connection to the at least one end point (5).