IP Telephony DoS Protection via Challenge-Response Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IP telephony systems are vulnerable to denial of service attacks, which disrupt normal operations and cause significant financial harm, especially in real-time systems like 911 networks, due to resource exhaustion from overwhelming message volumes.
Innovation Solution
An IP telephony protection system that monitors incoming messages, identifies suspicious senders, and blocks them using a protection scheme that includes challenging senders, evaluating responses, and maintaining blocked sender lists to prevent resource exhaustion and ensure timely message delivery.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an IP telephony system accepts all incoming messages without filtering, then message delivery completeness is maintained, but resource exhaustion occurs due to denial of service attacks
Solution Approach 1:
The system performs preliminary actions by maintaining blocked sender lists and suspect sender lists in advance. When a denial of service attack is detected, the system has already prepared filtering mechanisms to quickly block malicious senders without disrupting legitimate message flow, thus preventing resource exhaustion while maintaining delivery completeness
Solution Approach 2:
The patent introduces intermediary mechanisms including challenge-response systems and suspect sender lists that act as mediators between incoming messages and the IP telephony system. These intermediaries filter and evaluate messages before they reach the core system, preventing resource exhaustion from malicious attacks while allowing legitimate messages to pass through
2Object-affected harmful factors
If a protection scheme blocks incoming messages from suspected senders, then resource exhaustion is prevented, but legitimate messages may be blocked causing delivery delays
Solution Approach 1:
The protection scheme dynamically adjusts blocking decisions based on real-time evaluation of sender behavior. Senders are placed on suspect lists temporarily and subject to challenge-response verification. If they pass verification or exhibit legitimate patterns, they are removed from blocking lists. This dynamic approach prevents resource exhaustion while minimizing blocking of legitimate messages
Solution Approach 2:
The system implements feedback mechanisms where blocked senders can be challenged and evaluated. If a sender provides a correct response to a challenge or demonstrates legitimate messaging patterns, they are removed from the blocked list. This feedback loop ensures that legitimate messages are not permanently blocked while maintaining protection against denial of service attacks
3Measurement precision
If challenge-response verification is implemented for suspected senders, then attack detection accuracy is improved, but processing time and system complexity increase
Solution Approach 1:
The challenge-response verification is applied locally and selectively only to senders who are placed on suspect lists, not to all incoming messages. This localized application maintains high attack detection accuracy for suspicious senders while avoiding unnecessary processing complexity for legitimate senders, thus balancing detection precision with system simplicity
Data Source
AI summary
A system and method for protecting components of an IP telephony network whereby a protection scheme is enabled upon detection of resource exhaustion within the network that prevents delivery of incoming messages. Resource exhaustion may result from denial of service attacks and/or malfunctions in automated dialing systems. Once a protection scheme is enabled, the system activates mechanisms for identifying calling parties that are suspected of contributing to the resource exhaustion condition. These suspected calling parties may be placed in a blocked sender list, either manually or automatically. Calling parties may be presented with a challenge function in order to determine whether the call is being made by an automated dialing system. The system blocks incoming calls from calling parties identified in the blocked sender list either permanently or for a specified time duration. The protection scheme remains enabled for a specified duration or until the resource exhaustion condition has subsided.


