IP Telephony DoS Protection via Challenge-Response Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IP telephony systems are vulnerable to denial of service attacks, which disrupt normal operations and cause significant financial harm, especially in real-time systems like 911 networks, due to resource exhaustion from overwhelming message volumes.

Innovation Solution

An IP telephony protection system that monitors incoming messages, identifies suspicious senders, and blocks them using a protection scheme that includes challenging senders, evaluating responses, and maintaining blocked sender lists to prevent resource exhaustion and ensure timely message delivery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an IP telephony system accepts all incoming messages without filtering, then message delivery completeness is maintained, but resource exhaustion occurs due to denial of service attacks

Engineering Contradiction:
Improvemessage delivery completenessVSAvoidresource exhaustion
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by maintaining blocked sender lists and suspect sender lists in advance. When a denial of service attack is detected, the system has already prepared filtering mechanisms to quickly block malicious senders without disrupting legitimate message flow, thus preventing resource exhaustion while maintaining delivery completeness

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces intermediary mechanisms including challenge-response systems and suspect sender lists that act as mediators between incoming messages and the IP telephony system. These intermediaries filter and evaluate messages before they reach the core system, preventing resource exhaustion from malicious attacks while allowing legitimate messages to pass through

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If a protection scheme blocks incoming messages from suspected senders, then resource exhaustion is prevented, but legitimate messages may be blocked causing delivery delays

Engineering Contradiction:
Improveresource exhaustion preventionVSAvoidmessage delivery time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The protection scheme dynamically adjusts blocking decisions based on real-time evaluation of sender behavior. Senders are placed on suspect lists temporarily and subject to challenge-response verification. If they pass verification or exhibit legitimate patterns, they are removed from blocking lists. This dynamic approach prevents resource exhaustion while minimizing blocking of legitimate messages

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms where blocked senders can be challenged and evaluated. If a sender provides a correct response to a challenge or demonstrates legitimate messaging patterns, they are removed from the blocked list. This feedback loop ensures that legitimate messages are not permanently blocked while maintaining protection against denial of service attacks

Inventive Principle:
Principle #23Feedback

3Measurement precision

If challenge-response verification is implemented for suspected senders, then attack detection accuracy is improved, but processing time and system complexity increase

Engineering Contradiction:
Improveattack detection accuracyVSAvoidprotection scheme complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The challenge-response verification is applied locally and selectively only to senders who are placed on suspect lists, not to all incoming messages. This localized application maintains high attack detection accuracy for suspicious senders while avoiding unnecessary processing complexity for legitimate senders, thus balancing detection precision with system simplicity

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10542037B2Denial of service protection for IP telephony systems
Publication Date: 2020.01.21 RIBBON COMMUNICATIONS OPERATING CO INC
  • US10542037B2 patent drawing
  • US10542037B2 patent drawing
  • US10542037B2 patent drawing

AI summary

A system and method for protecting components of an IP telephony network whereby a protection scheme is enabled upon detection of resource exhaustion within the network that prevents delivery of incoming messages. Resource exhaustion may result from denial of service attacks and/or malfunctions in automated dialing systems. Once a protection scheme is enabled, the system activates mechanisms for identifying calling parties that are suspected of contributing to the resource exhaustion condition. These suspected calling parties may be placed in a blocked sender list, either manually or automatically. Calling parties may be presented with a challenge function in order to determine whether the call is being made by an automated dialing system. The system blocks incoming calls from calling parties identified in the blocked sender list either permanently or for a specified time duration. The protection scheme remains enabled for a specified duration or until the resource exhaustion condition has subsided.