Media Port Access Control via Dynamic Token Bucket Feedback
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mechanisms for controlling access to open media ports, such as VoIP gateways and UDP ports, are vulnerable to denial of service attacks and cannot adjust their operation in response to changes in data packet streams, leading to resource overload.
Innovation Solution
A packet token bucket system that uses feedback from the state of incoming data packets to adjust flow control parameters, incrementing and decrementing a counter to regulate data packet flow and reject malicious packets, while authenticating data packets to ensure valid sources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traffic shaping mechanisms like leaky bucket or token bucket are used to control data packet flow rates, then resource overload is prevented, but the mechanisms cannot adjust their operation in response to changes in data packet streams
Solution Approach 1:
The patent implements feedback by monitoring the state of data packet streams (such as packet arrival rates, patterns, and characteristics) and using this information to dynamically adjust flow control parameters. The system observes incoming traffic conditions and modifies its behavior accordingly, allowing the flow control mechanism to adapt to changing network conditions while maintaining protection against resource overload.
2Productivity
If open media ports accept all incoming packets to ensure legitimate traffic passes through, then authorized media streams are delivered, but rogue or malicious packets can consume common resources
Solution Approach 1:
The patent applies local quality by implementing flow control and monitoring specific to each media port or channel. Instead of applying a uniform flow control policy across all ports, the system tailors flow control parameters and monitoring to the characteristics of individual ports and their associated media streams. This allows legitimate traffic on authorized ports to pass through while malicious packets on unauthorized ports are identified and blocked, protecting common resources from harmful factors.
Data Source
AI summary
The present invention is directed to protecting media packet processors from rogue or malicious data packet flows. According to the present invention, feedback obtained from components of a media packet processor having information regarding media stream flows is used to adjust a counter or token bucket controlling the admission of such flows. More specifically, feedback is used to adjust a counter value such that the count value is decremented, or the operation of the counter in incrementing the count value according to a periodic schedule is suppressed, if a dropped packet is detected. Accordingly, the present invention may utilize the predictable quality of media stream flows, and information from components such as jitter buffers and CODECs, in order to tailor bounds on the flow of ingress traffic to a media packet processor.


