RTMADS Mitigating Emergency Telephony Attacks via Call Forking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Emergency telephone services, particularly VoIP networks, are vulnerable to malicious attacks such as Telephony Denial of Service (TDoS) and Distributed Denial of Service (DDoS) due to their accessibility over the Internet, leading to potential life-threatening situations as PSAPs become overloaded with fake or spoofed calls, disrupting the availability of critical services.

Innovation Solution

The implementation of a Real-time Telephony Monitor, Analyzer, and Decision SIP Server (RTMADS) system that works in conjunction with a Session Border Controller to fork incoming calls, collect and analyze data, and use a decision matrix to determine appropriate actions, such as terminating malicious calls or rerouting legitimate ones, to mitigate attacks within VoIP networks while adhering to existing SIP and IMS standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If VoIP nodes are made accessible via the Internet to enable emergency calls, then ease of operation and accessibility are improved, but vulnerability to malicious attacks and reliability deteriorate

Engineering Contradiction:
ImproveaccessibilityVSAvoidvulnerability to attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a Session Border Controller (SBC) as an intermediary component between the Internet and the IMS core network. The SBC acts as a security gateway that inspects, filters, and controls SIP traffic, blocking malicious packets while allowing legitimate emergency calls to pass through. This intermediary protects the vulnerable VoIP nodes without compromising Internet accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary security checks and analysis of incoming SIP packets before they reach the core network. The SBC pre-processes traffic by validating call requests, checking for spoofing indicators, and filtering malformed packets in advance, preventing attacks before they can overload the PSAPs.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If PSAPs accept all incoming emergency calls to ensure availability, then service availability is improved, but system overload and loss of function worsen during attacks

Engineering Contradiction:
Improveservice availabilityVSAvoidsystem overload
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a feedback mechanism where the SBC continuously monitors network conditions, call volumes, and attack patterns. Based on this real-time feedback, the SBC dynamically adjusts filtering rules and routing decisions, blocking malicious traffic while ensuring legitimate emergency calls are routed to available PSAPs, thus preventing overload while maintaining availability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system extracts and separates malicious traffic from legitimate emergency calls at the SBC layer. By taking out harmful packets through filtering and blocking before they reach the PSAPs, the system protects the emergency service infrastructure from overload while maintaining full availability for genuine emergencies.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If security filtering is implemented to block malicious calls, then reliability and protection are improved, but false rejection of legitimate calls and loss of information worsens

Engineering Contradiction:
ImproveprotectionVSAvoidfalse rejection
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent employs parameter-based filtering where the SBC analyzes multiple parameters of incoming SIP packets (source IP, destination IP, port numbers, SIP headers, message content) and makes routing decisions based on combinations of these parameters. This multi-parameter analysis reduces false rejections by distinguishing subtle differences between legitimate and malicious calls while maintaining strong protection.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system applies different filtering criteria and security rules to different types of traffic and network conditions. The SBC implements location-aware routing that considers the geographic origin of calls and applies appropriate filtering strategies locally, allowing legitimate calls from trusted regions to pass through while blocking attacks from known malicious sources, thereby reducing false rejections.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10637994B2Mitigating attacks on emergency telephone services
Publication Date: 2020.04.28 T MOBILE US INC
  • US10637994B2 patent drawing
  • US10637994B2 patent drawing
  • US10637994B2 patent drawing

AI summary

The disclosed system provides a Real-time Telephony (or Call) Monitor, Analyzer and Decision SIP Server (RTMADS) for mitigating attacks on emergency telephone systems. The RTMADS works in conjunction with an ingress node to fork incoming calls to an IMS network and the RTMADS. Within the RTMADS, forked telephone calls undergo data collection and mining, and parametric analysis. A decision matrix in the RTMADS uses the results of the data collection, mining, and parametric analysis, and other information, to make a decision with respect to incoming calls. For example, the RTMADS may decide to perform call setup on an incoming call using a dedicated or backup Public Safety Answering Point (PSAP), alert an Operations and Management (OAM) team regarding the incoming call, or accept and then terminate the incoming call.