RTMADS Mitigating Emergency Telephony Attacks via Call Forking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Emergency telephone services, particularly VoIP networks, are vulnerable to malicious attacks such as Telephony Denial of Service (TDoS) and Distributed Denial of Service (DDoS) due to their accessibility over the Internet, leading to potential life-threatening situations as PSAPs become overloaded with fake or spoofed calls, disrupting the availability of critical services.
Innovation Solution
The implementation of a Real-time Telephony Monitor, Analyzer, and Decision SIP Server (RTMADS) system that works in conjunction with a Session Border Controller to fork incoming calls, collect and analyze data, and use a decision matrix to determine appropriate actions, such as terminating malicious calls or rerouting legitimate ones, to mitigate attacks within VoIP networks while adhering to existing SIP and IMS standards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If VoIP nodes are made accessible via the Internet to enable emergency calls, then ease of operation and accessibility are improved, but vulnerability to malicious attacks and reliability deteriorate
Solution Approach 1:
The patent introduces a Session Border Controller (SBC) as an intermediary component between the Internet and the IMS core network. The SBC acts as a security gateway that inspects, filters, and controls SIP traffic, blocking malicious packets while allowing legitimate emergency calls to pass through. This intermediary protects the vulnerable VoIP nodes without compromising Internet accessibility.
Solution Approach 2:
The system performs preliminary security checks and analysis of incoming SIP packets before they reach the core network. The SBC pre-processes traffic by validating call requests, checking for spoofing indicators, and filtering malformed packets in advance, preventing attacks before they can overload the PSAPs.
2Reliability
If PSAPs accept all incoming emergency calls to ensure availability, then service availability is improved, but system overload and loss of function worsen during attacks
Solution Approach 1:
The patent implements a feedback mechanism where the SBC continuously monitors network conditions, call volumes, and attack patterns. Based on this real-time feedback, the SBC dynamically adjusts filtering rules and routing decisions, blocking malicious traffic while ensuring legitimate emergency calls are routed to available PSAPs, thus preventing overload while maintaining availability.
Solution Approach 2:
The system extracts and separates malicious traffic from legitimate emergency calls at the SBC layer. By taking out harmful packets through filtering and blocking before they reach the PSAPs, the system protects the emergency service infrastructure from overload while maintaining full availability for genuine emergencies.
3Reliability
If security filtering is implemented to block malicious calls, then reliability and protection are improved, but false rejection of legitimate calls and loss of information worsens
Solution Approach 1:
The patent employs parameter-based filtering where the SBC analyzes multiple parameters of incoming SIP packets (source IP, destination IP, port numbers, SIP headers, message content) and makes routing decisions based on combinations of these parameters. This multi-parameter analysis reduces false rejections by distinguishing subtle differences between legitimate and malicious calls while maintaining strong protection.
Solution Approach 2:
The system applies different filtering criteria and security rules to different types of traffic and network conditions. The SBC implements location-aware routing that considers the geographic origin of calls and applies appropriate filtering strategies locally, allowing legitimate calls from trusted regions to pass through while blocking attacks from known malicious sources, thereby reducing false rejections.
Data Source
AI summary
The disclosed system provides a Real-time Telephony (or Call) Monitor, Analyzer and Decision SIP Server (RTMADS) for mitigating attacks on emergency telephone systems. The RTMADS works in conjunction with an ingress node to fork incoming calls to an IMS network and the RTMADS. Within the RTMADS, forked telephone calls undergo data collection and mining, and parametric analysis. A decision matrix in the RTMADS uses the results of the data collection, mining, and parametric analysis, and other information, to make a decision with respect to incoming calls. For example, the RTMADS may decide to perform call setup on an incoming call using a dedicated or backup Public Safety Answering Point (PSAP), alert an Operations and Management (OAM) team regarding the incoming call, or accept and then terminate the incoming call.


