Unauthorized Access Prevention via Signaling Packet Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Unauthorized access from networks to terminals, often facilitated by viruses concealed in signaling packets, leads to buffer overflow and ineffective virus checking, allowing malicious traffic and sessions to proceed undetected.
Innovation Solution
An unauthorized access prevention method that receives signaling packets, detects and discards packets with unauthorized access descriptions, translates port numbers, and ensures only protocol-compliant session packets are transmitted, thereby preventing viral infections and buffer overflows.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a large number of signaling packets are sent to transmit video data or music data, then the session communication function is improved, but the buffer overflows and prevents the virus check function from being effective
Solution Approach 1:
The patent applies preliminary action by performing virus detection on signaling packets before they are transmitted to the terminal. The detection is conducted in advance during the signaling phase, identifying potential viruses in SDP descriptions or other packet components before they can cause buffer overflow or infect the terminal. This preliminary detection prevents harmful packets from reaching the terminal while allowing legitimate communication to proceed efficiently.
2Adaptability or versatility
If port numbers are opened to allow video data or music data transmission, then the communication capability is improved, but viruses are transmitted by using the other port together with the video data or music data for streaming
Solution Approach 1:
The patent uses an intermediary approach by introducing a detection mechanism that mediates between the network and the terminal. The detection unit acts as an intermediary that examines signaling packets containing port number descriptions, identifying viruses that attempt to use opened ports for transmission. This intermediary detection allows legitimate multi-port communication while blocking malicious viral transmission attempts.
3Speed
If signaling packets are transmitted without filtering, then the transmission speed is improved, but unauthorized access descriptions are transmitted to the terminal
Solution Approach 1:
The patent applies the extraction principle by removing harmful components from signaling packets during transmission. The detection unit extracts and identifies unauthorized access descriptions, virus signatures, or malicious SDP content from packets before they reach the terminal. By taking out these harmful elements through detection and filtering, the system maintains transmission speed for legitimate packets while preventing unauthorized access attempts.
Data Source
AI summary
Unauthorized access from a network to a terminal is prevented. If a signaling packet received from an external terminal contains a virus, the signaling packet is discarded. If the signaling packet does not apparently contains a virus, an unnecessary part is deleted and the signaling packet is transferred to an internal terminal in response to a polling signal. A port number described in a response packet received from the internal terminal is translated to a different port number. If a session packet received from the external terminal does not conform to a predetermined protocol, the session packet is discarded. If the session packet received from the external terminal conforms to the predetermined protocol, a port number is subject to reverse translation and a resultant session packet is transferred to the internal terminal.


