Unauthorized Access Prevention via Signaling Packet Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unauthorized access from networks to terminals, often facilitated by viruses concealed in signaling packets, leads to buffer overflow and ineffective virus checking, allowing malicious traffic and sessions to proceed undetected.

Innovation Solution

An unauthorized access prevention method that receives signaling packets, detects and discards packets with unauthorized access descriptions, translates port numbers, and ensures only protocol-compliant session packets are transmitted, thereby preventing viral infections and buffer overflows.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a large number of signaling packets are sent to transmit video data or music data, then the session communication function is improved, but the buffer overflows and prevents the virus check function from being effective

Engineering Contradiction:
Improvesession communication efficiencyVSAvoidvirus check effectiveness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by performing virus detection on signaling packets before they are transmitted to the terminal. The detection is conducted in advance during the signaling phase, identifying potential viruses in SDP descriptions or other packet components before they can cause buffer overflow or infect the terminal. This preliminary detection prevents harmful packets from reaching the terminal while allowing legitimate communication to proceed efficiently.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If port numbers are opened to allow video data or music data transmission, then the communication capability is improved, but viruses are transmitted by using the other port together with the video data or music data for streaming

Engineering Contradiction:
Improvecommunication capabilityVSAvoidviral transmission risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent uses an intermediary approach by introducing a detection mechanism that mediates between the network and the terminal. The detection unit acts as an intermediary that examines signaling packets containing port number descriptions, identifying viruses that attempt to use opened ports for transmission. This intermediary detection allows legitimate multi-port communication while blocking malicious viral transmission attempts.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If signaling packets are transmitted without filtering, then the transmission speed is improved, but unauthorized access descriptions are transmitted to the terminal

Engineering Contradiction:
Improvepacket transmission speedVSAvoidunauthorized access
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent applies the extraction principle by removing harmful components from signaling packets during transmission. The detection unit extracts and identifies unauthorized access descriptions, virus signatures, or malicious SDP content from packets before they reach the terminal. By taking out these harmful elements through detection and filtering, the system maintains transmission speed for legitimate packets while preventing unauthorized access attempts.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS7770211B2Unauthorized access prevention method, unauthorized access prevention apparatus and unauthorized access prevention program
Publication Date: 2010.08.03 NEC PLATFROMS LTD
  • US7770211B2 patent drawing
  • US7770211B2 patent drawing
  • US7770211B2 patent drawing

AI summary

Unauthorized access from a network to a terminal is prevented. If a signaling packet received from an external terminal contains a virus, the signaling packet is discarded. If the signaling packet does not apparently contains a virus, an unnecessary part is deleted and the signaling packet is transferred to an internal terminal in response to a polling signal. A port number described in a response packet received from the internal terminal is translated to a different port number. If a session packet received from the external terminal does not conform to a predetermined protocol, the session packet is discarded. If the session packet received from the external terminal conforms to the predetermined protocol, a port number is subject to reverse translation and a resultant session packet is transferred to the internal terminal.