SIP Anomaly Prevention System for Rate-Based DoS Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to effectively prevent rate-based denial of service attacks on Session Initiation Protocol (SIP) servers, which are vulnerable to flooding from illegitimate requests, leading to service denial and increased complexity in internet attacks.

Innovation Solution

A hardware-based integrated system that continuously and adaptively learns to identify and prevent SIP rate-thresholds, detecting and dropping packets with anomalies in headers, states, and content, while enforcing network policies through a Content Inspection Engine and policy-based packet filtering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional DoS mitigation appliances are used for SIP servers, then protection against basic attacks is provided, but the system cannot effectively prevent rate-based denial of service attacks and complex flooding patterns

Engineering Contradiction:
Improveprotection effectivenessVSAvoidattack pattern recognition
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts its detection and prevention mechanisms to handle rate-based DoS attacks by continuously monitoring traffic patterns and adjusting rate thresholds. The anomaly prevention system evolves its behavior based on observed attack patterns, making the protection effective against varying attack types while maintaining reliability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes operational parameters such as rate thresholds and detection sensitivity levels to effectively counter different attack patterns. By adjusting these parameters dynamically, the system maintains high protection effectiveness against rate-based attacks while avoiding false positives on legitimate traffic.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If comprehensive packet inspection and anomaly prevention is implemented, then security against complex attacks is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The anomaly prevention system is segmented into distinct functional modules: rate-based anomaly detection, header anomaly detection, state anomaly detection, and content inspection. Each module handles specific aspects of attack prevention, making the overall complex system manageable and maintainable while providing comprehensive security protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components such as anomaly detectors and inspection engines that sit between the network traffic and the SIP server. These intermediaries perform complex inspection and filtering operations, protecting the server from direct exposure to complex attack patterns while maintaining system architecture clarity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If rate thresholding and packet dropping is applied to prevent flooding, then server load is reduced, but legitimate traffic may be blocked

Engineering Contradiction:
Improveserver processing capacityVSAvoidtraffic flow management
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The system implements feedback mechanisms where the anomaly prevention system continuously monitors traffic patterns and adjusts rate thresholds based on observed behavior. This feedback loop ensures that legitimate traffic patterns are learned and preserved, while flooding patterns are detected and blocked, maintaining ease of operation for legitimate users.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary inspection and classification of packets before applying rate thresholding. By pre-identifying legitimate traffic patterns and establishing baseline behavior, the system can apply packet dropping more selectively, ensuring server processing capacity is protected while minimizing impact on legitimate traffic flow.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10009365B2System and method for integrated header, state, rate and content anomaly prevention for session initiation protocol
Publication Date: 2018.06.26 ATHENA SECURITY LLP
  • US10009365B2 patent drawing
  • US10009365B2 patent drawing
  • US10009365B2 patent drawing

AI summary

Methods and systems for an integrated solution to the rate based denial of service attacks targeting the Session Initiation Protocol are provided. According to one embodiment, header, state, rate and content anomalies are prevented and network policy enforcement is provided for session initiation protocol (SIP). A hardware-based apparatus helps identify SIP rate-thresholds through continuous and adaptive learning. The apparatus can determine SIP header and SIP state anomalies and drop packets containing those anomalies. SIP requests and responses are inspected for known malicious contents using a Content Inspection Engine. The apparatus integrates advantageous solutions to prevent anomalous packets and enables a policy based packet filter for SIP.