SIP Packet Analysis for Malicious Data Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security systems are ineffective in detecting unwanted data communicated via Session Initiation Protocol (SIP), particularly in voice over Internet Protocol (VoIP) communications, which allows malicious data to go undetected.

Innovation Solution

A system and method that identifies packets associated with electronic messages over a network using SIP, determines if they contain unwanted data, and performs a reaction based on this determination, including blocking or alerting, to prevent unwanted data from entering internal networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security systems are used for detecting unwanted data, then general security detection capability is provided, but detection of unwanted data communicated via SIP is ineffective

Engineering Contradiction:
Improvedetection effectivenessVSAvoidprotocol-specific detection capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary identification of SIP packets before full security analysis. By recognizing SIP protocol patterns in advance, the system can apply specialized detection rules specifically designed for SIP communications, thereby improving reliability for this protocol type without requiring complete redesign of the security architecture.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security system applies different detection strategies tailored to SIP protocol characteristics. Instead of using a uniform detection approach for all protocols, the system implements protocol-specific detection mechanisms that analyze SIP packet structures, headers, and message bodies with appropriate security rules, enhancing detection effectiveness for SIP while maintaining general capability for other protocols.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If traditional security techniques are applied to SIP communications, then general security coverage is maintained, but unwanted data via SIP remains undetected

Engineering Contradiction:
Improveprotocol coverageVSAvoidunwanted data detection accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The system changes detection parameters specifically when analyzing SIP packets. This includes adjusting analysis depth, packet inspection methods, and security rule application based on SIP protocol characteristics such as message types (INVITE, REGISTER, BYE), header structures, and body formats, thereby improving measurement precision for SIP-specific unwanted data while preserving broad protocol coverage.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If SIP communications are allowed without specialized detection, then network accessibility is maintained, but malicious packets can enter internal networks

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidmalicious data intrusion
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system introduces an intermediary security analysis layer that processes SIP packets between the external network and internal network. This intermediary component identifies and blocks malicious SIP packets while allowing legitimate SIP communications to pass through unchanged, thereby maintaining network accessibility for authorized traffic while preventing harmful factors from reaching internal networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8713678B1System, method, and computer program product for identifying unwanted data communicated via a session initiation protocol
Publication Date: 2014.04.29 MCAFEE LLC
  • US8713678B1 patent drawing
  • US8713678B1 patent drawing
  • US8713678B1 patent drawing

AI summary

A system, method, and computer program product are provided for identifying unwanted data communicated via a session initiation protocol. In use, packets associated with an electronic message communicated over a network utilizing a session initiation protocol are identified. Additionally, it is determined whether the packets include unwanted data. Furthermore, a reaction is performed, based on the determination.