Network Protection Device for SIP Session Control Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Communication networks employing session control protocols like SIP are vulnerable to Denial-of-Service (DoS) and Distributed DoS (DDoS) attacks, which can overwhelm proxies and deny service to legitimate users, with existing solutions struggling to effectively mitigate such attacks, especially in complex network environments.
Innovation Solution
Implementing a security management system that utilizes hardware-based deep packet inspection (DPI) technology to monitor and manage session control messages, adjusting thresholds for rejecting or allowing messages, and deploying a network protection device (NPD) to analyze and filter out malicious traffic, thereby preventing DoS and DDoS attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If session control messages are monitored and filtered using software-based methods, then security against DoS attacks is improved, but processing load on network devices increases and message filtering speed decreases
Solution Approach 1:
The patent replaces software-based message filtering with hardware-based deep packet inspection (DPI) technology. The network protection device uses dedicated hardware circuits to inspect and filter session control messages, eliminating the processing load from software and enabling high-speed message filtering while maintaining strong security protection against DoS attacks.
2Reliability
If deep packet inspection is implemented to filter malicious traffic, then security protection is improved, but device complexity increases
Solution Approach 1:
The patent segments the network protection function into a dedicated network protection device that operates independently from the proxy server. This separate hardware device performs deep packet inspection specifically for session control messages, providing comprehensive security protection while maintaining manageable system complexity through functional separation.
3Reliability
If threshold-based message rejection is implemented, then protection against DoS attacks is improved, but false rejection of legitimate traffic increases
Solution Approach 1:
The patent implements dynamic threshold adjustment where the network protection device continuously monitors traffic patterns and adapts rejection thresholds in real-time. This dynamic approach allows the system to maintain high protection levels against DoS attacks while automatically adjusting to avoid false rejection of legitimate traffic, reducing the false positive rate.
Data Source
AI summary
A method may include receiving session control messages and counting the session control messages of a same type having a same transaction identifier (ID). The method may further include blocking the session control messages of the same type having the same transaction ID when the count exceeds a threshold number. The method may further include determining whether the blocked session control messages are associated with an anomalous event and, when the blocked session control messages are not associated with the anomalous event, increasing the threshold number.


