Network Protection Device for SIP Session Control Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Communication networks employing session control protocols like SIP are vulnerable to Denial-of-Service (DoS) and Distributed DoS (DDoS) attacks, which can overwhelm proxies and deny service to legitimate users, with existing solutions struggling to effectively mitigate such attacks, especially in complex network environments.

Innovation Solution

Implementing a security management system that utilizes hardware-based deep packet inspection (DPI) technology to monitor and manage session control messages, adjusting thresholds for rejecting or allowing messages, and deploying a network protection device (NPD) to analyze and filter out malicious traffic, thereby preventing DoS and DDoS attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If session control messages are monitored and filtered using software-based methods, then security against DoS attacks is improved, but processing load on network devices increases and message filtering speed decreases

Engineering Contradiction:
Improvesecurity protectionVSAvoidmessage processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces software-based message filtering with hardware-based deep packet inspection (DPI) technology. The network protection device uses dedicated hardware circuits to inspect and filter session control messages, eliminating the processing load from software and enabling high-speed message filtering while maintaining strong security protection against DoS attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If deep packet inspection is implemented to filter malicious traffic, then security protection is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network protection function into a dedicated network protection device that operates independently from the proxy server. This separate hardware device performs deep packet inspection specifically for session control messages, providing comprehensive security protection while maintaining manageable system complexity through functional separation.

Inventive Principle:
Principle #1Segmentation

3Reliability

If threshold-based message rejection is implemented, then protection against DoS attacks is improved, but false rejection of legitimate traffic increases

Engineering Contradiction:
Improveattack protectionVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic threshold adjustment where the network protection device continuously monitors traffic patterns and adapts rejection thresholds in real-time. This dynamic approach allows the system to maintain high protection levels against DoS attacks while automatically adjusting to avoid false rejection of legitimate traffic, reducing the false positive rate.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8984627B2Network security management
Publication Date: 2015.03.17 VERIZON PATENT & LICENSING INC
  • US8984627B2 patent drawing
  • US8984627B2 patent drawing
  • US8984627B2 patent drawing

AI summary

A method may include receiving session control messages and counting the session control messages of a same type having a same transaction identifier (ID). The method may further include blocking the session control messages of the same type having the same transaction ID when the count exceeds a threshold number. The method may further include determining whether the blocked session control messages are associated with an anomalous event and, when the blocked session control messages are not associated with the anomalous event, increasing the threshold number.