TDOS Attack Detection and Banishment in Telephony Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Telephony denial of service (TDOS) attacks deplete resources of mobile positioning centers, Voice over Internet Protocol positioning centers, emergency call management centers, and public safety answering points by exhausting pseudo automatic number identification (pANI) pools, leading to loss of caller location and competition for resources with real calls.
Innovation Solution
Implementing algorithms to detect TDOS attacks by identifying repeated calls from the same number exceeding a threshold, banishing calls using error codes, and interrogating callers to determine legitimate emergencies, thereby preventing resource exhaustion and maintaining system functionality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the pANI pool is used to assign telephone numbers to incoming calls, then calls can be routed and processed, but the pool can be exhausted by TDOS attacks, leading to loss of caller location and resource depletion
Solution Approach 1:
The system performs preliminary actions by detecting TDOS attack patterns (repeated calls from same number within time threshold) before the pANI pool is exhausted. Once an attack is detected, the system proactively bans the attacking telephone number, preventing further consumption of pANI resources and protecting the pool from depletion
Solution Approach 2:
The system converts the harmful TDOS attack traffic into a beneficial security feature by using the attack patterns themselves as detection criteria. The repeated call behavior that constitutes the attack is precisely what triggers the ban mechanism, transforming the harmful resource consumption into useful intelligence for identifying and blocking malicious sources
2Reliability
If repeated calls are allowed to maintain pool resources, then real calls can access pANI numbers, but TDOS attacks can deplete the pool rapidly, causing loss of location information
Solution Approach 1:
The system applies preliminary anti-action by establishing a ban mechanism that prevents attacking telephone numbers from consuming pANI resources. By detecting the attack pattern early and banning the source number, the system counteracts the harmful effect before it can deplete the pool and cause location information loss
Solution Approach 2:
The system uses feedback from monitoring call patterns to dynamically adjust its response. By continuously tracking the number of calls from each telephone number within the threshold period, the system receives feedback on attack intensity and adjusts by banning numbers that exceed the threshold, thereby maintaining location availability
3Reliability
If the system monitors and bans calls exceeding call thresholds, then TDOS attacks can be halted, but additional processing overhead is introduced for call interception and banishment
Solution Approach 1:
The system applies partial action by monitoring only the essential parameters needed for attack detection (telephone number, call count, time threshold) rather than analyzing all call details. This selective monitoring provides sufficient protection against TDOS attacks while minimizing the processing overhead and complexity
Data Source
AI summary
A method includes receiving a first call; identifying a first telephone number associated with the first call; receiving a second call; identifying a second telephone number associated with the second call; determining to banish the second call, at least in part based the second telephone number and a determination that a number of calls associated with the first telephone number exceeds a predetermined threshold; and banishing the second call.


