TDOS Attack Detection and Banishment in Telephony Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Telephony denial of service (TDOS) attacks deplete resources of mobile positioning centers, Voice over Internet Protocol positioning centers, emergency call management centers, and public safety answering points by exhausting pseudo automatic number identification (pANI) pools, leading to loss of caller location and competition for resources with real calls.

Innovation Solution

Implementing algorithms to detect TDOS attacks by identifying repeated calls from the same number exceeding a threshold, banishing calls using error codes, and interrogating callers to determine legitimate emergencies, thereby preventing resource exhaustion and maintaining system functionality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the pANI pool is used to assign telephone numbers to incoming calls, then calls can be routed and processed, but the pool can be exhausted by TDOS attacks, leading to loss of caller location and resource depletion

Engineering Contradiction:
Improvecall processing capacityVSAvoidpANI pool resources
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The system performs preliminary actions by detecting TDOS attack patterns (repeated calls from same number within time threshold) before the pANI pool is exhausted. Once an attack is detected, the system proactively bans the attacking telephone number, preventing further consumption of pANI resources and protecting the pool from depletion

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system converts the harmful TDOS attack traffic into a beneficial security feature by using the attack patterns themselves as detection criteria. The repeated call behavior that constitutes the attack is precisely what triggers the ban mechanism, transforming the harmful resource consumption into useful intelligence for identifying and blocking malicious sources

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

2Reliability

If repeated calls are allowed to maintain pool resources, then real calls can access pANI numbers, but TDOS attacks can deplete the pool rapidly, causing loss of location information

Engineering Contradiction:
Improvecaller location availabilityVSAvoidTDOS attack impact
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary anti-action by establishing a ban mechanism that prevents attacking telephone numbers from consuming pANI resources. By detecting the attack pattern early and banning the source number, the system counteracts the harmful effect before it can deplete the pool and cause location information loss

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system uses feedback from monitoring call patterns to dynamically adjust its response. By continuously tracking the number of calls from each telephone number within the threshold period, the system receives feedback on attack intensity and adjusts by banning numbers that exceed the threshold, thereby maintaining location availability

Inventive Principle:
Principle #23Feedback

3Reliability

If the system monitors and bans calls exceeding call thresholds, then TDOS attacks can be halted, but additional processing overhead is introduced for call interception and banishment

Engineering Contradiction:
Improvesystem protection against attacksVSAvoidcall processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies partial action by monitoring only the essential parameters needed for attack detection (telephone number, call count, time threshold) rather than analyzing all call details. This selective monitoring provides sufficient protection against TDOS attacks while minimizing the processing overhead and complexity

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250211673A1Detection and methods for handling a TDOS attack
Publication Date: 2025.06.26 INTRADO LIFE & SAFETY INC
  • US20250211673A1 patent drawing
  • US20250211673A1 patent drawing
  • US20250211673A1 patent drawing

AI summary

A method includes receiving a first call; identifying a first telephone number associated with the first call; receiving a second call; identifying a second telephone number associated with the second call; determining to banish the second call, at least in part based the second telephone number and a determination that a number of calls associated with the first telephone number exceeds a predetermined threshold; and banishing the second call.