Behavioral Learning for UC Security and QoS

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unified Communication (UC) networks face challenges in providing high-quality, reliable, and secure voice-over-IP (VoIP) services due to security vulnerabilities, real-time requirements, and the convergence of PSTN and IP-telephony networks, which existing security solutions fail to adequately address.

Innovation Solution

A behavioral learning system that learns and abstracts positive flow behaviors of UC applications and endpoints, classifying messages into whitelists, blacklists, and graylists to allow, deny, quarantine, or redirect them based on analysis, ensuring real-time security and reliability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security solutions (encryption and deep-packet inspection) are employed to improve security, then security protection is enhanced, but additional time delays and jitters are introduced to VoIP/UC packet streams, impacting QoS

Engineering Contradiction:
Improvesecurity protectionVSAvoidtime delay and jitter
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary learning of normal VoIP/UC communication patterns during an initial phase, building a behavioral model that captures legitimate message flows, timing patterns, and protocol sequences. This pre-established model enables real-time security decisions without requiring complex analysis during actual communication, thus avoiding time delays and jitter in the packet stream

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors actual VoIP/UC traffic and compares it against the learned behavioral model, providing real-time feedback to detect deviations that indicate security threats. This feedback mechanism enables dynamic adaptation while maintaining low latency, as the system only intervenes when anomalies are detected rather than analyzing every packet in real-time

Inventive Principle:
Principle #23Feedback

2Reliability

If human intervention is used to respond to security attacks in data communication, then appropriate mitigation solutions are provided, but significant time delays occur which are unacceptable for real-time VoIP/UC communications

Engineering Contradiction:
Improvemitigation effectivenessVSAvoidresponse time delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements automated security response mechanisms that operate without human intervention. When the behavioral learning model detects anomalies consistent with attack patterns, the system automatically triggers mitigation actions such as blocking suspicious traffic, isolating affected endpoints, or alerting security personnel. This self-service capability ensures real-time response to threats while maintaining system reliability

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces the mechanical process of human analysis and decision-making with an automated behavioral learning engine that processes VoIP/UC traffic patterns. This substitution enables instantaneous detection and response to security threats by comparing actual traffic against learned normal behavior patterns, eliminating the time delays inherent in human intervention while maintaining effective mitigation

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If retransmission is used to handle lost data packets, then data integrity is maintained, but time delays occur that make callers repeat voice messages or reinvoke UC services, which is unacceptable

Engineering Contradiction:
Improvedata integrityVSAvoidretransmission delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary analysis of packet flows to identify and correct transmission errors before they result in lost data. By detecting anomalies in the behavioral patterns of packet sequences, the system can proactively mitigate issues that would otherwise require retransmission, maintaining data integrity while avoiding the time delays associated with retransmission protocols

Inventive Principle:
Principle #10Preliminary action

4Reliability

If existing security solutions are applied to VoIP/UC networks, then some security protection is provided, but they are not well suited to counterattack threats from converged PSTN and IP-telephony networks

Engineering Contradiction:
Improvesecurity protectionVSAvoidthreat coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system implements a universal behavioral learning model that captures the essential patterns of legitimate VoIP/UC communication across multiple protocols and network architectures. This model is designed to recognize normal behavior in both PSTN and IP-telephony networks, enabling the system to detect anomalies and threats from either network type without requiring separate security mechanisms for each protocol or network architecture

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8730946B2System and method to precisely learn and abstract the positive flow behavior of a unified communication (UC) application and endpoints
Publication Date: 2014.05.20 REDSHIFT INTERNETWORKING INC
  • US8730946B2 patent drawing
  • US8730946B2 patent drawing
  • US8730946B2 patent drawing

AI summary

A system and method to precisely learn and enforce security rules for Unified Communication (UC) applications and endpoints is disclosed. According to one embodiment, a behavioral learning system learns and abstracts positive flow behaviors of UC applications and endpoints. The properties of previously received messages from the endpoints and learned behaviors of the plurality of endpoints are stored in a database. A message from a endpoint is received by a message scanner and correlated with the AOR records in the database. The message is classified into one of a whitelist, a blacklist, and a graylist based on the results of analysis by the analysis engine. The whitelist contains the AOR records that are legitimate, the blacklist contains the AOR records that are a potential attack, and the graylist contains the AOR records that belong to neither the whitelist nor the blacklist. Based on the analysis and inspection of the message in light of the learned behaviors, a decision is made to allow, deny, quarantine or redirect the message.