UC Threat Detection With Dynamic Automated Response Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unified Communications (UC) systems face challenges in monitoring and managing complex call flows and anomalies due to the rapid increase in network nodes and interacting protocols, with existing Security Information and Event Management (SIEM) frameworks losing effectiveness at higher levels, and there is a need for a system that can monitor, detect, and mitigate these issues efficiently and effectively.

Innovation Solution

A system and method for dynamically detecting and mitigating threats and anomalies in communications systems, including automated and operator-controlled responses to threats and anomalies, with a combination of automated and operator-controlled responses to threats and anomalies, with a combination of automated and operator-controlled responses to threats and anomalies, with a combination of automated and operator-controlled responses to threats and anomalies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If automated threat response is implemented, then threat response speed is improved, but operator control and customization are reduced

Engineering Contradiction:
Improvethreat response speedVSAvoidoperator control
Core Design Contradiction:
SpeedVSEase of operation

Solution Approach 1:

The system dynamically adjusts the degree of automation based on threat severity and operator preferences. For high-severity threats, automated response is enabled; for lower-severity threats, operator approval is required. This dynamic control mechanism allows the system to maintain speed for critical issues while preserving operator control for nuanced decisions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback loops where operators can review and correct automated actions, and where the system learns from operator interventions to refine future automated responses. This feedback mechanism ensures that automation operates within operator intent while maintaining rapid response capability.

Inventive Principle:
Principle #23Feedback

2Reliability

If SIEM frameworks are applied at higher protocol levels, then UC monitoring capability is improved, but system complexity increases

Engineering Contradiction:
ImproveUC monitoring capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The monitoring system is segmented into separate functional modules: data collection, threat detection, policy enforcement, and operator interface. Each module operates independently and can be configured separately, reducing overall system complexity while maintaining comprehensive UC monitoring capability at higher protocol levels.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary layer that translates complex UC protocol interactions into simplified threat models and policies. This intermediary abstraction layer enables monitoring at UC level without requiring operators to directly manage protocol complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If manual operator response is required for all threats, then operator customization is improved, but response time increases

Engineering Contradiction:
Improveoperator customizationVSAvoidresponse time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary automated actions for routine threat responses based on pre-configured policies. Operators only intervene when customization is needed, reducing response time for standard cases while preserving operator customization capability for exceptional situations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes the operational parameters dynamically based on threat characteristics. For high-volume routine threats, automated batch processing is enabled; for unique or high-value threats, individual operator review is triggered. This parameter adjustment optimizes both response time and customization based on actual conditions.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3821360B1Communications methods and apparatus for dynamic detection and/or mitigation of threats and/or anomalies
Publication Date: 2025.11.12 RIBBON COMMUNICATIONS OPERATING CO INC
  • EP3821360B1 patent drawingFigure 1
  • EP3821360B1 patent drawingFigure 2
  • EP3821360B1 patent drawingFigure 3

AI summary

The present invention relates to methods and apparatus for dynamically detecting and/or mitigating threats in communications systems. Exemplary methods and apparatus of the present invention allow for a combination of automated and operator controlled responses to threats. While an operator is provided an opportunity to provide input on how to respond to a threat, after one or more threats of a given type are identified, the system will automatically take corrective action without waiting for operator input and/or in the absence of operator input following notification of a threat.