VoIP Attack Detection via Dynamic Audio CAPTCHA

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

VoIP networks face challenges in detecting and mitigating network attacks, particularly Distributed Denial of Service (DDoS) attacks, which existing solutions fail to address effectively in near real-time, compromising network security.

Innovation Solution

A comprehensive automated attack-avoidance solution that includes call monitoring, diversion of suspicious calls, and the application of audio challenge-response tests, utilizing a guardian module to administer CAPTCHA tests by generating and configuring scripts with altered sound files based on complexity levels to differentiate human from automated calls.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If automated call monitoring and analysis is implemented to detect attacks in real-time, then network security and attack detection capability are improved, but system complexity and processing requirements increase

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides attack detection into multiple specialized modules: anomaly detection module for statistical analysis, pattern recognition module for signature matching, and CAPTCHA module for challenge-response verification. Each module handles specific aspects of security monitoring, reducing overall system complexity while maintaining comprehensive protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a policy change engine as an intermediary layer between detection modules and mitigation actions. This engine translates detected anomalies into standardized policy changes, simplifying the coordination between multiple security components and reducing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If audio challenge-response tests with multiple complexity levels are administered to differentiate human from automated calls, then attack mitigation accuracy is improved, but processing time and computational resources increase

Engineering Contradiction:
Improveattack detection accuracyVSAvoidcall processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system dynamically adjusts CAPTCHA complexity levels based on detected anomaly severity and call patterns. For low-risk calls, simpler challenges are used; for high-risk calls, more complex multi-level challenges are administered. This dynamic adaptation maintains high detection accuracy while minimizing processing time for legitimate calls.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes multiple parameters of the audio challenge-response test including noise levels, playback speed, and question complexity based on the detected threat level. These parameter adjustments allow the system to optimize between accuracy and processing time by matching challenge difficulty to the suspected attack probability.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If suspicious calls are diverted for CAPTCHA verification, then malicious traffic blocking is improved, but legitimate call throughput and network efficiency decrease

Engineering Contradiction:
Improvemalicious traffic blockingVSAvoidcall throughput
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The system applies CAPTCHA verification selectively rather than universally - only to calls exhibiting specific anomaly patterns. The anomaly detection module identifies suspicious characteristics and triggers verification only for those calls, allowing legitimate traffic to pass through without interruption and maintaining high network throughput while still blocking malicious traffic effectively.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9692774B2Real-time network attack detection and mitigation infrastructure
Publication Date: 2017.06.27 RIBBON COMMUNICATIONS OPERATING CO INC
  • US9692774B2 patent drawing
  • US9692774B2 patent drawing
  • US9692774B2 patent drawing

AI summary

The invention features systems and methods for detecting and mitigating network attacks in a Voice-Over-IP (VoIP) network. A server is configured to receive information related to a mitigation action for a call. The information can include a complexity level for administering an audio challenge-response test to the call and an identification of the call. The server also generates i) a routing label based on the identification of the call, and ii) a script defining a plurality of variables that store identifications of a plurality of altered sound files for the audio challenge-response test. Each altered sound file is randomly selected by the server subject to one or more constraints associated with the complexity level. The server is further configured to transmit the script to a guardian module and the routing label to a gateway.