VoIP DoS Protection via DPI ACL Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing advanced voice services in wireless communications networks face limitations in providing superior user experiences and are vulnerable to voice-over-IP (VoIP) denial-of-service (DoS) attacks, which disrupt system functionality.

Innovation Solution

A system and method that includes servers interfacing with wireless communications networks to manage advanced voice services, such as Push-to-Talk-over-Cellular (PoC) calls, and implements a Deep Packet Inspection/Access List Controller (DPI/ACL) function to restrict traffic from unauthorized sources, identify and blacklist malicious activity, and whitelist trusted users, thereby protecting against DoS attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If advanced voice services are provided over IP networks, then service versatility and user access are improved, but vulnerability to DoS attacks increases

Engineering Contradiction:
Improveservice accessVSAvoidDoS attack vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

An intermediary security system is introduced between the IP network and the advanced voice services. This intermediary performs deep packet inspection, maintains whitelist/blacklist of authorized sources, and filters malicious traffic before it reaches the service servers, thereby enabling service access while blocking DoS attacks

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security system performs preliminary actions by pre-establishing whitelist and blacklist of authorized and malicious IP addresses before service delivery. The deep packet inspection mechanism is activated in advance to identify and block malicious traffic patterns before they can disrupt service operations

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traffic filtering and inspection mechanisms are implemented, then system security is improved, but network processing complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoidnetwork processing
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security function is segmented into modular components: deep packet inspection module, whitelist/blacklist management module, and traffic filtering module. This segmentation allows each component to handle specific tasks independently, improving security while making the complex processing more manageable and maintainable

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10116691B2VoIP denial-of-service protection mechanisms from attack
Publication Date: 2018.10.30 KODIAK NETWORKS INC
  • US10116691B2 patent drawing
  • US10116691B2 patent drawing
  • US10116691B2 patent drawing

AI summary

A system and method for providing advanced voice services in a wireless communications network. The system also interfaces to an Internet Protocol (IP) network to perform the advanced voice services for mobile units in the IP network and includes a protection mechanism against Voice-over-IP (VoiP) Denial-of-Service (DoS) attacks utilizing Advanced Group Services (AGS).