VoIP DoS Mitigation via SIP Call Initiation Rate Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Voice over Internet Protocol (VoIP) networks face challenges in mitigating Denial-of-Service (DoS) attacks, particularly when large numbers of call setup requests overwhelm SIP protocol processors, leading to blocked communication sessions.

Innovation Solution

The implementation of a method and apparatus within VoIP networks to detect and mitigate DoS attacks by analyzing call initiation rates, using DoS headers and attack mitigation rules, and employing in-band and out-of-band signaling protocols to identify and block malicious communication session requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If large numbers of call setup requests are processed by SIP protocol processors, then communication session establishment capability is improved, but processor utilization becomes excessively high leading to blocked sessions

Engineering Contradiction:
Improvecall setup request processing capacityVSAvoidcommunication session establishment reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary analysis of call initiation rates and identifies potential DoS attacks before they overwhelm the SIP protocol processors. By detecting suspicious patterns in advance and blocking malicious requests proactively, the system prevents processor overload while maintaining normal call setup operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary DoS attack detector and border element that sits between the external network and SIP protocol processors. This intermediary analyzes incoming call setup requests, identifies malicious traffic patterns, and blocks suspicious requests before they reach the core processing system, thereby protecting processor reliability while maintaining productivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If call initiation rate analysis is performed to detect DoS attacks, then attack detection capability is improved, but network signaling overhead increases

Engineering Contradiction:
ImproveDoS attack detection accuracyVSAvoidnetwork signaling messages
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system extracts only the essential information needed for DoS detection (call initiation rates and endpoint identifiers) from incoming signaling messages. By analyzing only these critical parameters rather than processing complete message content, the system achieves accurate attack detection while minimizing additional signaling overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The border element utilizes information already present in the incoming signaling messages (such as From headers and call initiation timing) to perform self-service DoS detection. This approach eliminates the need for additional probe messages or external monitoring infrastructure, reducing signaling overhead while maintaining detection precision.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8375453B2Methods and apparatus to mitigate a denial-of-service attack in a voice over internet protocol network
Publication Date: 2013.02.12 AT&T INTELLECTUAL PROPERTY I L P
  • US8375453B2 patent drawing
  • US8375453B2 patent drawing
  • US8375453B2 patent drawing

AI summary

Methods and apparatus to mitigate a Denial-of-Service (DoS) attack in a voice over Internet protocol (VoIP) network are disclosed. An example method comprises receiving a communication session initiation message from a communication session endpoint, determining whether the communication session endpoint is associated with a probable DoS attack, and sending to the communication session endpoint a communication session initiation response message comprising a DoS header when the communication session endpoint is associated with the probable DoS attack.