VoIP Communication Screening Service for Real-Time Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current VoIP communication systems face challenges in effectively detecting and blocking scam and phishing attempts in real-time due to the sheer volume of communications, which complicates data aggregation and threat processing, making reliable implementation difficult.

Innovation Solution

A communication screening service is implemented in a datacenter to analyze metadata and content of VoIP communications, using techniques such as speech-to-text conversion and threat pattern comparison, to detect malicious intent and generate rejections to block undesirable communications, saving threat signatures for future identification and prompting gateway servers to disrupt the communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If real-time threat processing is implemented to detect scam and phishing attempts, then security reliability is improved, but the sheer volume of communications makes it difficult or impossible to process

Engineering Contradiction:
Improvethreat detection reliabilityVSAvoidcommunication processing capacity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments threat detection into multiple filtering planes (media protection and filtering plane, policy based filtering plane, signature based filtering plane, protocol anomaly detection and filtering plane, and behavioral learning based filtering plane). Each plane handles specific aspects of communication analysis, dividing the overwhelming task of real-time threat processing into manageable segments that can be processed efficiently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary filtering and analysis at multiple stages before full threat processing. Communications are screened through successive filtering planes that eliminate obvious threats early, reducing the volume of communications that require more intensive analysis. Trust scores are maintained and updated in advance to enable faster decision-making on subsequent communications from the same sources.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If multiple filtering planes are used to detect threats, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidfiltering system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The filtering system is divided into five distinct filtering planes, each responsible for specific detection tasks. This segmentation allows each plane to be optimized for its specific function while maintaining overall system manageability. Each plane can be independently configured, monitored, and maintained.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The multiple filtering planes work together as an integrated system where each plane contributes to overall threat detection. The system provides universal protection across different types of threats (spam, scams, phishing, protocol anomalies) through a unified multi-plane architecture that handles diverse communication types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If comprehensive communication analysis is performed to detect scam and phishing schemes, then security protection is improved, but processor load, memory usage, and network bandwidth increase

Engineering Contradiction:
Improvesecurity protection levelVSAvoidprocessor load and resource consumption
Core Design Contradiction:
Object-affected harmful factorsVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary filtering at multiple stages before comprehensive analysis. Obvious threats are identified and blocked by earlier filtering planes, reducing the number of communications that require intensive processor-intensive analysis. This staged approach conserves computational resources while maintaining high security protection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies different levels of analysis intensity based on communication characteristics. Not all communications receive the same level of comprehensive analysis - instead, the system applies appropriate filtering depth based on trust scores, communication patterns, and preliminary screening results, optimizing resource usage while maintaining security.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3443723B1Blocking undesirable communications in voice over internet protocol systems
Publication Date: 2020.12.02 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3443723B1 patent drawingFigure 1
  • EP3443723B1 patent drawingFigure 2
  • EP3443723B1 patent drawingFigure 3

AI summary

Blocking of undesirable voice over internet protocol (VOIP) communications is disclosed. A communication screening service initiates operations to block a threat posed by a VOIP communication upon receiving the communication from a gateway server. The communication may include an audio/video conversation and/or an audio/video conference. Next, metadata and content of the communication is analyzed to detect a threat, such as a scamming scheme and/or a phishing scheme, from a sender of the communication. A rejection of the communication is generated to disrupt the threat associated with the communication. The rejection is transmitted to the gateway server to prompt the gateway server to block the communication.