IP Library Granted Patent US 7,684,317
Granted Patent B2
US 7,684,317 · App. 09/881,604 · Granted Mar 23, 2010

Protecting a network from unauthorized access

Assignee: Nortel Networks Limited
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,684,317
App. No.
09/881,604
Granted
Mar 23, 2010
Kind
B2
Abstract

A method and apparatus of protecting a first network from unauthorized access includes storing profile information for each call session, and determining if an unauthorized access of the first network is occurring based on the profile information. The profile information includes a predetermined threshold indicating a maximum acceptable rate of incoming data units from an external network to the first network. If the incoming data unit rate exceeds the predetermined threshold, then a security action is taken, such as generating an alarm or preventing further transport of data units from the external network to the first network.

Claims (35)

1. A method of dynamically protecting access to a first network, comprising:

receiving, in a system, a data unit containing a source address indicating a source of a data unit;

matching the source address with information stored in the system;

enabling entry of the data unit to the first network for communication to a destination device on the first network if the source address matches the information stored in the system and denying entry of the data unit to the first network if the source address does not match the information stored in the system,

wherein the destination device is separate from the system;

determining whether the data unit contains an identifier of a codec type that matches a stored codec type; and

indicating occurrence of an attack of the first network in response to determining that the identifier is of a codec type that does not match the stored codec type.

2. The method of claim 1 , wherein matching the source address with the information comprises matching the source address with one or more entries of a network address translation mapping table.

3. The method of claim 1 , wherein matching the source address comprises matching an Internet Protocol address.

4. A method of dynamically protecting access to a first network, comprising:

receiving, in a system, a data unit containing a source address indicating a source of the data unit;

matching, by an address filter in the system, the source address with information stored in the system;

enabling, by the address filter, entry of the data unit to the first network if the source address matches the information stored in the system and denying entry of the data unit to the first network if the source address does not match the information stored in the system; and

determining, by a protocol filter, if the data unit contains a payload according to a predetermined protocol, and denying, by the protocol filter, entry of the data unit if the data unit does not contain the payload according to the predetermined protocol,

wherein determining if the data unit contains a payload according to the predetermined protocol comprises determining if the data unit contains a payload according to a Real-Time Protocol or Real-Time Control Protocol.

5. A method of dynamically protecting access to a first network, comprising:

receiving, in a system, a data unit containing a source address indicating a source of a data unit;

matching the source address with information stored in the system;

enabling entry of the data unit to the first network if the source address matches the information stored in the system and denying entry of the data unit to the first network if the source address does not match the information stored in the system; and

storing profile information for a telephony call session, and determining if an unauthorized access of the first network is occurring based on the profile information,

wherein storing the profile information comprises storing a threshold representing a maximum acceptable rate of incoming data units from an external network to the first network.

6. The method of claim 5 , further comprising calculating a value for the threshold based on a frame size used in the call session.

7. The method of claim 5 , wherein storing the profile information further comprises storing a pattern expected in incoming data units.

8. The method of claim 7 , wherein storing the pattern comprises storing a codec type used in the call session.

9. The method of claim 5 , further comprising generating an alarm if the system detects a rate of incoming data units from the external network to the first network exceeding the threshold.

10. The method of claim 5 , further comprising denying further transport of incoming data units from the external network to the first network for the call session if the system detects a rate of incoming data units from the external network to the first network exceeding the threshold.

11. An article comprising at least one computer-readable storage medium containing instructions for protecting a first network, the instructions when executed causing a processor to:

determine if a rate of incoming data units from an external network to the first network exceeds a predetermined threshold;

perform a security action if the determined rate of incoming data units exceeds the predetermined threshold; and

determine if each incoming packet has a predetermined pattern,

wherein the instructions when executed cause the processor to determine if each incoming packet has the predetermined pattern by checking if each incoming packet has an indication of a predetermined codec type.

12. A system for use in communications between a first network and an external network, comprising:

a storage module to store a threshold value for a communications session, the threshold value representing an acceptable rate of incoming data units from the external network to the first network; and

a controller adapted to deny further entry of data units from the external network to the first network in the communications session in response to the controller detecting that the rate of incoming data units exceeds the threshold value,

the storage module to further store a codec type for the communications session, wherein the controller is adapted to deny entry of an incoming data unit if the incoming data unit does not contain an indication of the codec type.

Assignments (14)
RELEASE OF SECURITY INTEREST Recorded Jun 24, 2024
From: CITIZENS BANK, N.A.
To: RIBBON COMMUNICATIONS OPERATING COMPANY, INC. (F/K/A GENBAND US LLC AND SONUS NETWORKS, INC.)
Reel/Frame 067822/0433 →
TERMINATION AND RELEASE OF PATENT SECURITY AGREEMENT AT R/F 044978/0801 Recorded Dec 6, 2021
From: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
To: RIBBON COMMUNICATIONS OPERATING COMPANY, INC. (F/K/A GENBAND US LLC AND SONUS NETWORKS, INC.)
Reel/Frame 058949/0497 →
SECURITY INTEREST Recorded Mar 3, 2020
From: RIBBON COMMUNICATIONS OPERATING COMPANY, INC.
To: CITIZENS BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 052076/0905 →
SECURITY INTEREST Recorded Jan 2, 2018
From: GENBAND US LLC; SONUS NETWORKS, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 044978/0801 →
TERMINATION AND RELEASE OF PATENT SECURITY AGREEMENT Recorded Dec 29, 2017
From: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
To: GENBAND US LLC
Reel/Frame 044986/0303 →
CORRECTIVE ASSIGNMENT TO CORRECT PATENT NO. 6381239 PREVIOUSLY RECORDED AT REEL: 039269 FRAME: 0234. ASSIGNOR(S) HEREBY CONFIRMS THE PATENT SECURITY AGREEMENT. Recorded Jan 3, 2017
From: GENBAND US LLC
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 041422/0080 →
RELEASE AND REASSIGNMENT OF PATENTS Recorded Jul 7, 2016
From: COMERICA BANK, AS AGENT
To: GENBAND US LLC
Reel/Frame 039280/0467 →
PATENT SECURITY AGREEMENT Recorded Jul 6, 2016
From: GENBAND US LLC
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 039269/0234 →
RELEASE OF SECURITY INTEREST Recorded Jan 10, 2014
From: ONE EQUITY PARTNERS III, L.P., AS COLLATERAL AGENT
To: GENBAND US LLC
Reel/Frame 031968/0955 →
SECURITY AGREEMENT Recorded Nov 9, 2010
From: GENBAND US LLC
To: COMERICA BANK
Reel/Frame 025333/0054 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2010
From: NORTEL NETWORKS LIMITED
To: GENBAND US LLC
Reel/Frame 024879/0475 →
PATENT SECURITY AGREEMENT Recorded Jun 18, 2010
From: GENBAND US LLC
To: ONE EQUITY PARTNERS III, L.P., AS COLLATERAL AGENT
Reel/Frame 024555/0809 →
CHANGE OF NAME Recorded Jun 2, 2010
From: GENBAND INC.
To: GENBAND US LLC
Reel/Frame 024468/0507 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 14, 2001
From: MARCH, SEAN W.; SOLLEE, PATRICK N.; MCKNIGHT, DAVID W.
To: NORTEL NETWORK LIMITED
Reel/Frame 011919/0690 →
Continuity (1)
Related Publication 20030043740A1 · Mar 6, 2003