IP Library Granted Patent US 7,653,188
Granted Patent B2
US 7,653,188 · App. 11/243,753 · Granted Jan 26, 2010

Telephony extension attack detection, recording, and intelligent prevention

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,653,188
App. No.
11/243,753
Granted
Jan 26, 2010
Kind
B2
Abstract

A system and method are provided for detecting extension attacks made to a communication enterprise, and taking appropriate remedial action to prevent ongoing attacks and future attacks. One or more attributes of a suspect call are analyzed, and a risk is associated with each analyzed attribute. An overall risk or assessment is then made of the analyzed attributes, attack attributes are logged, and one or more remedial actions may be triggered as a result of the analyzed call attributes. The remedial actions may include recording the call, notifying an administrator of a suspect call, or isolating the communication enterprise from the attack by terminating the call or shutting down selected communication endpoints to prevent calls being made to those extensions. Rules may be applied to the analyzed attributes in order to trigger the appropriate remedial action. The call attributes analyzed may include call destination, call direction, call type, time of day of the call, call duration, whether a call source is spoofed, call volume from a particular call source, and hash values created for a suspect media stream.

Claims (80)

1. A method of protecting communication services of a communication enterprise, said method comprising the steps of:

detecting, by a processor, a perceived extension attack in the form of a call directed to one or more extensions within the communication enterprise, said detecting including analyzing at least one attribute of the call;

classifying, by a processor, a risk associated with the call based upon the analysis of the at least one attribute;

taking, by a processor, a remedial action to thwart the perceived attack according to the risk associated with the call: and

said detecting by a processor comprises (i) creating an algorithm, (ii) applying the algorithm to a first media stream of the call, (iii) generating a first media hash value reflective of the first media stream content, (iv) applying the algorithm to a second media stream of a subsequent call directed to the communications enterprise, (v) generating a second media hash value reflective of the second media stream, (vi) comparing the first and second hash values, and (vii) taking the remedial action if the first and second hash values fall within a pre-designated range.

2. A method, as claimed in claim 1 , further including the steps of:

recording the call; and

alerting an administrator of the communication enterprise of a type and risk associated with the call enabling the administrator to influence the remedial action taken.

3. A method, as claimed in claim 1 , wherein:

said detecting comprises detecting a spoofed call source by comparing a source ID attribute of the spoofed call to an actual call source ID wherein a look-up or reverse look-up is conducted to determine the actual call source.

4. A method, as claimed in claim 1 , wherein:

said detecting comprises analyzing call sequences sent from a call source to the enterprise, and taking the remedial action if the call sequences match a predetermined objectionable call sequence.

5. A method, as claimed in claim 1 , wherein:

said detecting comprises detecting calls sent to unadministered numbers in the enterprise, and taking the remedial action if the number of calls to the unadministered numbers reach an objectionable predetermined value.

6. A method, as claimed in claim 1 , wherein:

said detecting step comprises analyzing the time of day when calls are sent from a call source, and taking the remedial action if the number of calls received after normal hours of operation exceed a predetermined number of calls.

7. A method, as claimed in claim 1 , wherein:

said detecting comprises analyzing a call source, and determining whether the called source is fax, voice or modem.

8. A method, as claimed in claim 1 , wherein:

said detecting comprises determining whether a call is made from an extension within the enterprise.

9. A method, as claimed in claim 1 , wherein:

said detecting comprises detecting whether a plurality of calls from a call source have single or multiple durations.

10. A method, as claimed in claim 1 , wherein:

said detecting comprises detecting the number of calls received from a call source and determining whether the number of calls received comprises an objectionable number of calls.

11. A communication system, comprising:

a communication server interconnected to a communication network, said communication server receiving communications through the network from at least one attack source;

a first communication device having an address, and receiving communications from said network through said communication server; and

an extension attack prevention application associated with said communication server, wherein said application analyzes call attributes of a call, assigns a risk associated with the call, and proposes a remedial action to thwart a perceived attack when said assigned risk fulfills criteria for a predetermined remedial action, said extension attack prevention application comprising an algorithm applied to a first media stream of the call to generate a first media hash value, and applying the algorithm to a second media stream of a subsequent call to generate a second media hash value, and means for comparing the first and second hash values for taking a remedial action if the first and second hash values fall within a pre-designated range.

12. A system, as claimed in claim 11 , wherein:

said extension attack prevention application detects a spoofed call source by comparing a source of the spoofed call to an actual call source wherein a look-up or reverse lookup is conducted to determine the actual call source.

13. A system, as claimed in claim 11 , wherein:

said extension attack prevention application includes at least one rule applied to attributes of the call analyzed for being an extension attack, said attributes including at least one of a call duration, a call direction, a call type, a time of day, a call destination, a spoofed call source, and a number of calls received from a call source of the call, said rule being associated with determining whether to take the remedial action.

14. A system, as claimed in claim 11 , wherein:

said extension attack prevention application assesses an overall risk associated with the call, said assessment comprises an analysis of a plurality of attributes of the call, said attributes including at least one of a media hash value, a call duration, a call direction, a call type, a time of day, a call destination, a spoofed call source, and a number of calls received from a call source of the call.

15. A system, as claimed in claim 14 , wherein:

said assessment includes a computation applied to at least one of said call attributes, and assigning a risk associated with at least one analyzed call attribute.

16. A system, as claimed in claim 11 , wherein:

said extension attack prevention application notifies an administrator of the communication system of the perceived attack and an assigned risk associated with the attack thereby enabling the administrator to intervene the remedial action taken.

17. A system, as claimed in claim 11 , wherein:

said extension attack prevention application includes executable programming instructions incorporated within said communication server, at least one database associated with said programming instructions, wherein said programming instructions are modified over time to alter the assignment of risks associated with attacks based at least in part on historical analysis of previously occurring extension attacks.

18. A system, as claimed in claim 16 , wherein:

said application includes an interactive voice response application incorporated in said communication server wherein the administrator is provided multiple options in generating an appropriate remedial action by selecting a remedial action option.

19. An apparatus for protecting communication resources of a communication enterprise, said apparatus comprising:

a processor;

programming instructions executed by said processor, said programming instructions including an extension attack prevention application wherein said application detects attributes of a suspect call, logs the attributes, assigns a risk to each of a plurality of the attributes associated with the suspect call, and provides recommendations for remedial actions to be taken to thwart a perceived attack;

a processor readable memory associated with execution of the programming instructions, and for storage of data and said programming instructions;

at least one input device for manipulating said programming instructions, and for interfacing with outputs generated from said device in response to perceived attacks; and

wherein said attributes include a media hash value and a spoofed call source.

20. A system for protecting communication resources of a communication enterprise, said system comprising:

a communication server for interfacing with a communication network, said communication server receiving and routing incoming communications, and facilitating transmission of communications with respect to addressed communication devices;

means incorporated within said communication server for protecting the communication resources from extension attacks sent by one or more attack sources through the communication network, said means for protecting including:

(i) means for detecting an extension attack;

(ii) means for assigning a risk associated with the attack;

(iii) means for taking a remedial action based on the assigned risk to thwart the attack; and

(iv) said means for detecting comprises (i) creating an algorithm, (ii) applying the algorithm to a first media stream of the call, (iii) generating a first media hash value reflective of the first media stream content, (iv) applying the algorithm to a second media stream of a subsequent call directed to the communications enterprise, (v) generating a second media hash value reflective of the second media stream and (vi) comparing the first and second hash values.

21. A system, as claimed in claim 20 , wherein:

said means for detecting includes detecting a spoofed call source by comparing a source of the spoofed call to an actual call source, wherein a reverse lookup is conducted to determine the actual call source.

22. A system, as claimed in claim 20 , wherein:

said means for detecting comprises analyzing call sequences sent from a call source to the enterprise, and taking the remedial action if the call sequences match a predetermined objectionable call sequence.

23. A system, as claimed in claim 20 , wherein:

said means for detecting comprises detecting calls sent to unadministered numbers in the enterprise, and taking the remedial action if the number of calls to the unadministered numbers reach an objectionable predetermined value.

24. A system, as claimed in claim 20 , wherein:

said means for detecting comprises analyzing the time of day when calls are sent from a call source, and taking the remedial action if the number of calls received after normal hours of operation exceed a predetermined number of calls.

25. A system, as claimed in claim 20 , wherein:

said means for detecting comprises analyzing a call source, and determining whether the call source is fax, voice or modem.

26. A system, as claimed in claim 20 , wherein:

said means for detecting comprises determining whether a call is made from an extension within the enterprise.

27. A system, as claimed in claim 20 , wherein:

said means for detecting comprises detecting whether a plurality of calls from a call source have a single or multiple durations.

28. A system, as claimed in claim 20 , wherein:

said means for protecting includes executable programming instructions incorporated within said communication server at least when data base associated with said programming instructions, wherein said programming instructions are modified over time to alter the assignment of risks associated with attacks based at least in part on historical analysis of previously occurring extension attacks.

29. The apparatus as claimed in claim 19 , wherein:

said programming instructions:

(i) creates an algorithm,

(ii) applies the algorithm to a first media stream of the suspect call,

(iii) generates a first media hash value reflective of the first media stream content,

(iv) applies the algorithm to a second media stream of a subsequent suspect call directed to the communications enterprise,

(iv) generates a second media hash value reflective of the second media stream,

(v) compares the first and second hash values, and

(vi) causes implementation of a selected remedial action when the first and second hash values fall within a pre-designated range.

Assignments (28)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2024
From: AVAYA LLC
To: ARLINGTON TECHNOLOGIES, LLC
Reel/Frame 067022/0780 →
INTELLECTUAL PROPERTY RELEASE AND REASSIGNMENT Recorded Mar 25, 2024
From: CITIBANK, N.A.
To: AVAYA LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 066894/0117 →
INTELLECTUAL PROPERTY RELEASE AND REASSIGNMENT Recorded Mar 25, 2024
From: WILMINGTON SAVINGS FUND SOCIETY, FSB
To: AVAYA LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 066894/0227 →
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
BANKRUPTCY COURT ORDER RELEASING THE SECURITY INTEREST RECORDED AT REEL/FRAME 020156/0149 Recorded Jul 25, 2022
From: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
To: AVAYA, INC.; AVAYA TECHNOLOGY LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES
Reel/Frame 060953/0412 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
RELEASE OF SECURITY INTEREST Recorded Jan 9, 2018
From: CITICORP USA, INC.
To: AVAYA, INC.; SIERRA HOLDINGS CORP.; AVAYA TECHNOLOGY, LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.
Reel/Frame 045032/0213 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 025863/0535 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST, NA
To: AVAYA INC.
Reel/Frame 044892/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 030083/0639 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 045012/0666 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
SECURITY AGREEMENT Recorded Mar 13, 2013
From: AVAYA, INC.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., THE
Reel/Frame 030083/0639 →
SECURITY AGREEMENT Recorded Feb 22, 2011
From: AVAYA INC., A DELAWARE CORPORATION
To: BANK OF NEW YORK MELLON TRUST, NA, AS NOTES COLLATERAL AGENT, THE
Reel/Frame 025863/0535 →
CONVERSION FROM CORP TO LLC Recorded May 12, 2009
From: AVAYA TECHNOLOGY CORP.
To: AVAYA TECHNOLOGY LLC
Reel/Frame 022677/0550 →
REASSIGNMENT Recorded Jun 26, 2008
From: AVAYA TECHNOLOGY LLC; AVAYA LICENSING LLC
To: AVAYA INC
Reel/Frame 021156/0287 →
SECURITY AGREEMENT Recorded Nov 28, 2007
From: AVAYA, INC.; AVAYA TECHNOLOGY LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.
To: CITICORP USA, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 020166/0705 →
SECURITY AGREEMENT Recorded Nov 27, 2007
From: AVAYA, INC.; AVAYA TECHNOLOGY LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 020156/0149 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2005
From: AVAYA TECHNOLOGY CORP.
To: AVAYA TECHNOLOGY LLC
Reel/Frame 016787/0469 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 20, 2005
From: KLOBERDANS, MICHAEL JAMES; WALTON, JOHN MICHAEL
To: AVAYA TECHNOLOGY CORP.
Reel/Frame 016664/0469 →