IP Library Granted Patent US 8,582,567
Granted Patent B2
US 8,582,567 · App. 11/502,244 · Granted Nov 12, 2013

System and method for providing network level and nodal level vulnerability protection in VoIP networks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,582,567
App. No.
11/502,244
Granted
Nov 12, 2013
Kind
B2
Abstract

The present invention provides a system, method and apparatus for providing network level and nodal level vulnerability protection in VoIP networks by receiving a communication, filtering the received communication using three or more stages selected from the group comprising a media protection and filtering plane, a policy based filtering plane, a signature based filtering plane, a protocol anomaly detection and filtering plane and a behavioral learning based filtering plane, and either allowing or denying the received communication based the filtering step. The stages are applicable to one or more protocols including SIP, IMS, UMA, H.248, H.323, RTP, CSTA/XML or a combination thereof. In addition, the stages can be implemented within a single device or are distributed across a network (e.g., SIP network, a UMA network, an IMS network or a combination thereof).

Claims (52)

1. A method for protecting one or more communications devices comprising the steps of:

receiving a communication at a first processor communicably coupled to the one or more communications devices via a network;

filtering the received communication using the first processor wherein the first processor executes three or more stages selected from the group comprising a media protection and filtering plane, a policy-based filtering plane, a signature-based filtering plane, a protocol anomaly detection and filtering plane, and a behavioral learning-based filtering plane;

either allowing or blocking the received communication using the first processor based on the selected stages;

wherein the media protection and filtering plane blocks the received communication whenever the communication falls outside one or more communication media-based parameters comprising signaling media integrity, media validation and anomaly detection;

wherein the policy-based filtering plane blocks the received communication whenever one or more user defined media and time policies are violated;

wherein the signature-based filtering plane blocks the received communication whenever the received communication matches one or more known attack signatures;

wherein the protocol anomaly detection and filtering plane blocks the received communication whenever the received communication violates one or more protocol policies comprising a protocol misuse policy, a protocol message scrubbing policy, and a device specific policy;

wherein the behavioral learning-based filtering plane uses a probability analysis to detect anomalies based on one or more learned parameters and resolve probable false alarms into a correct decision to either block or allow the received communication; further comprising:

one or more media subsystems having a second processor communicably and securely connected to one or more signaling subsystems and deployed as a security and monitoring interface between the network and the one or more communications devices; and

an element management system (EMS) subsystem having a third processor communicably and securely connected to the one or more signaling subsystems; or

a verify subsystem having a fourth processor communicably and securely connected to the one or more signaling subsystems.

2. The method as recited in claim 1 , wherein the stages further comprise an authentication plane and an encryption plane.

3. The method as recited in claim 1 , wherein the stages are applicable to one or more protocols including SIP, IMS, UMA, H.248, H.323, RTP, CSTA/XML or a combination thereof.

4. The method as recited in claim 1 , wherein the method is implemented in one or more subsystems including the one or more signaling subsystems, the one or more media subsystems, an intelligence subsystem, the EMS subsystem, the verify subsystem or a combination thereof.

5. The method as recited in claim 1 , wherein the stages are implemented within a single device or are distributed across the network.

6. The method as recited in claim 1 , wherein the method is implemented within a SIP network, a UMA network, an IMS network or a combination thereof.

7. The method as recited in claim 1 , wherein the denied communication comprises a DoS attack, blended attack, VoIP SPAM or a combination thereof.

8. A non-transitory computer readable medium for protecting one or more communications devices comprising program instructions when executed by a first processor causes the first processor to perform the steps of:

receiving a communication at the first processor communicably coupled to the one or more communications devices via a network;

filtering the received communication using three or more stages selected from the group comprising a media protection and filtering plane, a policy-based filtering plane, a signature-based filtering plane, a protocol anomaly detection and filtering plane and a behavioral learning-based filtering plane;

either allowing or blocking the received communication based on the selected stages;

wherein the media protection and filtering plane blocks the received communication whenever the received communication falls outside one or more communication media based parameters comprising signaling media integrity, media validation and anomaly detection;

wherein the policy-based filtering plane blocks the communication whenever one or more user defined media and time policies are violated;

wherein the signature-based filtering plane blocks the received communication whenever the received communication matches one or more known attack signatures;

wherein the protocol anomaly detection and filtering plane blocks the received communication whenever the received communication violates one or more protocol policies comprising a protocol misuse policy, a protocol message scrubbing policy and a device specific policy;

wherein the behavioral learning-based filtering plane uses a probability analysis to detect anomalies based on one or more learned parameters and resolve probable false alarms into a correct decision to either block or allow the received communication; further comprising:

one or more media subsystems having a second processor communicably and securely connected to one or more signaling subsystems and deployed as a security and monitoring interface between the network and the one or more communications devices; and

an element management system (EMS) subsystem having a third processor communicably and securely connected to the one or more signaling subsystems; or

a verify subsystem having a fourth processor communicably and securely connected to the one or more signaling subsystems.

9. The computer readable medium as recited in claim 8 , wherein the stages further comprise an authentication plane and an encryption plane.

10. The computer readable medium as recited in claim 8 , wherein the stages are applicable to one or more protocols including SIP, IMS, UMA, H.248, H.323, RTP, CSTA/XML or a combination thereof.

11. The computer readable medium as recited in claim 8 , wherein the program instructions are executed by one or more processors within one or more subsystems including the one or more signaling subsystems, the one or more media subsystems, an intelligence subsystem, the EMS subsystem, the verify subsystem or a combination thereof.

12. The computer readable medium as recited in claim 8 , wherein the stages are implemented within a single device or are distributed across the network.

13. A system for protecting one or more communications devices comprising:

a network communicably coupled to the one or more communications devices;

one or more signaling subsystems having a first processor deployed as a security and monitoring gateway between the one or more communications devices and the network;

an intelligence subsystem having a second processor communicably and securely connected to the one or more signaling subsystems;

wherein the first processor of the one or more signaling subsystems receives a communication, filters the received communication using three or more stages selected from the group comprising a media protection and filtering plane, a policy-based filtering plane, a signature-based filtering plane, a protocol anomaly detection and filtering plane and a behavioral learning-based filtering plane, and either allows or denies the received communication based the selected stages;

wherein the media protection and filtering plane blocks the received communication whenever the received communication falls outside one or more communication media based parameters comprising signaling media integrity, media validation and anomaly detection;

wherein the policy-based filtering plane blocks the received communication whenever one or more user defined media and time policies are violated;

wherein the signature-based filtering plane blocks the received communication whenever the received communication matches one or more known attack signatures;

wherein the protocol anomaly detection and filtering plane blocks the received communication whenever the received communication violates one or more protocol policies comprising a protocol misuse policy, a protocol message scrubbing policy and a device specific policy;

wherein the behavioral learning-based filtering plane uses a probability analysis to detect anomalies based on one or more learned parameters and resolve probable false alarms into a correct decision to either block or allow the received communication; further comprising:

one or more media subsystems having a third processor communicably and securely connected to the one or more signaling subsystems and deployed as a security and monitoring interface between the network and the one or more communications devices; and

an element management system (EMS) subsystem having a fourth processor communicably and securely connected to the one or more signaling subsystems; or

a verify subsystem having a fifth processor communicably and securely connected to the one or more signaling subsystems.

14. The system as recited in claim 13 , wherein the stages further comprise an authentication plane and an encryption plane.

15. The system as recited in claim 13 , wherein the stages are applicable to one or more protocols including SIP, IMS, UMA, H.248, H.323, RTP, CSTA/XML or a combination thereof.

16. The system as recited in claim 13 , wherein the stages are implemented within a single device or are distributed across the network.

17. The system as recited in claim 13 , wherein the system is implemented within a SIP network, a UMA network, an IMS network or a combination thereof.

18. The system as recited in claim 13 , wherein the denied communication comprises a DoS attack, blended attack, VoIP SPAM or a combination thereof.

Assignments (19)
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
MERGER Recorded Oct 28, 2011
From: SIPERA SYSTEMS, INC.
To: AVAYA INC.
Reel/Frame 027138/0920 →
RELEASE Recorded Oct 24, 2011
From: SILICON VALLEY BANK
To: SIPERA SYSTEMS, INC.
Reel/Frame 027120/0119 →
RELEASE OF SECURITY INTEREST Recorded Mar 4, 2011
From: COMERICA BANK
To: SIPERA SYSTEMS, INC.
Reel/Frame 025901/0892 →
SECURITY AGREEMENT Recorded Jan 25, 2011
From: SIPERA SYSTEMS, INC.
To: SILICON VALLEY BANK
Reel/Frame 025694/0699 →
SECURITY AGREEMENT Recorded May 21, 2008
From: SIPERA SYSTEMS, INC.
To: COMERICA BANK
Reel/Frame 020979/0211 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2006
From: KURAPATI, SRIKRISHNA; JOGLEKAR, SACHIN PURUSHOTTAM; IYENGAR PRASANNA, VENKATESAN; TYAGI, SATYAM; THODIME, GURU; KHANDELWAL, PRAVIN; MANCHENELLA, CHANDRASEKHAR; SINGH, MUKESH KUMAR; THODIME, RAGHAVENDRA VENKATA
To: SIPERA SYSTEMS, INC.
Reel/Frame 018222/0887 →