IP Library Granted Patent US 7,940,654
Granted Patent B2
US 7,940,654 · App. 11/592,775 · Granted May 10, 2011

Protecting a network from unauthorized access

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,940,654
App. No.
11/592,775
Granted
May 10, 2011
Kind
B2
Abstract

A method and apparatus of protecting a first network from unauthorized access includes storing profile information for each call session, and determining if an unauthorized access of the first network is occurring based on the profile information. The profile information includes a predetermined threshold indicating a maximum acceptable rate of incoming data units from an external network to the first network. If the incoming data unit rate exceeds the predetermined threshold, then a security action is taken, such as generating an alarm or preventing further transport of data units from the external network to the first network.

Claims (30)

1. A node for use in communications between a first network and an external network, comprising:

a storage module to store a threshold value for a communications session, the threshold value representing an acceptable rate of incoming data units from the external network to the first network; and

a controller to deny further entry of data units from the external network to the first network in the communications session and to generate a report of an attack from the external network in response to the controller detecting that the rate of incoming data units exceeds the threshold value,

the storage module to further store address information, wherein the controller is to compare a source address of a particular incoming data unit with the address information stored in the system and to deny further entry of the particular incoming data unit if the source address does not match the address information stored in the system.

2. The node of claim 1 , wherein the address information comprises a network address translation table.

3. The node of claim 2 , wherein the network address translation table comprises a network address and port translation table.

4. The node of claim 1 , wherein the controller is to further check if the particular incoming data unit contains a Real-Time Protocol or Real-Time Control Protocol payload, and to deny further entry of the particular incoming data unit if the incoming data unit does not contain a Real-Time Protocol or Real-Time Control Protocol payload.

5. A method of protecting a first network, comprising

determining if a rate of incoming data units from an external network to the first network exceeds a predetermined threshold in a given call session;

performing a security action if the determined rate of incoming data units exceeds the predetermined threshold, wherein performing the security action comprises generating a report that an attack is occurring; and

storing plural thresholds for corresponding plural call sessions, wherein the predetermined threshold is one of the plural thresholds.

6. The method of claim 5 , wherein the determining, performing, and storing are performed by a node, the method further comprising:

storing, by the node, a network address translation table;

determining, by the node, whether a source address of a particular incoming data unit matches an entry of the network address translation table; and

in response to determining that the source address does not match an entry of the network address translation table, the node denying entry of the particular incoming data unit to the first network.

7. The method of claim 5 , wherein the determining, performing, and storing are performed by a node, the method further comprising:

determining, by the node, a type of payload of a particular incoming data unit; and

in response to determining that the payload is not one of a Real-Time Protocol payload and a Real-Time Control Protocol payload, the node denying entry of the particular incoming data unit.

8. An article comprising at least one non-transitory machine-readable storage medium containing instructions for protecting a first network, the instructions when executed causing a node to:

determine if a rate of incoming data units from an external network to the first network exceeds a predetermined threshold in a given call session;

perform a security action if the determined rate of incoming data units exceeds the predetermined threshold; and

calculate the predetermined threshold based at least in part on a frame size used in the call session.

9. The article of claim 8 , wherein performing the security action comprises generating a report that an attack is occurring.

10. The article of claim 8 , wherein the instructions when executed cause the node to further:

store a network address translation table;

determine whether a source address of a particular incoming data unit matches an entry of the network address translation table; and

in response to determining that the source address does not match an entry of the network address translation table, deny entry of the particular incoming data unit to the first network.

11. The article of claim 8 , wherein the instructions when executed cause the node to further:

determine a type of payload of a particular incoming data unit; and

in response to determining that the payload is not one of a Real-Time Protocol payload and a Real-Time Control Protocol payload, deny entry of the particular incoming data unit.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Jun 24, 2024
From: CITIZENS BANK, N.A.
To: RIBBON COMMUNICATIONS OPERATING COMPANY, INC. (F/K/A GENBAND US LLC AND SONUS NETWORKS, INC.)
Reel/Frame 067822/0433 →
TERMINATION AND RELEASE OF PATENT SECURITY AGREEMENT AT R/F 044978/0801 Recorded Dec 6, 2021
From: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
To: RIBBON COMMUNICATIONS OPERATING COMPANY, INC. (F/K/A GENBAND US LLC AND SONUS NETWORKS, INC.)
Reel/Frame 058949/0497 →
SECURITY INTEREST Recorded Mar 3, 2020
From: RIBBON COMMUNICATIONS OPERATING COMPANY, INC.
To: CITIZENS BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 052076/0905 →
SECURITY INTEREST Recorded Jan 2, 2018
From: GENBAND US LLC; SONUS NETWORKS, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 044978/0801 →
TERMINATION AND RELEASE OF PATENT SECURITY AGREEMENT Recorded Dec 29, 2017
From: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
To: GENBAND US LLC
Reel/Frame 044986/0303 →
CORRECTIVE ASSIGNMENT TO CORRECT PATENT NO. 6381239 PREVIOUSLY RECORDED AT REEL: 039269 FRAME: 0234. ASSIGNOR(S) HEREBY CONFIRMS THE PATENT SECURITY AGREEMENT. Recorded Jan 3, 2017
From: GENBAND US LLC
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 041422/0080 →
RELEASE AND REASSIGNMENT OF PATENTS Recorded Jul 7, 2016
From: COMERICA BANK, AS AGENT
To: GENBAND US LLC
Reel/Frame 039280/0467 →
PATENT SECURITY AGREEMENT Recorded Jul 6, 2016
From: GENBAND US LLC
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 039269/0234 →
RELEASE OF SECURITY INTEREST Recorded Jan 10, 2014
From: ONE EQUITY PARTNERS III, L.P., AS COLLATERAL AGENT
To: GENBAND US LLC
Reel/Frame 031968/0955 →
SECURITY AGREEMENT Recorded Nov 9, 2010
From: GENBAND US LLC
To: COMERICA BANK
Reel/Frame 025333/0054 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2010
From: NORTEL NETWORKS LIMITED
To: GENBAND US LLC
Reel/Frame 024879/0475 →
PATENT SECURITY AGREEMENT Recorded Jun 18, 2010
From: GENBAND US LLC
To: ONE EQUITY PARTNERS III, L.P., AS COLLATERAL AGENT
Reel/Frame 024555/0809 →
CHANGE OF NAME Recorded Jun 2, 2010
From: GENBAND INC.
To: GENBAND US LLC
Reel/Frame 024468/0507 →