IP Library Patent Application 13313945
Patent Application
App. No. 13/313,945

SYSTEMS AND METHODS FOR PROVIDING SECURITY FOR SIP AND PBX COMMUNICATIONS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/313,945
Abstract

The present application is directed to systems and methods for providing security for session initiation protocol (SIP) services via a single device providing an SIP proxy and video conference bridge. A device deployed as a proxy between a first client and a second client receives an SIP request of the first client to establish a real-time communication with the second client. The device determines, based on application of a policy to the first SIP request, to deny the SIP request. The device receives a real-time communication protocol request, originated by the first client, to establish a real-time communication channel with the second client. The device identifies that the first client originating the real-time communication protocol request corresponds to the first client of the denied SIP request, and discards the real-time communication protocol request, at a transport layer of a network stack of the device, responsive to the identification.

Claims (33)

1 . A method for providing security for session initiation protocol (SIP) services via an Ethernet device providing an SIP proxy and video conference bridge, the method comprising:

receiving, by a device installed as an Ethernet adapter on a computing device and deployed as a proxy between a first client and a second client, a first session initiation protocol (SIP) request of the first client to establish a real-time communication with the second client;

determining, by a firewall of the device based on application of a policy to the first SIP request, to deny the first SIP request;

receiving, by the device, a real-time communication protocol request, originated by the first client, to establish a real-time communication channel with the second client;

identifying, by the firewall, that the first client originating the real-time communication protocol request corresponds to the first client of the denied first SIP request; and

discarding the real-time communication protocol request, by the firewall at or below a transport layer of a network stack of the computing device, responsive to the identification.

2 . The method of claim 1 , wherein determining to deny the first SIP request comprises determining, based on applying an access control list policy to a source IP address of the first SIP request, to deny the first SIP request.

3 . The method of claim 1 , wherein determining to deny the first SIP request comprises determining the first SIP request comprises an invalid session request.

4 . The method of claim 1 , wherein determining to deny the first SIP request comprises determining that a user of the first client has not been authenticated or lacks authorization.

5 . The method of claim 1 , wherein determining to deny the first SIP request comprises determining to deny the first SIP request, responsive to receiving a predetermined number of additional SIP requests from the first client in a predetermined period.

6 . The method of claim 1 , further comprising adding a source IP address of the first SIP request to a block list of an access control list, responsive to determining to deny the first SIP request.

7 . The method of claim 1 , wherein receiving a real-time communication protocol request to establish a real-time communication channel with the second client comprises receiving a real-time communication protocol request to initiate a video conference via a video conference bridge of the device with the second client.

8 . The method of claim 1 , wherein identifying that the first client originating the real-time communication protocol request corresponds to the first client of the denied first SIP request comprises determining that the source IP of the real-time communication protocol request corresponds to the source IP of the denied first SIP request.

9 . The method of claim 1 , wherein discarding the real-time communication protocol request comprises discarding the real-time communication protocol request prior to inspecting the real-time communication protocol request at a layer of the network stack above the transport layer.

10 . A system for providing security for session initiation protocol (SIP) services via an Ethernet device providing an SIP proxy and video conference bridge, the system comprising:

a device installed as an Ethernet adapter on a computing device and deployed as a proxy between a first client and a second client, the device comprising:

an Ethernet interface configured to:

receive a first session initiation protocol (SIP) request of the first client to establish a real-time communication with the second client, and

receive a real-time communication protocol request, originated by the first client, to establish a real-time communication channel with the second client; and

a firewall configured to:

determine, based on application of a policy to the first SIP request, to deny the first SIP request,

identify that the first client originating the real-time communication protocol request corresponds to the first client of the denied first SIP request, and

discard the real-time communication protocol request, at or below a transport layer of a network stack of the computing device, responsive to the identification.

11 . The system of claim 10 , wherein the firewall is configured to determine, based on applying an access control list policy to a source IP address of the first SIP request, to deny the first SIP request.

12 . The system of claim 10 , wherein the firewall is configured to determine the first SIP request comprises an invalid session request.

13 . The system of claim 10 , wherein the firewall is configured to determine that a user of the first client has not been authenticated or lacks authorization.

14 . The system of claim 10 , wherein the firewall is configured to determine to deny the first SIP request, responsive to receiving a predetermined number of additional SIP requests from the first client in a predetermined period.

15 . The system of claim 10 , wherein the firewall is configured to add a source IP address of the first SIP request to a block list of an access control list, responsive to determining to deny the first SIP request.

16 . The system of claim 10 , wherein the device further comprises a video conference bridge, and the Ethernet interface is configured to receive a real-time communication protocol request to initiate a video conference via the video conference bridge with the second client.

17 . The system of claim 10 , wherein the firewall is configured to determine that the source IP of the real-time communication protocol request corresponds to the source IP of the denied first SIP request.

18 . The system of claim 10 , wherein the firewall is configured to discard the real-time communication protocol request prior to inspecting the real-time communication protocol request at a layer of the network stack above the transport layer.

19 . The system of claim 10 , wherein the device comprises a SIP proxy and SIP registrar.

20 . The system of claim 10 , wherein the firewall is in communication with the SIP proxy and SIP registrar.

Assignments (3)
NUNC PRO TUNC ASSIGNMENT Recorded Nov 25, 2015
From: POSITRON TELECOMMUNICATIONS SYSTEMS INTELLECTUAL PROPERTY, LLC
To: POSITRON INTELLECTUAL PROPERTY, LLC.
Reel/Frame 037144/0688 →
NUNC PRO TUNC ASSIGNMENT Recorded Mar 16, 2015
From: CERINET USA, INC.
To: POSITRON TELECOMMUNICATIONS SYSTEMS INTELLECTUAL PROPERTY LLC.
Reel/Frame 035173/0397 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2011
From: WEISER, REGINALD; MCGRAVIE, RICHARD
To: POSITRON TELECOMMUNICATION SYSTEMS, INC.
Reel/Frame 027369/0820 →