IP Library Granted Patent US 9,819,745
Granted Patent B2
US 9,819,745 · App. 14/794,989 · Granted Nov 14, 2017

System and method for prevention of denial of service attacks for hosted network address translator

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,819,745
App. No.
14/794,989
Granted
Nov 14, 2017
Kind
B2
Abstract

To determine the correct media stream to latch onto, the system and method uses a hashing algorithm to uniquely identify a legitimate media stream. A first invite message is received at a Session Border Controller (SBC) to establish a communication session. For example a Session Initiation Protocol (SIP) INVITE is received. The first invite message comprises a first hash of a fingerprint. For example, the hash may be a hashed session key. A media message is received that contains the fingerprint to establish a media stream for the communication session. A second hash is created using the fingerprint in the media message. The first hash is compared to the second hash. In response to the first hash matching the second hash, a Network Address Translator (NAT) latches to an address and/or a port in the media message. Thus, the correct media stream is associated with the communication session.

Claims (34)

1. A method comprising:

receiving, by a processor, a first invite message to establish a first communication session, wherein the first invite message comprises a first hash of a first fingerprint;

receiving, by the processor, a media message, containing the first fingerprint, to establish a media stream for the communication session;

creating, by the processor, a second hash using the first fingerprint in the media message;

comparing, by the processor, the first hash to the second hash; and

in response to the first hash matching the second hash, latching to an address and/or a port in the media message.

2. The method of claim 1 , further comprising:

in response to the first hash not matching the second hash, not latching to the address or the port in the media message.

3. The method of claim, 1 wherein the first hash uses at a hashing algorithm that is one of the following: BLAKE-256, BLAKE-512, ECOH, GOST, HAS-160, HAVAL, JH, MD2, MD4, MD5, MD6, RadioGatun, RIPEMD, RIPEMD-128, RIPEND-160, RIPEMD-320, SHA-1, SHA-3 SHA-224, SHA-256, SHA-512, Skein, SipHash, Snefru, Spectral Hash, SWIFFT, Tiger, or Whirlpool.

4. The method of claim 1 , wherein the first communication session is one of a Session Initiation Protocol (SIP) communication session, an H.323 communication session, or a Web Real-Time Communication (WebRTC) communication session.

5. The method of claim 1 , wherein the first invite message is a first Session Initiation Protocol (SIP) INVITE message, wherein the media message is a Real-time Transport Protocol (RTP) or a Secure RTP (SRTP) message, and wherein the first communication session is a SIP communication session.

6. The method of claim 5 , wherein the first hash is sent in a SIP header in the first SIP INVITE.

7. The method of claim 5 , further comprising:

receiving a second SIP INVITE to establish a second SIP communication session, wherein the second SIP INVITE comprises a second hash of a second fingerprint, wherein the second fingerprint is different from the first fingerprint.

8. The method of claim 5 , wherein the first fingerprint is sent in a payload of the RTP or SRTP message.

9. The method of claim 5 , wherein the first hash is sent in a Session Description Protocol (SDP) <fmt>header in the first SIP INVITE message.

10. The method of claim 9 , wherein the SDP <fmt>header has an additional header that indicates a presence of the first hash.

11. A session border controller comprising:

a microprocessor; and

a computer readable medium, coupled with the microprocessor and comprising microprocessor readable and executable instructions that cause the microprocessor to:

receive a first invite message to establish a first communication session, wherein the first invite message comprises a first hash of a first fingerprint, receive a media message containing the first fingerprint to establish a media stream for the communication session, create a second hash using the first fingerprint in the media message, compare the first hash to the second hash, and latch to an address and/or a port in the media message in response to the first hash matching the second hash.

12. The session border controller of claim 11 , wherein the instructions further cause the microprocessor to not latch to the address or the port in the media message in response to the first hash not matching the second hash.

13. The session border controller of claim 11 , wherein the first communication session is one of a Session Initiation Protocol (SIP) communication session, an H.323 communication session, or a Web Real-Time Communication (WebRTC) communication session.

14. The session border controller of claim 11 , wherein the first invite message is a first Session Initiation Protocol (SIP) INVITE message, wherein the media message is a Real-time Transport Protocol (RTP) or a Secure RTP (SRTP) message, and wherein the first communication session is a SIP communication session.

15. The session border controller of claim 14 , wherein the first hash is sent in a SIP header in the first SIP INVITE.

16. The session border controller of claim 14 , wherein the instructions further cause the microprocessor to receive a second SIP INVITE to establish a second SIP communication session and wherein the second SIP INVITE comprises a second hash of a second fingerprint, wherein the second fingerprint is different from the first fingerprint.

17. The session border controller of claim 14 , wherein the first fingerprint is sent in a payload of the RTP or SRTP message.

18. The session border controller of claim 14 , wherein the first hash is sent in a Session Description Protocol (SDP) <fmt>header in the first SIP INVITE message.

19. The session border controller of claim 18 , wherein the SDP <fmt>header has an additional header that indicates a presence of the first hash.

20. A communication device comprising:

a microprocessor; and

a computer readable medium, coupled with the microprocessor and comprising microprocessor readable and executable instructions that cause the microprocessor to:

generate a hash of a fingerprint; and

send an invite message that comprises the hash of a fingerprint to a Session Border Controller (SBC), wherein the invite message is to establish a communication session, and send a media message to the SBC that includes the fingerprint, wherein the SBC uses the hash of the fingerprint and the fingerprint to determine whether to latch to an address and/or a port in the media message.

Assignments (9)
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
SECURITY INTEREST Recorded May 1, 2018
From: EXTREME NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 046050/0546 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2018
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 046051/0775 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
THIRD AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 044639/0300 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2017
From: AVAYA INC.; AVAYA COMMUNICATION ISRAEL LTD; AVAYA HOLDINGS LIMITED
To: EXTREME NETWORKS, INC.
Reel/Frame 043569/0047 →
SECOND AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Jul 14, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 043200/0614 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2015
From: PAL, BISWAJYOTI; CHATTERJEE, MANISH
To: AVAYA INC.
Reel/Frame 036042/0861 →