IP Library Granted Patent US 7,412,722
Granted Patent B1
US 7,412,722 · App. 10/215,410 · Granted Aug 12, 2008

Detection of softswitch attacks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,412,722
App. No.
10/215,410
Granted
Aug 12, 2008
Kind
B1
Abstract

A security system ( 150 ) in a network includes a softswitch ( 440 ) and a detection unit ( 420 ). The detection unit ( 420 ) detects activity directed to the softswitch ( 440 ) and records the detected activity. In another implementation, a method for configuring a security device ( 150 ) for use in a network includes installing a detection unit ( 420 ) to monitor and record traffic directed to the security device ( 150 ), installing a deceptive operating system ( 430 ), installing a softswitch ( 440 ), and configuring the deceptive operating system ( 430 ) and softswitch ( 440 ) to mirror settings used in an active softswitch ( 140 ) in the network.

Claims (80)

1. A security device, comprising:

a softswitch emulator that performs no switching functions;

a communication interface configured to connect the security device to a data network;

a detection unit configured to:

detect activity directed to the softswitch emulator, and

record detected activity

a deceptive operating system that is configured to emulate a softswitch operating system; and

a first storage unit configured to:

store first data for configuring the softswitch emulator to mirror at least one active softswitch connected to the data network, and

store second data for configuring the deceptive operating system to emulate an operating system of the at least one active softswitch.

2. The security device of claim 1 , wherein the data network is a packet network.

3. The security device of claim 1 , further comprising a second interface for connecting to a public switched telephone network.

4. The A security device, comprising:

a softswitch emulator that performs no switching functions;

a communication interface configured to connect the security device to a data network;

a deceptive operating system that is configured to emulate a softswitch operating system; and

a detection unit configured to:

detect activity directed to the softswitch emulator;

record detected activity;

detect activity directed to the deceptive operating system; and

record the detected activity directed to the deceptive operating system.

5. A security device, comprising:

a softswitch emulator that performs no switching functions;

a communication interface configured to connect the security device to a data network;

a detection unit configured to:

detect activity directed to the softswitch emulator and

record detected activity;

a deceptive operating system that is configured to emulate a softswitch operating system; and

a real operating system platform for the security device.

6. A security device, comprising:

a softswitch emulator that performs no switching functions;

a communication interface configured to connect the security device to a data network;

a deceptive operating system that is configured to emulate a softswitch operating system;

a detection unit configured to:

detect activity directed to the softswitch emulator;

record detected activity; and

record at least one of keystrokes when recording the detected activity and functions executed by the softswitch when recording the detected activity.

7. A method, comprising:

connecting a security device to a data network, wherein the security device includes a softswitch emulator that performs no switching functions;

monitoring traffic directed to the security device; and

recording the traffic directed to the security device;

wherein the security device includes a deceptive operating system and wherein the recording includes:

capturing at least one of keystrokes and functions executed by the softswitch emulator directed to the deceptive operating system, and

storing the at least one of keystrokes and executed functions.

8. The method of claim 7 , wherein the data network is an active network that includes a functioning softswitch.

9. The method of claim 7 , wherein the data network is a packet network.

10. The method of claim 7 , further comprising connecting the security device to a public switched telephone network.

11. The method of claim 8 , further comprising analyzing the recorded traffic to determine a vulnerability of the functioning softswitch to network attacks.

12. A security device, comprising:

a softswitch emulator that performs no switching functions;

a real operating system platform for the security device;

a deceptive operating system that is configured to emulate a softswitch operating system wherein the softswitch emulator and the deceptive operating system are configured to mirror settings in one or more softswitches in a data network;

a communication interface that connects the security device to the data network; and

a detection unit that monitors activity in the data network and that is configured to:

detect activity directed to the softswitch emulator,

record detected activity,

detect activity directed to the deceptive operating system, and

record the detected activity directed to the deceptive operating system.

13. The security device of claim 12 , wherein the data network is a packet network.

14. The security device of claim 12 , further comprising a second interface for connecting to a public switched telephone network.

15. A security device, comprising:

a softswitch emulator that performs no switching functions;

a real operating system platform for the security device;

a deceptive operating system that is configured to emulate a softswitch operating system, wherein the softswitch emulator and the deceptive operating system are configured to mirror settings in one or more softswitches in a data network;

a communication interface that connects the security device to the data network; and

a detection unit that monitors activity in the data network and that is configured to:

detect activity directed to the softswitch emulator, and

record detected activity; and

a first storage unit configured to:

store first data for configuring the softswitch emulator to mirror at least one active softswitch connected to the data network, and

store second data for configuring the deceptive operating system to emulate an operating system of the at least one active softswitch.

16. A security device, comprising:

a softswitch emulator that performs no switching functions;

a real operating system platform for the security device;

a deceptive operating system that is configured to emulate a softswitch operating system, wherein the softswitch emulator and the deceptive operating system are configured to mirror settings in one or more softswitches in a data network;

a communication interface that connects the security device to the data network; and

a detection unit that monitors activity in the data network and that is configured to:

detect activity directed to the softswitch emulator

record detected activity, and

record at least one of keystrokes when recording the detected activity and functions executed by the softswitch when recording the detected activity.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2015
From: VERIZON PATENT AND LICENSING INC.
To: PALO ALTO NETWORKS, INC.
Reel/Frame 037093/0790 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2014
From: VERIZON LABORATORIES INC.
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 033428/0478 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 8, 2002
From: NORRIS, EDWARD JAMES; DUMAS, DAVID KENNETH
To: VERIZON LABORATORIES INC.
Reel/Frame 013190/0402 →