Method for protecting a packet-based network from attacks, and security border node
3 Assignments
0 Petitions
Accused Products
Abstract
The invention relates to a security border node (2a) for protecting a packet-based network from attacks, comprising: an anomaly detection unit (10) for performing an anomaly detection, in particular a statistical analysis, on session control messages (11), in particular on SIP messages contained in a packet stream (5) received in the security border node (2a). The security border node further comprises a message context provisioning unit (13) for providing at least one session control message (11) to the anomaly detection unit (10) together with message context information (12, 17, 24) related to a client (22) and/or to a session (23) to which the session control message (11, 11a to 11f) is attributed. The invention also relates to a method for protecting a packet-based network from attacks, to a computer program product, and to a packet-based network.
-
Citations
28 Claims
-
1-14. -14. (canceled)
-
15. Method for protecting a packet-based network from attacks, comprising:
-
performing an anomaly detection on session control messages contained in a packet stream received in a security border node of the network, wherein the performing step performs the anomaly detection on at least one session control message together with message context information about the session control message being related to a session to which the session control message is attributed, the message context information comprising session history information. - View Dependent Claims (16, 17, 18, 28)
-
-
19. Security border node for protecting a packet-based network from attacks, comprising:
-
an anomaly detection unit configured to perform an anomaly detection on session control messages contained in a packet stream received in the security border node;
wherein;a message context provisioning unit configured to provide at least one session control message to the anomaly detection unit together with message context information related to a session to which the session control message is attributed, the message context information comprising session history information. - View Dependent Claims (20, 21, 22, 23, 24, 25, 26, 27)
-
Specification