×

System and method for providing network level and nodal level vulnerability protection in VoIP networks

  • US 8,582,567 B2
  • Filed: 08/09/2006
  • Issued: 11/12/2013
  • Est. Priority Date: 08/09/2005
  • Status: Active Grant
First Claim
Patent Images

1. A method for protecting one or more communications devices comprising the steps of:

  • receiving a communication at a first processor communicably coupled to the one or more communications devices via a network;

    filtering the received communication using the first processor wherein the first processor executes three or more stages selected from the group comprising a media protection and filtering plane, a policy-based filtering plane, a signature-based filtering plane, a protocol anomaly detection and filtering plane, and a behavioral learning-based filtering plane;

    either allowing or blocking the received communication using the first processor based on the selected stages;

    wherein the media protection and filtering plane blocks the received communication whenever the communication falls outside one or more communication media-based parameters comprising signaling media integrity, media validation and anomaly detection;

    wherein the policy-based filtering plane blocks the received communication whenever one or more user defined media and time policies are violated;

    wherein the signature-based filtering plane blocks the received communication whenever the received communication matches one or more known attack signatures;

    wherein the protocol anomaly detection and filtering plane blocks the received communication whenever the received communication violates one or more protocol policies comprising a protocol misuse policy, a protocol message scrubbing policy, and a device specific policy;

    wherein the behavioral learning-based filtering plane uses a probability analysis to detect anomalies based on one or more learned parameters and resolve probable false alarms into a correct decision to either block or allow the received communication;

    further comprising;

    one or more media subsystems having a second processor communicably and securely connected to one or more signaling subsystems and deployed as a security and monitoring interface between the network and the one or more communications devices; and

    an element management system (EMS) subsystem having a third processor communicably and securely connected to the one or more signaling subsystems;

    ora verify subsystem having a fourth processor communicably and securely connected to the one or more signaling subsystems.

View all claims
  • 19 Assignments
Timeline View
Assignment View
    ×
    ×