发明名称 Real-time network attack detection and mitigation infrastructure
摘要 The invention features systems and methods for detecting and mitigating network attacks in a Voice-Over-IP (VoIP) network. A server is configured to receive information related to a mitigation action for a call. The information can include a complexity level for administering an audio challenge-response test to the call and an identification of the call. The server also generates i) a routing label based on the identification of the call, and ii) a script defining a plurality of variables that store identifications of a plurality of altered sound files for the audio challenge-response test. Each altered sound file is randomly selected by the server subject to one or more constraints associated with the complexity level. The server is further configured to transmit the script to a guardian module and the routing label to a gateway.
申请公布号 US9332026(B2) 申请公布日期 2016.05.03
申请号 US201414242758 申请日期 2014.04.01
申请人 SONUS NETWORKS, INC. 发明人 Lapsley David;Mansur Miri;Klotzbach Jonathan;Shu Ti-yuan Dean;Chary Sri;Joseph Joby;Topham Mark;Matragi Wassim;Dumble Kenneth
分类号 G08B23/00;H04L29/06 主分类号 G08B23/00
代理机构 代理人 Straub Stephen T.;Straub Ronald P.;Straub Michael P.
主权项 1. A method of operating elements of a communications system to detect and mitigate network attacks in a VoIP network, said elements including a gateway, an analyzer and a guardian module, the method comprising: receiving, by the gateway, via the VOIP network, an incoming call and associated signaling; transmitting, from the gateway to the analyzer, a call detail record (CDR) for the incoming call; maintaining in memory, by the analyzer, a plurality of adaptable profiles that capture statistical and behavioral properties of call detail records (CDRs) associated with a plurality of received calls in the VOIP network; maintaining in memory, by the analyzer, a plurality of reference profiles that reflect normal call behavior corresponding to the plurality of adaptable profiles; updating, by the analyzer, an adaptable profile from the plurality of adaptable profiles based on the CDR of the incoming call; comparing, by the analyzer, the updated adaptable profile with a corresponding reference profile from the plurality of reference profiles; determining, by the analyzer, if an anomaly indicative of a network attack exists based on the comparing using multivariate analysis; and when said analyzer determines that an anomaly exists indicative of a network attack: generating, by the analyzer, an alarm corresponding to the incoming call indicative of the network attack;transmitting, by the analyzer, to a rules engine, the alarm indicative of the network attack to determine a mitigation action for the incoming call; anddetermining by the rules engine one or more mitigation actions for the incoming call, said one or more mitigation actions including a first mitigation action comprising rerouting the incoming call to the guardian module to receive an audio challenge-response test, wherein a complexity level of the test is determined based on the alarm.
地址 Westford MA US