首页> 外国专利> Session initiation protocol (SIP) firewall for IP multimedia subsystem (IMS) core

Session initiation protocol (SIP) firewall for IP multimedia subsystem (IMS) core

机译:IP多媒体子系统(IMS)核心的会话发起协议(SIP)防火墙

摘要

A SIP firewall defends an IMS network against SIP registration-based DoS/DDoS attacks by issuing fake authentication challenges when suspiciously high registration traffic is present. The fake authentication challenges include a predictive nonce that is to be used in the challenge response, thus forcing users to be state-aware and to issue the SIP registration requests from valid IP address in order to successfully respond to the fake authentication challenges. Upon confirming an association between the challenge response and the fake authentication challenges, the firewall opens a registration window to a protected node of the core network. In such manner, the firewall opens a registration window to (unauthenticated) legitimate users while stopping DDoS mode of registrations (or at least making them extremely difficult and costly) without impacting or involving the protected node.
机译:当存在可疑的高注册流量时,SIP防火墙通过发出伪造的身份验证质询来防御IMS网络,以抵御基于SIP注册的DoS / DDoS攻击。伪身份验证质询包括将在质询响应中使用的预测随机数,从而迫使用户具有状态意识,并从有效IP地址发出SIP注册请求,以便成功响应伪身份质询。在确认质询响应和伪身份验证质询之间的关联后,防火墙将向核心网络的受保护节点打开注册窗口。以这种方式,防火墙在不影响或涉及受保护节点的情况下,在停止DDoS注册模式(或至少使其极为困难和昂贵)的同时,向(未经身份验证的)合法用户打开注册窗口。

著录项

  • 公开/公告号US8955090B2

    专利类型

  • 公开/公告日2015-02-10

    原文格式PDF

  • 申请/专利权人 THIERRY C. BESSIS;ASHWIN V. RANA;

    申请/专利号US20110987554

  • 发明设计人 ASHWIN V. RANA;THIERRY C. BESSIS;

    申请日2011-01-10

  • 分类号G06F21/00;H04L29/06;H04L9/32;

  • 国家 US

  • 入库时间 2022-08-21 15:16:36

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号