Patent · US Active

Signature-free intrusion detection

US9736172B2 · kind B2 · utility

3Cited by
14References
13Claims
0Family size

Assignee

Inventors

Key dates

Filing dateSep 12, 2007
Grant dateAug 15, 2017
Priority date
Expiry dateNov 10, 2031

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/0254
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

An apparatus and method are disclosed for detecting intrusions in Voice over Internet Protocol systems, without the use of an attack signature database. In particular, the illustrative embodiment is based on the observation that some VoIP-related protocols (e.g., the Session Initiation Protocol [SIP], etc.) are simple enough to be represented by a finite-state machine (FSM) of compact size. A finite-state machine is maintained for each session/node/protocol combination, and any illegal state or state transition—which might be the result of a malicious attack—is flagged as a potential intrusion.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.