EP1869858A2 - Verfahren zur steuerung des sendens unangeforderter voice-informationen - Google Patents

Verfahren zur steuerung des sendens unangeforderter voice-informationen

Info

Publication number
EP1869858A2
EP1869858A2 EP06726330A EP06726330A EP1869858A2 EP 1869858 A2 EP1869858 A2 EP 1869858A2 EP 06726330 A EP06726330 A EP 06726330A EP 06726330 A EP06726330 A EP 06726330A EP 1869858 A2 EP1869858 A2 EP 1869858A2
Authority
EP
European Patent Office
Prior art keywords
call
entity
information
network
sending
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Withdrawn
Application number
EP06726330A
Other languages
English (en)
French (fr)
Inventor
Bertrand Mathieu
Yvon Gourhant
Quentin Loudier
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Orange SA
Original Assignee
France Telecom SA
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by France Telecom SA filed Critical France Telecom SA
Publication of EP1869858A2 publication Critical patent/EP1869858A2/de
Withdrawn legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L65/00Network arrangements, protocols or services for supporting real-time applications in data packet communication
    • H04L65/1066Session management
    • H04L65/1076Screening of IP real time communications, e.g. spam over Internet telephony [SPIT]
    • H04L65/1079Screening of IP real time communications, e.g. spam over Internet telephony [SPIT] of unsolicited session attempts, e.g. SPIT
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L65/00Network arrangements, protocols or services for supporting real-time applications in data packet communication
    • H04L65/1066Session management
    • H04L65/1101Session protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L65/00Network arrangements, protocols or services for supporting real-time applications in data packet communication
    • H04L65/1066Session management
    • H04L65/1101Session protocols
    • H04L65/1104Session initiation protocol [SIP]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04MTELEPHONIC COMMUNICATION
    • H04M7/00Arrangements for interconnection between switching centres
    • H04M7/006Networks other than PSTN/ISDN providing telephone service, e.g. Voice over Internet Protocol (VoIP), including next generation networks with a packet-switched transport layer
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04MTELEPHONIC COMMUNICATION
    • H04M3/00Automatic or semi-automatic exchanges
    • H04M3/22Arrangements for supervision, monitoring or testing
    • H04M3/2281Call monitoring, e.g. for law enforcement purposes; Call tracing; Detection or prevention of malicious calls

Definitions

  • a practice of sending unsolicited information to users is developing. When it comes to sending e-mail or e-mail, most often of a commercial nature, to users who have not requested it, the practice is called spam. Spam is recognized as a real scourge, causing significant productivity losses in companies.
  • the practice is also developing in the field of instant messengers and in this case takes the name spim of the English "spam on instant messaging”.
  • the same practice can also be found in the field of telephony over IP and in this case is called spit of the English language "spam over Internet Telephony”.
  • IP telephony is a rapidly expanding voice communication technology that leverages an IP data network to deliver multimedia communications over a single voice and data network.
  • the sending of unsolicited information in a VoIP or spit network causes significant nuisance.
  • the spit can lead to a saturation of voice mailboxes associated with users, and at worst to unavailability of a network equipment following a massive sending of messages. Spit sending causing the unavailability of the network equipment is then called a denial of service attack.
  • the techniques used to fight spam are not directly applicable.
  • An example of a technique widely used today to fight against spam is to block unwanted emails by using filters on mail servers or client computers, after the mail is sent and before it is received.
  • Filters can recognize keywords, or more advanced filters can, after a learning phase calculate a probability that an email is spam or not from key words it contains.
  • this technique based on the recognition of keywords is difficult to apply to voice messages.
  • said technique does not prevent the mail from circulating in the network.
  • the object of the present invention is to propose a method adapted to the detection of unsolicited voice information in a voice over IP telecommunications network.
  • the invention also aims to propose a method comprising a reaction step following the spit detection.
  • Another object of the invention is to provide technical means for collecting information relating to an entity identified as emitting spit and to propose a decontamination service if it turns out that the terminal associated with the entity is infected by a worm or virus that issues spit to the terminal user.
  • a first object of the invention relates to a method of combating ( "sending unsolicited information in a transmission network by packets from an issuing entity to a destination entity, characterized in that the unsolicited information is of the voice type and the sending of the unsolicited information is made during a call which includes a call establishment phase. call during which at least one call signaling message is transmitted in the network, followed by an established calling phase during which said unsolicited information is transmitted, and in that the method comprises:
  • the detection of unsolicited information is a prerequisite for a reaction.
  • the advantage of the detection method lies in the fact that it is implemented in the call establishment phase, therefore, before the unsolicited information flows in the network and arrives at the destination entity.
  • the detection of unsolicited information is done by analyzing the call signaling message from the transmitting entity and a call context relating to the previous calls from the issuing entity.
  • the analysis of the call signaling message makes it possible to retrieve information relating to the call during the establishment phase, such as, for example, information on the sending entity causing the call.
  • the analysis is done in the network and has considerable advantages:
  • a terminal infected with a virus or a worm that emits spit at the end of the terminal user can be identified / located
  • the detection of spit is not conditioned by a configuration specific to the user or his terminal since the detection is done in the network,
  • a network operator has information on a user at the origin of spit that can be requested in a legal framework.
  • the detection of unsolicited information is done by counting over a period of time a number of call signaling messages relating to a call in the establishment phase and by comparing the number of signaling messages. to a threshold value that must not be exceeded.
  • the transmission of a multimedia call in the same way as a conventional telephone call, comprises several steps, including numbering, ringing, stalling, talking, or posting a message on a voice mailbox. Said steps take time.
  • the analysis mode corresponds to the technical consideration of this deSai: if an issuing entity sends several calls simultaneously, or in a short window of time, then the call transmission has been automated. Indeed, if it happens that an issuing entity sends two successive calls to a destination entity, it rarely sends 5 or 10 successive calls to the same destination entity.
  • the detection of unsolicited information is by identification over a rolling period of time of an automation logic in the call composition.
  • the advantage of this mode is that it provides a technical means in the network to detect an automatic path of a list of addresses used to dial calls.
  • the reaction consists in limiting the number of calls that can be sent per unit of time by the entity sending the unsolicited information.
  • the reaction consists of redirecting all or part of the identified call as sending unsolicited information to an entity of the network.
  • the invention contributes to the development and propagation of VoIP technology by removing a brake that is the spit.
  • the method can be used to propose a decontamination service of a terminal associated with the transmitting entity infected by a worm or a virus that transmits the unsolicited voice information without the knowledge of the user associated with it. issuing entity.
  • the invention also relates to a system for controlling the sending of unsolicited information comprising a packet transmission network, an issuing entity, a destination entity and an entity in the network, characterized in that the unsolicited information is of the voice type and the sending of the unsolicited information is during a call which includes a call setup phase during which at least one call signaling message is transmitted in the network, followed an established call phase during which said unsolicited information is transmitted, and in that the entity in the network comprises:
  • a detection module arranged to detect, during said call, the unsolicited information.
  • the system comprises a reaction module arranged to react following the detection of the unsolicited information.
  • the computer program according to the invention comprises instructions for acting on the calls coming from the sending entity and identified as being the sending of the unsolicited information.
  • FIG. 1 illustrates a spit detection method based on on several modes of analysis of SIP signaling messages exchanged during the establishment of a VoIP call.
  • FIG. 2 illustrates a reaction method following spit detection based on several reaction modes.
  • FIG. 3 shows an architecture corresponding to a first embodiment of the invention in which the spit and reaction detection methods are installed on application servers placed in a VoIP network based on SIP.
  • FIG. 4 shows an architecture corresponding to a second embodiment of the invention in which the spit detection and reaction methods are installed in the network at the level of application probes.
  • IP IP telephony
  • ITU-T International Telecommunications Union-Teiecommunications standardization
  • SIP Session Initiation Protocol
  • I 1 IETF Internet Engineering Task Force
  • IP telephony more specifically the signaling transmission part, is also realized by using a Peer to Peer concept for peer-to-peer, or P2P, which designates a type of communication protocol whose elements do not play exclusively. client or server roles but work both ways, being both clients and servers of other nodes in the network.
  • RTP Real Time Protocol
  • P2P Peer to Peer concept for peer-to-peer
  • the SIP protocol handles multimedia calls based on a client / server mode: messages exchanged during a SIP dialogue are requests or responses.
  • the SIP messages contain information relating to the current call, including but not limited to an identifier of the call, information relating to an entity issuing the message in a field of the message called "FROM", and information relating to to a destination entity in a message field called "TO".
  • a response to a request contains fields that are identical to those of the request, including the call identifier, the "FROM" field, and the "TO" field.
  • a SIP response includes a status code of the response that allows you to know how the request was processed. The status code qualifies a message received in response to a SIP request as an error or success message.
  • a multimedia call initiated by an issuing entity that sends a request and which does not obtain a response ends thanks to a mechanism called TCP temme, implemented by the TCP transport protocol on which s Supports SIP: an armed timer at the sending entity when sending the request plays the role of stopwatch and no response to the request, expires, which ends the call.
  • TCP temme implemented by the TCP transport protocol on which s Supports SIP: an armed timer at the sending entity when sending the request plays the role of stopwatch and no response to the request, expires, which ends the call.
  • the sending and receiving entities involved in a SlP-based multimedia call are designated by addresses called Uniform Resource Locator Session Initiation Protocol (SIP) URLs that identify a user and a terminal and are in the form: "user_information @ domasne", where "user_information" is a name or a phone number, and domain is a domain name or an IP address.
  • SIP Uniform Resource Locator Session Initiation Protocol
  • the user can be calling or called, as in a conventional phone call.
  • the terminal can be a VoIP terminai, such as a personal assistant (or "PDA” for Personal Digital Assistant), a personal computer (or “PC” for Personal Computer), an IP phone.
  • a VoIP call is transmitted over an IP packet transmission network.
  • both call signaling messages and data corresponding to information transmitted by the transmitting entity to the destination entity are transmitted in the network.
  • the VoIP call in the same way as a conventional telephone call, goes through several phases, for example and non-exhaustively by a call setup phase during which the issuing entity has provided the SlP URL address. of the recipient entity that it wishes to join but the recipient entity is not yet informed that the issuing entity wishes to join it.
  • call signaling messages circulate in the network in order to reserve the necessary resources for the call and to see if the destination entity is in a busy or free state.
  • the destination entity was joined, either because it went off-hook when it was informed of the call or because a mailbox associated with the destination entity was triggered. , behaving as if the recipient entity had dropped out.
  • data packets relating to a conversation between the sending entity and the receiving entity are circulating in the network.
  • a VoIP-type IP network 20, or Voice over IP for voice over IP is in charge of establishing VoIP communications.
  • An issuing entity 1 initiates a VoIP call to a destination entity 2. It is considered that the sending and receiving entities form an integral part of the network 20.
  • a detection module 5 is installed in a first network entity 3. Alternatively, the detection module 5 is installed in a remote machine which dialog with the first network entity 3 of the network 20.
  • the detection module 5 is a program stored in a memory of the first network entity 3; i! comprises instructions for implementing the detection method sefon the invention.
  • the defection process 5 is triggered in a VoIP call set-up phase following the reception by the first network entity 3 of a SIP INVITE 4 call signaling message corresponding to an invitation sent by the transmitting entity 1 to the destination entity 2 to participate in a multimedia call.
  • the message includes information about the sending entity 1 in the "FROM" field and the destination entity 2 in the "TO" field.
  • a step 100 following the triggering of the detection module, the fields of the message 4 are analyzed.
  • the analysis uses an appei context 6 managed by the first network entity 3 which contains information relating to the previous messages received from the transmitting entity 1.
  • the analysis makes it possible to qualify the current message of spit or not and made according to four different modes described below.
  • the detection module 5 comprises at least one of the following four modes of analysis:
  • the analysis is done as follows: the detection module 5 counts the SIP INVITE 4 call signaling messages from the transmitting entity 1. If, for a first period of time 7 defined in the detection module 5, the number of SIP INVITE 4 call signaling messages received from the transmitting entity 1 exceeds a first threshold value 8 defined in the detection module 5, then it is considered that the The call transmission from the transmitting entity 1 has been automated and the messages from the transmitting entity 1 can be likened to spit.
  • An automated call broadcast may correspond to a spit broadcast or not. Indeed, some entities may be allowed to automate their sending of messages. Said entities are referenced in lists of entities authorized to issue several calls simultaneously called whitelists.
  • the call context managed by the network entity 3 contains for each call sent by the sending entity 1 at least one call identifier and a callback timestamp value.
  • the analysis is done as follows: the detection module 5 counts the successive calls from the sending entity 1 to the destination entity 2 during a second period of time 9 defined in FIG. the detection module 5. If the number of calls exceeds a second value defined in the detection module 5, then it is considered that the call transmission from the transmitting entity has been automated and that the messages from the terminal associated with the transmitting entity can be likened to spit.
  • the call context managed by the first network entity 3 contains for each call sent by the sending entity 1 at least the identifier of the call, a timestamp value of the call and a identity of the recipient entity 2.
  • the analysis is done as follows: the detection module 5 identifies an automation logic 11 in the composition of the addressee addresses in VoIP calls sent by the issuing entity 1 during a third period defined in the detection module 5.
  • the automation logic corresponds for example to a sequential logic in called user identities specified in the "TO" field of the SIP INVITE 4 call signaling message, which can be chosen by browsing an alphabetical directory of usernames. Another logic of automation is detected by detecting a constant call duration on a significant number of calls.
  • the call context managed by the first network entity 3 contains for each call sent by the sending entity 1 at least the identifier of the call, a time stamp value of the call and a SIP URL of the destination entity 2.
  • the analysis is done as follows: the detection module 5 counts for a fourth time period 13 defined in the detection module 5 the number of error messages received by the first entity 3 network from a routing element 25 VoIP network 20 following recipients entities call attempts that do not exist.
  • the field 'TO ! Î of SIP INVITE 4 call signaling message is filled in mats the information therein does not correspond to any existing entity of the network 20.
  • the fourth mode of analysis therefore consists of counting a number of messages whose status code corresponds to an error and if the number exceeds a third threshold value 16 defined in the detection module, then it is considered that the call transmission from the sending entity has been automated and therefore the messages from this entity can be assimilated to spit.
  • the call context managed by the first network entity 3 contains for each call sent by the sending entity 1 and which has failed at least the identifier of the call and a time stamp value of 1. 'call.
  • the first, second, third and fourth periods of time may be different or identical.
  • the first, second and third threshold values may be different or identical.
  • the four detection modes described above are independent. They can be used in a complementary way (that is, one mode is used alone or several modes are used in combination).
  • the detection method provides technical means, through the analysis of call signaling, to identify an entity that sends spit voluntarily or involuntarily via a virus or a worm that has infected the termina! associated with the entity and issues spit without the knowledge of the terminal user.
  • Information that identifies an entity that issues spit facilitates possible future legal action if it turns out that users associated with the entities knowingly issue spit, or allow to provide a decontamination service in the event that the terminate associated with the entity has been infected with a worm or virus.
  • a spit reaction module 50 is installed in a second network entity 33 of the network 20.
  • the reaction module 50 is installed in a remote machine that communicates with the second network entity 33 of the network 20.
  • the reaction module 50 is a program stored in a memory of its second network entity 33; i! includes instructions for implementing the reaction method according to the invention.
  • the reaction method 50 is triggered following spit detection by a detection module 5 with reference to FIG. 1.
  • the detection and reaction modules 50 of the present invention are independent in the sense that spit detection is performed. by an entity or a moduie other than that described in the context of the invention may give rise to the triggering of the reaction module.
  • the modules 50 and 5 are installed in the same network entity.
  • reaction module 50 comprises at least one of the following reaction modes:
  • a first reaction mode the calls initiated by the transmitting entity 1, identified as spit by the detection module, are blocked 51.
  • the call signal SlP INVITE received from the the transmitting entity is not routed by the network 20.
  • the reaction module 50 sends an information message 52 to the transmitting entity 1 informing it of the impossibility of joining the entity recipient 2.
  • the feedback module 50 does not refer to the transmitting entity 1.
  • the call ends in a step 53 through a TCP timeout mechanism.
  • the number of calls that the transmitting entity 1 is allowed to transmit per unit of time is limited to a value 54 defined in the reaction module 50.
  • the value 54 can be parameterized so as to be permanent or temporary.
  • an event 56 associated with the spit identified by the detection module 50 is routed to a network entity 58 in charge of call supervision operations in the network 20.
  • the network entity 58 can host the IS (Information System) of the network 20, or an after-sales service, or a VoiP support service.
  • the routing of the event 56 to the network entity 58 makes it possible to envisage more global actions, beyond the repetition of the same operations on each call made:
  • the coordinates of the user associated with the issuing entity are retrieved in order to send a mail to the user summarizing the calls suspected of constituting spit and proposing him to contact a service capable of escaping. propose solutions before being reduced to a restricted category of calls,
  • the reaction module 50 is extended in order to follow up a profile! more or less spammers, to obtain and keep up-to-date statistics specific to the spit, to rely on the evolution of users to group equivalent profile spit users into common categories for providing identical processing for a set of client users belonging to the same category.
  • This makes it possible to correlate calls and to detect changes in behavior.
  • This makes it possible to define lists of users who emit spit, the lists are also called blacklists, or to analyze that a user with behavior until now normal now issues spit. In the latter case, his terminal may have been infected by a virus or worm and spit unknowingly. Thus, it is possible to detect that terminals have been infected and to propose a decontamination service of the terminal.
  • there may be white lists of people authorized to make simultaneous calls such as government services.
  • spit detection counters can advantageously be correlated with whitelists before making decisions to block communications.
  • spit detection and reaction modules are installed in a SIP application server, in the form of value-added or evolved services.
  • a VoIP network architecture based on the SiP protocol and integrating the spit detection and response modules 50 at an application server 60a and 60b respectively is presented.
  • This embodiment is advantageously used to detect the spit and react in the context of a VoIP network architecture deployed by a network operator with routing elements in the network.
  • Said routing elements may be SIP delegate servers (the term commonly used is the term "SIP proxy”) 61a and 61b respectively, servers to which are connected issuer or recipient entities or SIP clients 62a and 62b respectively.
  • Said SIP proxy servers have the role of routing calls in the network SlP.
  • the invention is illustrated in a SIP-based architecture and also applies to an architecture based on the H323 protocol because the protocol uses the same functional components, for example, and in a non-proprietary manner.
  • exhaustive H323 gatekeepers which are elements of the network whose role is to establish the communication between an issuing entity and a destination entity and to set up the routing in the same way as an element routing of an architecture based on SiP.
  • SIP communication is established between two SIP clients 62a and 62b via SiP proxy servers 61a and 62b, respectively, which are responsible for routing calls in the VoIP network.
  • the architecture may include SIP lease servers 63a and 63b, respectively, to provide the current location of users and SIP registration servers 64a and 64b respectively that register clients of a domain 65 or 66 in a database.
  • the SIP proxy servers 61a and 61b may be made to communicate with each other as indicated by the arrow 67 if the SiP clients are connected to different SIP proxy servers 61a and 61b. This is the case when communication is established between two SIP clients 62a and 62b belonging to different domains 65, 66.
  • Said application servers may be located near SIP proxy servers as shown in Figure 3.
  • an application server may be connected to multiple SlP proxy servers, or multiple application servers. can be connected to a SIP proxy server when it comes to performing multiple value-added service logic or load sharing.
  • Said application servers have access to all call signaling parameters, they can modify them, they can redirect communications and interact with other modules. It is therefore easy to implement a value-added service on a SIP architecture.
  • software modules running on application servers are added to the architecture. Different possibilities are offered for integrating value-added services into a VoIP architecture:
  • an application server according to the invention is installed in a standard Internet Protocol Multimedia Subsystem (IMS) architecture derived from the 3GPP (Third Generation Partnership). Project), http://www.3gpp.org.
  • IMS Internet Protocol Multimedia Subsystem
  • the spit detection and reaction modules 50 are installed at application probes 70-1 and 70-2 respectively placed in the network.
  • Application probes are equipment placed in the network of a telecommunications operator or an internet service provider that identifies each flow in real time, analyzes the flow to the application level and intercepts in a transparent manner, ie without users or terminals knowing as the stream has been analyzed, all packets of data streams.
  • the application probes are said to be passive if they limit their action to watch the stream flow without acting on said stream. Passive probes can analyze the stream in real time and record data about the stream to a file for later analysis.
  • the data are, for example, and non-exhaustively a number of data exchanged, a number of connections established, a type of fiux.
  • the subsequent analysis of the data can be used to understand the functioning of the network, to analyze the behavior of users, to classify users into categories.
  • Passive probes are advantageously used when no reaction follows a spit detection.
  • external entities may implement delayed response mechanisms, for example by routing all calls that will be issued by a terminal suspected of sending spit to a voice server.
  • Application probes can also affect the flow. In this case, we speak of active application probes.
  • the active application sensor can act on the P2P stream.
  • This relates to the invention when the P2P protocol performs a VoIP function.
  • a multimedia session consists of two streams: one stream that corresponds to the set of SIP signaling messages and one stream that corresponds to the data conveyed by the protocol.
  • the SIP signaling identified by the active application probe, can then be analyzed to detect spit in the same way as in a spit detection module as described above and which would be installed at an SiP proxy server or an application server: call signaling fields are analyzed and, depending on a stored call context, the call is called spit or not.
  • An active application probe can also act on said streams, especially if they are assimilated to spit, in the same way as in a spit reaction module as described above and which would be installed at a SIP proxy level.
  • the RTP stream identified by the active application probe, may advantageously be analyzed in order to detect spit. Spit detection from RTP streams is achieved by recognizing common characteristics in the payload portion of packets, corresponding to data, of different RTP packets indicating that the same data is flowing several times in the network.
  • the recognition of common characteristics may consist in identifying the same signature in RTP data packets or the same data packet size, indicating that data of the same size circulates in the network.
  • a correlation is made between the opening of a RTP session for data transport and SIP signaling. The information provided by said SIP signaling then allows the probe to react to the spit detection in the same way as in the reaction module described above.
  • the active application probes can be placed at different points of the VoIP network, as shown in FIG. 4.
  • Said probes 70-1 and 70-2, respectively, are installed between an SiP client 62a and a SIP proxy server 61a or between two proxy servers.
  • the invention consists in adding spit detection and reaction modules at the level of active application probes.
  • the advantage of this embodiment is considerable: it makes it possible to detect VoIP communications transiting on a VoIP architecture of an operator based on different protocols: for example SIP or H323, but also VoIP communications using Peer-to-technology. peer.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Business, Economics & Management (AREA)
  • General Business, Economics & Management (AREA)
  • Multimedia (AREA)
  • Telephonic Communication Services (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Mobile Radio Communication Systems (AREA)
EP06726330A 2005-04-13 2006-04-10 Verfahren zur steuerung des sendens unangeforderter voice-informationen Withdrawn EP1869858A2 (de)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
FR0503710 2005-04-13
PCT/FR2006/050324 WO2006108989A2 (fr) 2005-04-13 2006-04-10 Procede de lutte contre l'envoi d'information vocale non sollicitee

Publications (1)

Publication Number Publication Date
EP1869858A2 true EP1869858A2 (de) 2007-12-26

Family

ID=35385313

Family Applications (1)

Application Number Title Priority Date Filing Date
EP06726330A Withdrawn EP1869858A2 (de) 2005-04-13 2006-04-10 Verfahren zur steuerung des sendens unangeforderter voice-informationen

Country Status (4)

Country Link
US (1) US20090034527A1 (de)
EP (1) EP1869858A2 (de)
JP (1) JP2008538470A (de)
WO (1) WO2006108989A2 (de)

Families Citing this family (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20070297337A1 (en) * 2006-06-21 2007-12-27 International Business Machines Corporation Apparatus and methods for determining availability and performance of entities providing services in a distributed system using filtered service consumer feedback
US9100417B2 (en) * 2007-09-12 2015-08-04 Avaya Inc. Multi-node and multi-call state machine profiling for detecting SPIT
US9438641B2 (en) * 2007-09-12 2016-09-06 Avaya Inc. State machine profiling for voice over IP calls
US9736172B2 (en) 2007-09-12 2017-08-15 Avaya Inc. Signature-free intrusion detection
JP2014112884A (ja) * 2008-10-06 2014-06-19 Nec Corp 通信方法及び通信システム
WO2010041761A1 (en) * 2008-10-06 2010-04-15 Nec Corporation Protection against unsolicited communication for internet protocol multimedia subsystem
JP2010114870A (ja) 2008-10-06 2010-05-20 Nec Corp 通信システム及び通信制御方法
US20100135470A1 (en) * 2008-12-01 2010-06-03 At&T Intellectual Property I, L.P. Call impact determination tool
US9705939B2 (en) * 2009-05-20 2017-07-11 Peerless Network, Inc. Self-healing inter-carrier network switch
KR101580185B1 (ko) * 2009-06-29 2015-12-24 삼성전자주식회사 VoIP 서비스에서 스팸 제어 방법 및 장치
CN103490849A (zh) * 2012-06-13 2014-01-01 华为技术有限公司 分析信令流量的方法及装置

Family Cites Families (24)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5649302A (en) * 1994-12-27 1997-07-15 Motorola, Inc. Method and apparatus for identifying an inbound message in a radio communication system
US5740534A (en) * 1996-02-22 1998-04-14 Motorola, Inc. Method for determining available frequencies in selective call receivers
US6834057B1 (en) * 1999-02-12 2004-12-21 Broadcom Corporation Cable modem system with sample and packet synchronization
EP1166540A2 (de) * 1999-04-01 2002-01-02 Callwave Inc. Verfahren und gerät zum bereitstellen von erweiterten telekommunikationsdiensten
US6229794B1 (en) * 1999-08-13 2001-05-08 Motorola, Inc. Selective call device and method for monitoring at least two communication systems
US7707252B1 (en) * 2000-05-12 2010-04-27 Harris Technology, Llc Automatic mail rejection feature
US20020085700A1 (en) * 2000-07-24 2002-07-04 Darrell Metcalf System and method for disconnecting and preventing unwanted telephone calls and for enhancing desired calls
US6819932B2 (en) * 2001-03-05 2004-11-16 Tekelec Methods and systems for preventing delivery of unwanted short message service (SMS) messages
US7257773B1 (en) * 2002-02-14 2007-08-14 Mcafee, Inc. Method and system for identifying unsolicited mail utilizing checksums
US20040203432A1 (en) * 2002-09-27 2004-10-14 Basavaraj Patil Communication system
JP3928866B2 (ja) * 2003-04-18 2007-06-13 日本電信電話株式会社 DoS攻撃元検出方法、DoS攻撃阻止方法、セッション制御装置、ルータ制御装置、プログラムおよびその記録媒体
US20050132197A1 (en) * 2003-05-15 2005-06-16 Art Medlar Method and apparatus for a character-based comparison of documents
US20050020289A1 (en) * 2003-07-24 2005-01-27 Samsung Electronics Co., Ltd. Method for blocking spam messages in a mobile communication terminal
US7835294B2 (en) * 2003-09-03 2010-11-16 Gary Stephen Shuster Message filtering method
US7110779B2 (en) * 2004-01-29 2006-09-19 Harris Corporation Wireless communications system including a wireless device locator and related methods
US7627670B2 (en) * 2004-04-29 2009-12-01 International Business Machines Corporation Method and apparatus for scoring unsolicited e-mail
US7747860B2 (en) * 2004-05-04 2010-06-29 Message Level, Llc System and method for preventing delivery of unsolicited and undesired electronic messages by key generation and comparison
US20050249195A1 (en) * 2004-05-07 2005-11-10 Anita Simpson Methods, systems and computer program products for handling multiple incoming calls simultaneously using central office voice over network (co_von)
US7307997B2 (en) * 2004-05-21 2007-12-11 Alcatel Lucent Detection and mitigation of unwanted bulk calls (spam) in VoIP networks
US20060020993A1 (en) * 2004-07-21 2006-01-26 Hannum Sandra A Advanced set top terminal having a call management feature
US20060026242A1 (en) * 2004-07-30 2006-02-02 Wireless Services Corp Messaging spam detection
US7239866B2 (en) * 2004-12-21 2007-07-03 Lucent Technologies Inc. Spam checking for internetwork messages
US8385516B2 (en) * 2005-04-29 2013-02-26 Eclips, Inc. Ringback blocking and replacement system
US20070011731A1 (en) * 2005-06-30 2007-01-11 Nokia Corporation Method, system & computer program product for discovering characteristics of middleboxes

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See references of WO2006108989A3 *

Also Published As

Publication number Publication date
JP2008538470A (ja) 2008-10-23
WO2006108989A3 (fr) 2007-02-15
WO2006108989A2 (fr) 2006-10-19
US20090034527A1 (en) 2009-02-05

Similar Documents

Publication Publication Date Title
US9531782B2 (en) Dynamic management of collaboration sessions using real-time text analytics
US20130287029A1 (en) Preventing illicit communications
EP1931105A1 (de) Verfahren und System zur Steuerung von Multimedia-Sessions, mit deren Hilfe sich der Aufbau der Kommunikationskanäle kontrollieren lässt
EP3085065B1 (de) Verfahren zur aktualisierung der von einem dns server erhaltenen informationen.
EP1944930A2 (de) Signalisierungsverfahren, das die Berücksichtigung des Grundes des Anrufs erlaubt
EP1869858A2 (de) Verfahren zur steuerung des sendens unangeforderter voice-informationen
EP2606626B1 (de) Verarbeitung einer kommunikationsübergabe in einem sip-modus
Nassar et al. VoIP honeypot architecture
FR2934451A1 (fr) Etablissement et controle d'appel par equipement tiers.
EP1894350B1 (de) Sicherung der ip-telefonie
EP3560168B1 (de) Klassifizierung und routing von steuerungsnachrichten für eine kommunikationsinfrastruktur
US20020196923A1 (en) System and method of call processing
WO2020128258A1 (fr) Procédé de basculement d'une communication de tcp sur udp
FR3081655A1 (fr) Procede de traitement de messages par un dispositif d'un reseau de voix sur ip
EP3804253B1 (de) Verfahren zur aktualisierung einer datenbank eines voice-over-ip-netzwerks
EP4409864A1 (de) Verfahren und vorrichtung zur steuerung des zugriffs auf einen anwendungsdienst
EP3391615B1 (de) Verfahren zur kommunikation zwischen einem anrufenden endgerät und einer vielzahl angerufener endgeräte
EP2100430B1 (de) Telekommunikationsverfahren und System mit Zugang zum selben Informationssatz für mindestens zwei verschiedene Benutzer
WO2007077402A2 (fr) Procede et dispositif de gestion des communications personnelles d'au moins un utilisateur
WO2006090083A1 (fr) Procede de securisation d'un reseau de communication audiovisuelle
WO2012072942A2 (fr) Procede contre la formation de boucles dans les renvois d'appel
Singh et al. A study on methodology on VoIP-based communication investigation through network packet analysis
Khoshbakhtian et al. Comparative Analysis of IMP services
EP2541864A1 (de) Kommunikationsschnittstelle zwischen Videokameras und einem Multimedia-Subsystem
Rüger et al. A spit avoidance workflow for sip-provider

Legal Events

Date Code Title Description
PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

17P Request for examination filed

Effective date: 20071005

AK Designated contracting states

Kind code of ref document: A2

Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LI LT LU LV MC NL PL PT RO SE SI SK TR

DAX Request for extension of the european patent (deleted)
17Q First examination report despatched

Effective date: 20110920

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN

18D Application deemed to be withdrawn

Effective date: 20120131