摘要:
The invention refers to a method for preventing attacks on a network server (3) within a call-based-services-environment, preferably a VoIP-environment. The environment comprises a network (1), the network server (3) connected to the network (1), a number of user agents (2) connected to the network (1) and means (4) for restricting access to the network server (3) from the network (1). The call server (3) comprises an attack-detection device (8) for detecting and identifying attacks from the network (1) on the network server (3). In order to allow fast and reliable protection of the network server (3) against attacks it is suggested that
characteristic parameters of the attacks identified are entered into a black-list (6), the content of the black-list (6) is transmitted via a feedback-path (7) to an attack-prevention-device (5) for controlling the access restricting means (4), the attack-prevention-device (5) inspects and analyzes traffic directed from the network (1) to the network server (3) and controls the access restricting means (4) according to the content of the black-list (6) and according to the characteristic parameters of the traffic analyzed, and the access restricting means (4) restrict access from the network (1) to the network server (3) according to control commands received from the attack-prevention-device (5).
摘要:
Verfahren zum Zusenden von digitalen Kopien geschützter Medien unter Einsatz von empfängerindividuellen digitalen Wasserzeichen von einem Medienserver (1) über ein Telekommunikationsnetz (2) und eine Netzzugangseinrichtung (3, 4) mit Anschlußeinrichtungen an ein Endteilnehmergerät (5-8), bei dem eine digitale Kopie, die an ein bestimmtes Endteilnehmergerät (5-8) des Telekommunikationsnetzes (2) gesendet werden soll in derjenigen Netzzugangseinrichtung (3, 4) zur Verfügung gestellt wird, von der aus das Endteilnehmergerät (5-8) an das Telekommunikationsnetz (2) angeschlossen ist, bei dem die mit dem digitalen Wasserzeichen versehene digitale Kopie über diejenige Anschlußeinrichtung der Netzzugangseinrichtung (3, 4) an das Endteilnehmergerät (5-8) abgesendet wird, über die dieses Endteilnehmergerät (5-8) angeschlossen ist, wobei das digitale Wasserzeichen in dieser Netzzugangseinrichtung (3, 4) in die zu sendende digitale Kopie eingeprägt wird, wobei das digitale Wasserzeichen mindestens Angaben enthält, die der Identifizierung desjenigen Endteilnehmers dienen, an den die digitale Kopie gesendet werden soll.
摘要:
The invention relates to a protection unit (15) for protecting a packet-based network from attacks, comprising: a signature analyzer (5) for analyzing a packet stream (6) received in a security border node (2a) of the packet-based network (1) and for detecting attacks by comparing signatures of the packet stream (6) with a set of signatures of previously identified attacks, an anomaly detector, in particular a statistical analyzer (7), for detecting anomalies in the packet stream (6), and a signature interference unit (9) for updating the set of signatures when anomalies in the packet stream (6) are detected, the updated set of signatures (12) being subsequently used for performing the signature analysis. A distribution unit (13) distributes at least one signature of the updated set of signatures (12) to at least one further, preferably to each further security border node of the packet-based network (1). The invention also relates to a security border node comprising such a protection unit, to a network comprising at least two such protection units, and to a corresponding protection method.
摘要:
The present invention relates to a method of determining a location of a base station (10) in a wireless communication network (100). The method comprises the step of using the environment (50) of the wireless communication network (100) local to the base station (10) to obtain location information of said base station (10). The invention further relates to a base station in a wireless communication network for performing said method.
摘要:
A method for supporting mobility of at least one mobile telecommunications terminal (5.1-5.3) in operative connection with a telecommunications network (2) having a plurality of telecommunications resources (3.1-3.6) accessible via a plurality of access networks (4.1-4.3) and associated access technologies (4.1a,b-4.3a,b) in operative connection with the telecommunications network (2), wherein the mobile telecommunications terminal (5.1-5.3) is provided with information about access networks (4.1-4.3) and access technologies (4.1a,b-4.3a,b) available at least at its present geographic location for choosing an access to the telecommunications network (2) via one of the respective access networks (4.1-4.3) and associated access technologies (4.1a,b-4.3a,b) in accordance with specifications of at least one telecommunications resource (3.1-3.6) requested by the mobile telecommunications terminal (5.1-5.3), and wherein the information are provided independently of the access networks (4.1-4.3) by means of a mobility service broker system (6) in operative connection with a plurality of access networks (4.1-4.3). Introduction of an operator independent broker system (6) leads to considerable advantages on the subscriber terminal side, e.g. for reasons of pricing and by limiting power consumption of the mobile telecommunications terminal (5.1-5.3).
摘要:
A method for seamless handover of a multimedia stream session to a roaming terminal (4). In accordance with the proposed method, a first mediating network element (8.1) is comprised in a communication path to the roaming terminal (4). Said first mediating network element (8.1) first secures a session context of the multimedia stream session for to allow identification of the roaming terminal. Said first mediating network element (8.1) then observes an address change of the roaming terminal on a media overlay level of the multimedia stream session and subsequently redirects the multimedia stream to the new address. Then, alternative mediating network elements (8.2, 8.3) for replacing the first mediating network element (8.1) are determined on a control level of the network (1). In this way, a complete handover of the multimedia stream session is achieved in a seamless way for an end-user owing to a cross-layer approach, while bridging a timeframe between the event of changing the terminal address and an event of having completed re-registration and session redirection on the control level of the network.
摘要:
The invention relates to a network node (R2, D2), a module therefor and a distribution method. The network node comprises: - receiving means (RB) for receiving a data stream (CDS) from a content source, in particular a content server (CS), of the network (NET), - encryption means (EM) for individually encrypting said data stream to a subscriber data stream (SDS1, SDS2, SDS3), the encryption being specific to a subscriber terminal (T1, T2, T3) being coupled or able to be coupled with the network, and - sending means (SM) for sending the subscriber data stream (SDS1, SDS2, SDS3) to the terminal.
摘要:
The invention relates to a method for providing location information relating to an emergency call, in which when there exists differing location information (Form 1, Form 2, ..., Form m), a weighting is made of any available location information and that the location information (Form 2) with the highest ranking is provided for further use, as well as a telecommunications terminal, a server and a computer program product.
摘要:
Die Erfindung betrifft ein Verfahren zum Erbringen eines Dienstes oder einer Anwendung in einer Netzwerkumgebung mit Netzwerkelementen, die ein Telekommunikationsnetz (NW1) beinhaltet, das mindestens zwei Netzwerkknoten (GW1-GW5) zum Erbringen von Diensten oder Anwendungen aufweist, die alle mit einer gemeinsamen Schicht zur Dienstunterstützung ausgestattet sind, wobei, wenn ein bestimmter Netzwerkknoten (GW1-GW5) nicht derart ausgestattet ist, daß er einen bestimmten Dienst oder eine bestimmte Anwendung erbringen kann, dieser Netzwerkknoten (GW1-GW5) mit Hilfe der Schicht zur Dienstunterstützung überprüft, ob ein anderer Netzwerkknoten (GW1-GW5) diesen Dienst oder diese Anwendung erbringen kann und wenn der andere Netzwerkknoten (GW1-GW5) diesen Dienst oder diese Anwendung erbringen kann, der erste Netzwerkknoten (GW1-GW5) die Aufgabe zur Erbringung dieses Dienstes oder dieser Anwendung an den anderen Netzwerkknoten (GW1-GW5) übergibt, der diesen Dienst oder diese Anwendung anschließend erbringt, sowie ein Telekommunikationsnetz und Netzwerkknoten hierfür.