Use Case

Screening Call Floods Before They Overwhelm You with TDoS Protection

The Challenge

A telephony denial-of-service attack does not try to crash a server. It ties up the phones. When bad actors flood a business or service provider with unwanted calls, the agents and staff who answer them are overwhelmed, and legitimate callers cannot get through.

The damage is done at the level of who is answering the phone. Each individual call may be a perfectly valid SIP call; the harm is in the sheer number arriving at once. These attacks can come from extortion attempts, malfunctioning dialers, or illegal robocall campaigns, but the effect is the same regardless of intent. That is different from a protocol-level attack on the SIP infrastructure, which is covered separately in the guide to SIP denial-of-service attack prevention.

The Solution

How Reputation-Based Screening Stops It

Because each flooding call can look valid on its own, stopping TDoS means judging calls against intelligence about the numbers behind them. The session border controller provides the control point, and a reputation or analytics service provides the judgment.

When the SBC receives a call, it forwards the invitation to the analytics platform, which determines whether the call is good, bad, or suspicious based on reputation and analytics gathered across many networks. The SBC then acts on that determination through call disposition: the call can be blocked, redirected to voicemail, or allowed through to the customer. The worst offenders are screened out before they ever reach an agent, while legitimate calls pass through normally.

TDoS protection topology: flooding calls arrive at the ProSBC, which checks each with a reputation service and blocks, redirects to voicemail, or allows the call to the business

TDoS protection: flooding calls arrive at the SBC, which checks each against a reputation or analytics service and then blocks, redirects, or allows the call through. Click to enlarge.

Key Capabilities

What the SBC Does for TDoS Protection

Receiving and Forwarding for Scoring

Every call, including the flood, arrives at the SBC over its SIP or TDM trunks. For each one, the SBC forwards the call’s details to the reputation or analytics service and waits for the determination, so the judgment is made before the call reaches an agent.

Enforcing the Disposition

Based on the score it gets back, the SBC blocks a bad call outright, redirects a suspicious one to voicemail so a human can judge it later, or lets a good one through. This three-way disposition does not force a simple allow-or-block choice on uncertain calls.

Working Within the Security Edge

TDoS screening runs alongside the SBC’s other protections at the boundary, including access control and layered security. A business gets call-flood defense as part of a defended edge rather than a separate appliance.

Deployment Options

Deploy It Your Way

TDoS protection can be operated in whatever model suits the business or provider:

Self-Managed

Run ProSBC as software on your own infrastructure and configure the reputation-service integration directly. Full control over scoring policies and call disposition rules.

Managed Service

Hand deployment and operation to TelcoBridges through the ProSBC managed service. The screening integration is set up and monitored so attacks are caught and handled rather than discovered by customers.

Fully Hosted

TelcoBridges hosts and manages the SBC entirely. A business under attack gets screening set up and monitored without building the integration itself.

FAQ

Frequently Asked Questions

What is TDoS protection?

It is the use of an SBC together with a reputation or analytics service to evaluate flooding calls as they arrive and block, redirect, or allow each one based on its risk. It defends against unwanted call volume aimed at overwhelming a business, as opposed to protocol-level network attacks.

How is TDoS different from a SIP DoS attack?

TDoS is an attack by volume of calls that can each look legitimate, aimed at tying up agents and lines. A SIP DoS attack targets the SIP infrastructure itself at the protocol level. TDoS is judged by which calls to answer; SIP DoS is defended at the network layer. The two are related but distinct.

How does the SBC decide what to do with a flooding call?

The SBC forwards each call to a cloud reputation or analytics service, which scores it as good, bad, or suspicious. The SBC then applies a disposition: block the bad call, redirect the suspicious one to voicemail, or allow the good one through to the customer.

Are TDoS attacks always deliberate?

No. They can be deliberate, such as extortion attempts, but they can also be accidental, caused by malfunctioning dialers or illegal robocall campaigns spilling onto a target. The screening approach handles both, because it judges calls by risk regardless of the intent behind the flood.

Screen Out Call Floods with ProSBC

Talk to a solutions architect about deploying TDoS protection with ProSBC, or start evaluating on your own.

Prefer to evaluate on your own first? Start your 30-day free trial.