Low latency content disambiguation and reconstruction (CDR) for live streaming video
By decoding, extracting, and adjusting encoded information, the problem of malicious proxies in encoded video streams was solved, achieving low-latency and high-efficiency video stream transmission and enhancing network security.
Patent Information
- Application Number
- CN202080021868.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-03-17
- Filing Date
- 2020-03-12
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2040-03-12
AI Technical Summary
Existing technologies are insufficient to effectively eliminate and reconstruct malicious proxies lurking in encoded video streams, leading to cybersecurity threats, especially excessive latency and computational resource consumption in live video streaming.
By decoding, extracting, and adjusting the encoded information, replacing the quantization parameters with randomly selected quantization parameters, and re-encoding the video stream to produce a modified encoded video stream, computational resource consumption is reduced and unpredictability is improved, preventing the injection of malicious proxies.
It significantly reduces the latency of encoded video stream transmission, lowers the computational resource requirements, and renders malicious proxies ineffective, thereby improving the immunity of secure networks.
Smart Images

Figure CN113614724B_ABST
Abstract
Description
BACKGROUND
[0001] The present invention, in some embodiments thereof, relates to CDR (Content Disarm and Reconstruction) of encoded video streams, and, more specifically, but not exclusively, to low-latency CDR of streaming of encoded live video streams using encoded information extracted from the encoded video and adjusted to produce a modified encoded video stream.
[0002] The increasing reliance of modern life services, applications, systems and platforms on information technology, information sharing and distributed computing has opened a wide array of avenues for network threats and cyber attacks initiated by malicious parties (e.g., hackers) to attempt to expose, alter, disable, destroy, steal, gain unauthorized access to, or exploit unauthorized use of such information and computer resources.
[0003] Accordingly, cyber security has become a major challenge and a constant competition between malicious parties that design malicious cyber attacks and cyber security efforts that develop and deploy countermeasures to identify, block and / or neutralize these malicious cyber attacks.
[0004] As part of cyber security efforts, many methods, techniques and tools have been developed to concentrate and exploit different aspects and features of cyber threats. However, as the nature, footprint, type, pattern, characteristics, effects and / or operational modes of cyber threats are constantly changing, the cyber security challenge persists. SUMMARY
[0005] According to a first aspect of the present invention there is provided a method of disarming and reconstructing an encoded video stream to neutralize malicious agents potentially embedded in the encoded video stream, comprising using one or more processors for:
[0006] - decoding a received encoded video stream to obtain a decoded video stream.
[0007] - extracting from the encoded video stream encoded information computed by an initiating encoder to create the encoded video stream.
[0008] - adjusting the encoded information by replacing one or more quantization parameters defined in the encoded information with respective adjusted quantization parameters computed based on randomly selected values from a range of quantization parameter values.
[0009] - encoding the decoded video stream using the adjusted encoded information to produce a modified encoded video stream.
[0010] - transmitting the modified encoded video stream.
[0011] According to a second aspect of the application, there is provided a system for neutralizing and reconstructing an encoded video stream to invalidate a malicious agent potentially embedded in the encoded video stream, comprising one or more processors executing code. The code comprises:
[0012] - encoding instructions for decoding a received encoded video stream to obtain a decoded video stream.
[0013] - instructions to encode to extract from the encoded video stream the encoding information computed by the originating encoder to create the encoded video stream.
[0014] - instructions to adjust the encoding information by replacing one or more quantization parameters defined in the encoding information with respective adjusted quantization parameters computed based on a randomly selected value from a range of quantization parameter values.
[0015] - encoding instructions to encode the decoded video stream using the adjusted encoding information to produce a modified encoded video stream.
[0016] - instructions to encode for transmission the modified encoded video stream.
[0017] According to a third aspect of the application, there is provided a computer program product for neutralizing and reconstructing an encoded video stream to invalidate a malicious agent potentially embedded in the encoded video stream, comprising:
[0018] - a non-transitory computer-readable storage medium.
[0019] - first program instructions for decoding a received encoded video stream to obtain a decoded video stream.
[0020] - second program instructions for extracting from the encoded video stream the encoding information computed by the originating encoder to create the encoded video stream.
[0021] - third program instructions for adjusting the encoding information by replacing one or more quantization parameters defined in the encoding information with respective adjusted quantization parameters computed based on a randomly selected value from a range of quantization parameter values.
[0022] - fourth program instructions for encoding the decoded video stream using the adjusted encoding information to produce a modified encoded video stream.
[0023] - fifth program instructions for transmitting the modified encoded video stream.
[0024] wherein the first, second, third, fourth and fifth program instructions are executed by one or more processors from the non-transitory computer-readable storage medium.
[0025] In a further implementation form of the first, second and / or third aspect, the received encoded video stream is extracted from a transport stream that encapsulates the received encoded video stream.
[0026] In a further implementation form of the first, second and / or third aspect, the modified encoded video stream is encapsulated in an output transport stream.
[0027] In a further implementation form of the first, second and / or third aspect, the encoded video stream is a live encoded video stream depicting a live event.
[0028] In a further implementation form of the first, second and / or third aspect, the encoded video stream is encoded according to a video encoding protocol, such as MPEG-1, MPEG-2, MPEG-4, H.261, H.263, H.264 and H.265.
[0029] In a further implementation form of the first, second and / or third aspect, the encoding information comprises motion vectors, quantization parameters and macroblock types generated by the originating encoder for a plurality of frames encoded in the encoded video stream.
[0030] In a further implementation form of the first, second and / or third aspect, the adjusted quantization parameter value of the respective quantization is equal to or lower than the quantization parameter value of the respective quantization parameter.
[0031] Other systems, methods, features, and advantages of the present disclosure will be or become apparent to one with skill in the art upon examination of the following drawings and detailed description. It is intended that all such additional systems, methods, features, and advantages be included within this description, be within the scope of the present disclosure, and be protected by the accompanying claims.
[0032] Unless otherwise defined, all technical and / or scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the application pertains. Although methods and materials similar or equivalent to those described herein can be used in the practice or testing of embodiments of the application, exemplary methods and / or materials are described below. In case of conflict, the patent specification, including definitions, will control. In addition, the materials, methods, and examples are illustrative only and are not intended to be necessarily limiting.
[0033] Implementation of the method and / or system of embodiments of the application can involve performing or completing selected tasks manually, automatically, or a combination thereof. Moreover, according to actual instrumentation and equipment of embodiments of the method and / or system of the application, several selected tasks could be implemented by hardware, by software or firmware or by a combination thereof to achieve the techniques and / or
[0034] For example, hardware for performing selected tasks according to embodiments of the application could be implemented as a chip or a circuit. As software, selected tasks according to embodiments of the application could be implemented as a plurality of software instructions being executed by a computer using any suitable operating system. In an exemplary embodiment of the application, one or more tasks according to exemplary embodiments of method and / or system as described herein are performed by a data processor, such as a computing platform for executing a plurality of instructions. Optionally, the data processor includes a volatile memory for storing instructions and / or data and / or a non-volatile storage, for example, a magnetic hard-disk and / or removable media. Optionally, a network connection is provided as well. A display and / or a user input device such as a keyboard or mouse are optionally provided as well. BRIEF DESCRIPTION OF DRAWINGS
[0035] Some embodiments of the application are herein described, by way of example only, with reference to the accompanying drawings. With specific reference now to the drawings in detail, it is stressed that the particulars shown are by way of example and for purposes of illustrative discussion of embodiments of the application. In this regard, the description taken with the drawings makes apparent to those skilled in the art how embodiments of the application can be performed.
[0036] In the drawings:
[0037] Figure 1 is a flowchart of an exemplary process of eliminating and reconstructing an encoded video stream to neutralize a malicious agent potentially embedded in the encoded video stream, in accordance with some embodiments of the application; and
[0038] Figure 2 is a schematic diagram of an exemplary system for eliminating and reconstructing an encoded video stream to neutralize a malicious agent potentially embedded in the encoded video stream, in accordance with some embodiments of the application. DETAILED DESCRIPTION
[0039] The present application, in some embodiments thereof, relates to CDR of encoded video streams and, more specifically, but not exclusively, to low-latency CDR of encoded live video streams using encoded information extracted from the encoded video and adjusted to produce a modified encoded video stream for streaming.
[0040] According to some embodiments of the application, there are provided methods, systems and computer program products for content disarming and reconstruction (CDR) of a received encoded video stream to neutralize a malicious agent potentially embedded in the encoded video stream comprising a sequence of frames encoded according to one or more encoding protocols (e.g., MPEG-1, MPEG-2, MPEG-4, H.261, H.263, H.264, H.265, etc.).
[0041] In particular, the CDR is intended to increase the immunity of a secure (internal) network (e.g., a private network, a corporate network, an organizational network, a factory network, an institutional network, etc.) to network threats originating from an external untrusted network (e.g., the Internet). As such, the CDR of the received encoded video stream can be applied by one or more access systems and / or devices (e.g., gateways, routers, proxy servers, etc. that act as a gate between the secure (internal) network and the external untrusted network).
[0042] As the encoded video stream is received from an untrusted network, one or more malicious program components (e.g., viruses, worms, Trojan horses, malicious agents, ransomware, spyware, adware, scareware, etc.) can potentially reside in the received (incoming) encoded video stream. Such malicious program components can be configured to expose, alter, disable, destroy, steal, gain unauthorized access to, and / or exploit unauthorized use of resources in the secure network.
[0043] During the CDR process, the received encoded video stream is first decoded to decode the encoded video, and then the decoded video is reconstructed, i.e., re-encoded according to the original encoding protocol to produce an output encoded video stream that can be modified compared to the received encoded video stream. As the video is decoded and then re-encoded, any redundant components, particularly any malicious program components that are added, injected, and / or reside in the received encoded video stream, can be removed or at least altered to the extent that the malicious program components are rendered ineffective, thereby preventing malicious operations of the malicious program components.
[0044] Decoding the incoming encoded video stream can be relatively simple, thus consuming limited computational resources, such as, for example, processing power, processing time, storage resources, etc. However, re-encoding the decoded video to produce the output encoded video stream can require a significant amount of computational resources, as the encoding protocol applied to compress the video stream while maintaining high video quality can be extremely resource-consuming.
[0045] Compression of video streams is primarily based on reducing spatial and temporal redundancies between subsequent frames of the video stream. To identify and exploit this redundancy, advanced motion estimation techniques are applied to calculate encoding information (e.g., motion vectors, quantization parameters, macroblock types, etc.) to produce the encoded video stream. Motion estimation involves complex image processing and motion prediction algorithms that can require a significant amount of computational resources, e.g., processing power, processing time, storage resources, etc., that can further result in a significant amount of power consumption.
[0046] Thus, to reduce the computational resources required to re-encode the video stream to produce the output encoded video stream, the encoding information computed by the initiating encoder that encoded the received (input) encoded video stream can be extracted from the input encoded video stream and used to produce the output encoded video stream. Thus, during the CDR process, no motion estimation computations are performed to produce the output encoded video stream, but rather the output encoded video stream is produced (encoded) using the encoding information computed by the initiating encoder.
[0047] In particular, generating the output encoded video stream using the extracted encoding information can significantly reduce the CDR time, thereby significantly reducing the latency from the time the input encoded video stream is received to the time the output encoded video stream is transmitted. This can be particularly important in the case that the encoded video stream is a live streamed video stream that depicts a live event.
[0048] However, a malicious party (human and / or automated) can be able to predict the structure of the reconstructed output encoded video stream and can inject the malicious program component(s) in a manner that can allow one or more of these malicious program components to withstand (survive) the CDR process and maintain its malicious functionality in the output encoded video stream.
[0049] To prevent such exploitation, the encoding information extracted from the input encoded video stream can be adjusted prior to being used to produce (encode) the output encoded video stream, which can be modified compared to the received encoded video stream. In particular, the encoding information can be adjusted by replacing one or more of the quantization parameters defined in the encoding information with adjusted quantization parameters. To ensure the unpredictability of the structure and / or patterns of the modified encoded video stream, the adjusted quantization parameter(s) can be computed based on randomly selecting values from a range and / or group of quantization parameter values. The randomly and unpredictably modified structure and / or patterns of the modified encoded video stream can thus prevent a malicious party from injecting malicious program components that can withstand the CDR process or at least render such injection attempts ineffective.
[0050] After adjustment, the output encoded video stream is produced (encoded) using the adjusted encoding information, which is thus modified from the input (received) encoded video stream. The modified encoded video stream can then be transmitted, distributed, and / or provided to one or more decoding clients connected to a secure network, e.g., servers, network nodes, compute nodes, computers, smartphones, etc.
[0051] The quantization parameter is directly related to the quantization step, which defines the sampling rate and the sample number used to sample the frames in the encoded video stream. Thus, the quantization step influences the quality of the encoded video stream with respect to the bit rate of the encoded video stream. The quantization step is inversely proportional to the quality, since the sample rate and number are translated into quality, such that the lower the quantization step the higher the video quality, and vice versa, the higher the quantization step, the lower the quality. However, the sample rate and number are also translated into bit rate, and the quantization step is inversely proportional to the bit rate of the encoded video, such that the lower the quantization step the higher the bit rate, and vice versa, the higher the quantization step, the lower the bit rate.
[0052] In order to maintain the video quality and prevent degradation of the output (and possibly modified) encoded video stream compared to the input encoded video stream, the adjusted quantization parameter is randomly selected to be equal to or lower than the original quantization parameter defined in the encoded information extracted from the input encoded video stream. Since the adjusted quantization parameter is equal to or lower than the original quantization parameter, the corresponding quantization step of the modified video stream is also lower, resulting in no quality drop of the modified video stream compared to the originally received encoded video stream.
[0053] It should be emphasized that the use of the adjusted encoded information to produce (encode) the modified encoded video stream is transparent to any decoder complying with the encoding protocol, allowing the decoder to decode the modified video stream similarly to what is done for the originally encoded video stream.
[0054] The application of CDR based on adjusted encoded information can present significant advantages and benefits compared to existing CDR and / or network security methods and systems.
[0055] First, the CDR based on adjusted encoded information can remove or at least alter the structure of unknown malicious program components, which can or can not reside in the encoded video stream and can have unknown footprint, pattern, characteristics, effects, mode of operation, etc. Thus, the CDR does not have to be designed and / or trained to identify known network threats, i.e. known malicious program components, which can be done by some network security methods. Moreover, the number of such malicious program components can be extremely high, resulting in extensive utilization of computing resources and / or delay in delivering the received encoded video stream to clients on a secure network. On the other hand, the CDR based on adjusted encoded information does not process the encoded video stream to identify known malicious program components, and can thus deliver the encoded video stream to secure network clients using significantly reduced computing resources and imposing significantly reduced delay. While low delay encoded video delivery can provide a major advantage for any video stream, the low delay can be more advantageous when delivering encoded real-time video streams, where the transmission delay can significantly reduce user experience, etc.
[0056] Furthermore, some existing CDR methods can decode a received encoded video stream and then encode the decoded video to produce an output encoded video stream. As described earlier herein, encoding the decoded video can require a large amount of computational resources, which can potentially result in a significant delay due to complex and resource-intensive motion prediction algorithms applied to compute the encoding information of the encoded video stream. Thus, existing CDR methods can require a large amount of computational resources to reconstruct the output encoded video stream, and can often cause significant delay in transmitting the output encoded video stream to a secure network client. On the other hand, CDR based on adjusted encoding information does not perform any motion estimation computation for computing the encoding information, but instead uses the encoding information based on the original encoding information computed by the original encoder and extracted from the received encoded video stream. CDR based on adjusted encoding information can thus significantly reduce the computational resources for reconstructing the output encoded video stream. As a result of the reduced computation time, using CDR based on adjusted encoding information can also significantly reduce the delay in delivering the received encoded video stream to a secure network client.
[0057] Furthermore, as CDR based on adjusted encoding information is based on randomly adjusting the encoding information and using it to create a modified encoded video stream, the modified encoded video stream can have a random and unpredictable structure and / or pattern. A malicious party can not be able to predict the structure and / or pattern of the modified encoded video stream, and thus can not be able to design a malicious program component that would survive the CDR process based on adjusted encoding information when residing in the encoded video stream.
[0058] Before one or more embodiments of the application are explained in detail, it is to be understood that the application is not limited in its application to the details of construction and the
[0059] As will be appreciated by one of skill in the art, aspects of the present application can be embodied as a system, method, or computer program product. Accordingly, aspects of the present application can take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, micro-code, etc.) or an embodiment combining software and hardware aspects that can all generally be referred to herein as a "circuit," "module" or "system." Furthermore, aspects of the present application can take the form of a computer program product embodied in one or more computer readable medium(s) having computer readable program code embodied thereon.
[0060] Any combination of one or more computer readable medium can be utilized. The computer readable storage medium can be a tangible device that can retain and store instructions for use by an instruction execution device. The computer readable medium can be a computer readable signal medium or a computer readable storage medium. A computer readable storage medium can be, for example but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer readable storage medium include the following: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In the context of this document, a computer readable storage medium can be any tangible medium that can contain, or store a program for use by or in connection with an instruction execution system, apparatus, or device.
[0061] A computer readable signal medium can include a propagated data signal with computer readable program code embodied therein, for example, in baseband or as part of a carrier wave. Such a propagated signal can take any of a variety of forms, including, but not limited to, electro-magnetic, optical, or any suitable combination thereof. A computer readable signal medium can be any computer readable medium that is not a computer readable storage medium and that can communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device.
[0062] Program code embodied on a computer readable medium can be transmitted using any appropriate medium, including but not limited to wireless, wire line, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0063] Computer program code for carrying out operations of the present application can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages.
[0064] The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer, or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider). The program code can be downloaded to the respective computing / processing device from a computer-readable storage medium, or to an external computer or external storage device from the network (for example, the Internet, a local area network, a wide area network and / or a wireless network).
[0065] The computer program instructions can also be loaded onto a computer or other programmable information processing apparatus to cause a series of operations to be performed on the computer or other programmable information processing apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable information processing apparatus implement the functions / acts specified in the flowchart and / or block diagram block or blocks.
[0066] The computer program instructions can also be loaded onto a computer or other programmable information processing apparatus to cause a series of operations to be performed on the computer or other programmable information processing apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable information processing apparatus implement the functions / acts specified in the flowchart and / or block diagram block or blocks.
[0067] Referring now to the drawings, Figure 1 is a flowchart of an exemplary process of disarming and reconfiguring an encoded video stream to neutralize a malicious agent potentially embedded in the encoded video stream in accordance with some embodiments of the present application. The exemplary process 100 can be performed to apply a CDR to an encoded video stream received from an untrusted (external) source in order to increase the immunity of a secure (internal) network to network threats originating from one or more malicious program components that can potentially reside in the received encoded video stream prior to transmission of the encoded video stream to a client of the secure network.
[0068] See also Figure 2 , Figure 2is a schematic illustration of an exemplary system for eliminating and reconstructing an encoded video stream to neutralize a malicious agent potentially embedded in the encoded video stream in accordance with some embodiments of the present application. An exemplary content elimination and reconstruction (CDR) system 200 (e.g., a computer, a server, a compute node, a cluster of compute nodes, etc.) can perform processes such as process 100 for eliminating and reconstructing an input encoded video stream 202 and reconstructing a decoded video to produce an output encoded video stream 204.
[0069] Input encoded video stream 202 is encoded in accordance with one or more encoding protocols (e.g., MPEG-1, MPEG-2, MPEG-4, H.261, H.263, H.264, H.265, etc.) including a sequence of frames. Input encoded video stream 202 can be a live streamed video stream depicting a live event (e.g., a sporting event, a concert, a live performance, a public performance, etc.) currently in progress.
[0070] In particular, CDR system 200 can be implemented in one or more access systems and / or devices, e.g., a gateway, a router, a proxy server, etc., used as a gate between secure (internal) networks 240, e.g., a private network, a corporate network, an organizational network, a factory network, an institutional network, etc., and external untrusted networks 242, e.g., the Internet.
[0071] CDR system 200 can include a network interface 210 for receiving input encoded video stream 202 and transmitting output encoded video stream 204, a processor 212 for performing process 100, and a storage 214 for storing code and / or data.
[0072] Network interface 210 can include one or more network interfaces for connecting to one or more wired and / or wireless networks, e.g., a local area network (LAN), a wide area network (WAN), a metropolitan area network (MAN), a cellular network, the Internet, etc., to facilitate communication with one or more network nodes connected to secure networks 240 and for communicating with one or more remote resources connected to untrusted networks 242.
[0073] Processor 212 includes one or more processors, homogeneous or heterogeneous, each including one or more processing nodes arranged for parallel processing, as clusters and / or as one or more multi-core processors. Processor 212 can further contain one or more hardware-specific components, e.g., an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), a digital signal processor (DSP), a graphics processor unit (GPU), a network processor, etc., to support execution of process 100.
[0074] The memory 214 for storing data and / or program code can include one or more non-transitory memory devices, persistent non-volatile devices, e.g., hard drives, solid state drives (SSDs), disks, flash memory arrays, etc., and / or volatile devices, e.g., random access memory (RAM) devices, cache memory, etc. The memory 214 can further include one or more network storage resources, e.g., storage servers, network attached storage (NAS), network drives, etc., accessible via the network interface 210 over one or more networks.
[0075] The processor 212 can execute one or more software modules, e.g., processes, applications, agents, utilities, tools, scripts, operating systems (OS), etc., each including a plurality of program instructions stored in a non-transitory medium, such as the memory 214, and executed by one or more processors, such as the processing circuit 212.
[0076] The processor 212 can execute one or more functional modules, which can be implemented by one or more of the software modules, one or more of the hardware-specific components, and / or a combination thereof. The functional modules can include, for example, a de-multiplexing 220, a decoding module 222, an encoding information extraction module 224, a quantization parameter calculation module 226, an encoding module 228, a multiplexing module 230, etc.
[0077] The de-multiplexing module 220 can be configured to receive the input encoded video stream 202 from the untrusted network 242 via the network interface 210. The input encoded video stream 202 can be typically encapsulated in an input transport stream, which is a standard digital container format typically used in broadcast systems for the transmission and storage of audio, video, and program and system information protocol (PSIP) data. Accordingly, the de-multiplexing module 220 can be configured to de-multiplex the input transport stream and extract the encapsulated input encoded video stream 202.
[0078] The decoding module 222 can be configured to decode the input encoded video stream 202 extracted from the input transport stream to produce a decoded video stream.
[0079] The encoding information extraction module 224 can be configured to extract from the input encoded video stream 202 the encoding information computed by an originating encoder that encoded and produced the input encoded video stream 202.
[0080] The quantization parameter calculation module 226 can be configured to adjust one or more quantization parameters defined in the extracted encoding information to produce adjusted encoding information.
[0081] Encoding module 228 can be configured to re-encode the video decoded from input encoded video stream 202 using the adjusted encoding information to produce output encoded video stream 204.
[0082] Multiplexing module 220 can be configured to encapsulate output encoded video stream 204 in an output transport stream that can be transmitted via network interface 210 to one or more clients connected to secure network 240.
[0083] As shown at 102, process 100 begins with demultiplexing module 220 receiving input encoded video stream 202 via network interface 210.
[0084] As input encoded video stream 202 is typically received from an untrusted network, one or more malicious program components can potentially reside in input encoded video stream 202, e.g., viruses, worms, Trojan horses, malicious agents, ransomware, spyware, adware, scareware, etc.
[0085] As shown at 104, in the case where input encoded video stream 202 is encapsulated in an input transport stream, demultiplexing module 220 can demultiplex the input transport stream and extract the encapsulated input encoded video stream 202.
[0086] As shown at 106, decoding module 222 can decode input encoded video stream 202 to extract the video stream encoded therein.
[0087] As shown at 108, encoding information extraction module 224 can extract encoding information from input encoded video stream 202. The encoding information computed and generated by the originating encoder that encoded and produced input encoded video stream 202 can include, for example, motion vectors, quantization parameters, macroblock types, etc. of input encoded video stream 202. As described previously herein, the encoding information primarily relates to motion estimation, and thus generating the encoding information involves resource-intensive computations that can require significant computational resources.
[0088] As shown at 110, quantization parameter computation module 226 can adjust the encoding information. In particular, quantization parameter computation module 226 can adjust one or more of the quantization parameters defined in the encoding information of input encoded video stream 202.
[0089] The quantization parameters are directly related to the quantization step size of one or more frames of the encoded video stream, and thus affect the sample rate and number of samples of the video, and thus the quality of the encoded video relative to the bit rate of the encoded video. The quantization step size is inversely proportional to the quality, as the sample rate and number are translated into quality, such that the lower the quantization step size the higher the video quality, and vice versa, the higher the quantization step size the lower the quality. However, the sample rate and number are also translated into bit rate, and the quantization step size is inversely proportional to the bit rate of the encoded video, such that the lower the quantization step size the higher the bit rate, and vice versa, the higher the quantization step size the lower the bit rate.
[0090] The quantization parameter calculation module 226 can adjust one or more of the quantization parameters by replacing one or more of the quantization parameters with a respective adjusted quantization parameter calculated based on a random selection of a quantization parameter value from a range of quantization parameter values. However, the quantization parameter calculation module 226 is configured to calculate the adjusted quantization parameter to be equal to or lower than the original quantization parameter, in order to avoid a degradation in quality of the output encoded video stream 204 compared to the input encoded video stream 202 after re-encoding the video using the adjusted quantization parameter to produce the output encoded video stream 204.
[0091] Optionally, the quantization parameter calculation module 226 is configured to calculate the one or more adjusted quantization parameters under a maximum bit rate constraint, such that the output encoded video stream 204 encoded (produced) using the one or more adjusted quantization parameters will have a bit rate that does not exceed the maximum bit rate.
[0092] For example, assume that the input encoded video stream 202 is encoded according to the H.264 encoding protocol, which defines a range of 0 to 51 for quantization parameters. Assume that the encoded information extracted from the input encoded video stream 202 includes a certain quantization parameter having a value of 15. In this case, the quantization parameter calculation module 226 can calculate a respective adjusted quantization parameter based on a random selection of the respective adjusted quantization parameter from a certain range of quantization parameter values 10-15 that includes a lower quantization parameter value, in order to avoid a degradation in video quality.
[0093] As shown at 112, the encoding module 228 encodes the video decoded from the input encoded video stream 202 to produce the output encoded video stream 204, which can generally be a modified encoded video stream compared to the input encoded video stream 202. However, the encoding module 228 does not perform any motion estimation calculations, but rather uses adjusted encoding information based on the encoding information calculated by the originating encoder that produced the input encoded video stream 202. The encoding module 228 thus requires significantly reduced computational resources to produce (encode) the output encoded video stream 204.
[0094] As shown at 114, the multiplexer 230 can encapsulate the output encoded video stream 204 in an output transport stream.
[0095] As shown at 116, the multiplexer 230 can transmit the output encoded video stream 204, optionally encapsulated in an output transport stream, via the network interface 210. Thus, the output encoded video stream 204 can be transmitted, distributed, and / or communicated to one or more network nodes (clients) connected to the secure network 240. Since the output encoded video stream 204 is encoded according to the same encoding protocol as the original input encoded video stream 202, the CDR process 100 can be transparent to any decoder that complies with the selected encoding protocol. Thus, any decoder that is capable of decoding the input encoded video stream 202 is capable of decoding the output encoded video stream 204.
[0096] It is expected that during the life of a patent maturing from this application many relevant systems, methods and computer programs will be developed and the scope of the terms video encoding protocol and transport stream protocol is intended to include all such new technologies a priori.
[0097] As used herein, the term "about" means ± 10 %.
[0098] The terms "comprising," "containing," "including," "having," and their variations, mean "including but not limited to."
[0099] The term "consisting of means "including and limited to."
[0100] As used herein, the singular forms "a," "an," and "the" include plural reference unless the context clearly dictates otherwise. For example, the term "a compound" or "at least a compound" can include a plurality of compounds, including mixtures thereof.
[0101] In this application, various embodiments of the application can be presented in a range format. It should be understood that the description in range format is merely for convenience and brevity and is to be interpreted -in the context of the specification as a whole. Therefore, the description of a range it should be considered to include all possible subranges and individual numerical values within that range. For example, description of a range such as from 1 to 6 should be considered to include the
[0102] Whenever a numerical range is indicated, it is meant to include any cited numeral (fractional or integral) within the indicated range. The phrases "range / interval between a first indicated number and a second indicated number" and "from [the first indicated number] to [the second indicated number]" are used herein interchangeably and are meant to include the first and second specified numbers and all the fractional and integral
[0103] It should be appreciated that certain features of the application, which are, for clarity, described in the context of separate embodiments, can also be provided in combination in a single embodiment. Conversely, various features of the application, which are, for brevity, described in the context of a single embodiment, can also be provided separately or in any suitable
[0104] Although the application has been described in conjunction with specific embodiments thereof, it is evident that many alternatives, modifications and variations will be apparent to those skilled in the art. Accordingly, it is intended to embrace all such alternatives, modifications and variations as fall within the spirit and broad scope of the appended claims.
[0105] All publications, patents and patent applications mentioned in this specification are herein incorporated by reference in their entirety to the same extent as if each individual publication, patent or patent application was specifically and individually indicated to be incorporated by reference. In addition, citation or identification of any reference in this application shall not be construed as an admission that such reference is available as prior art to the present application. To the extent that section headings are used, they should not be construed as necessarily limiting. In addition, any priority document(s) of this application is / are hereby incorporated by reference in its / their entirety.
Claims
1. A method of nullifying and reconstructing an encoded video stream to neutralize a malicious agent potentially embedded in the encoded video stream, comprising: using at least one processor to: decode a received encoded video stream to obtain a decoded video stream; extract from the encoded video stream encoding information computed by an originating encoder to create the encoded video stream; adjust the encoding information by replacing at least one quantization parameter defined in the encoding information with a corresponding adjusted quantization parameter computed based on a randomly selected value from a range of quantization parameter values; encode the decoded video stream using the adjusted encoding information to produce a modified encoded video stream; and transmit the modified encoded video stream.
2. The method of claim 1, wherein the received encoded video stream is extracted from a received transport stream that encapsulates the encoded video stream.
3. The method of claim 1, wherein the modified encoded video stream is encapsulated in an output transport stream.
4. The method of claim 1, wherein the encoded video stream is a live encoded video stream depicting a live event.
5. The method of claim 1, wherein the encoded video stream is encoded according to a video encoding protocol that is a member of the group consisting of MPEG-1, MPEG-2, MPEG-4, H.261, H.263, H.264, and H.
265.
6. The method of claim 1, wherein the encoding information includes motion vectors, quantization parameters, and macroblock types generated by the originating encoder for a plurality of frames encoded in the encoded video stream.
7. The method of claim 1, wherein the quantization parameter value of the corresponding adjusted quantization is equal to or lower than the quantization parameter value of the at least one quantization parameter.
8. A system for nullifying and reconstructing an encoded video stream to neutralize a malicious agent potentially embedded in the encoded video stream, comprising: at least one processor executing code, the code comprising: encoding instructions to decode a received encoded video stream to obtain a decoded video stream; code instructions to extract from the encoded video stream encoding information computed by an originating encoder to create the encoded video stream; code instructions to adjust the encoding information by replacing at least one quantization parameter defined in the encoding information with a corresponding adjusted quantization parameter computed based on a randomly selected value from a range of quantization parameter values; code instructions to encode the decoded video stream using the adjusted encoding information to produce a modified encoded video stream; and instructions encoded to send the modified encoded video stream.
9. The system of claim 8, wherein the received encoded video stream is extracted from a received transport stream that encapsulates the encoded video stream.
10. The system of claim 8, wherein the modified encoded video stream is encapsulated in an output transport stream. 11. The system of claim 8, wherein the encoded video stream is a live encoded video stream depicting a live event.
12. The system of claim 8, wherein the encoded video stream is encoded according to a video encoding protocol that is a member of the group consisting of MPEG-1, MPEG-2, MPEG-4, H.261, H.263, H.264, and H.
265.
13. The system of claim 8, wherein the encoding information includes motion vectors, quantization parameters, and macroblock types generated by the originating encoder for a plurality of frames encoded in the encoded video stream.
14. The system of claim 8, wherein the quantization parameter values of the correspondingly adjusted quantization are equal to or lower than the quantization parameter values of the at least one quantization parameter.
15. A computer program product for canceling and reconstructing an encoded video stream to neutralize a malicious agent potentially embedded in the encoded video stream, comprising: a non-transitory computer readable storage medium; first program instructions for decoding a received encoded video stream to obtain a decoded video stream; second program instructions for extracting from the encoded video stream encoding information computed by an originating encoder to create the encoded video stream; third program instructions for adjusting the encoding information by replacing at least one quantization parameter defined in the encoding information with a correspondingly adjusted quantization parameter computed based on a randomly selected value from a range of quantization parameter values; fourth program instructions for encoding the decoded video stream using the adjusted encoding information to produce a modified encoded video stream; and fifth program instructions for transmitting the modified encoded video stream; wherein the first program instructions, the second program instructions, the third program instructions, the fourth program instructions, and the fifth program instructions are executed by at least one processor from the non-transitory computer readable storage medium.
16. The computer program product of claim 15, wherein the received encoded video stream is extracted from a received transport stream that encapsulates the encoded video stream.
17. The computer program product of claim 15, wherein the modified encoded video stream is encapsulated in an output transport stream.
18. The computer program product of claim 15, wherein the encoded video stream is a live encoded video stream depicting a live event.
19. The computer program product of claim 15, wherein the encoding information includes motion vectors, quantization parameters, and macroblock types generated by the originating encoder for a plurality of frames encoded in the encoded video stream.
20. The computer program product of claim 15, wherein the quantization parameter values of the correspondingly adjusted quantization are equal to or lower than the quantization parameter values of the at least one quantization parameter.
Citation Information
Patent Citations
Compiler based obfuscation
CN105103127A
Macroblock-Level Adaptive Quantization in Quality-Aware Video Optimization
US20120314764A1