Encrypted VoIP Traffic Classification via Behavioral Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing encryption of internet traffic, particularly with over 50% of traffic already encrypted and projected to rise to 80% in developed markets, poses a challenge for network operators to accurately identify and classify VoIP services, including encrypted VoIP traffic.

Innovation Solution

A method and system for classifying and handling VoIP traffic flows on a computer network, which involves collecting traffic flow data, determining if an IP session is a VoIP session, correlating similar IP sessions, and creating IPDR or CDR records based on correlated parameters, even for encrypted traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional metadata collection methods are used for traffic classification, then the system is simple to implement, but it cannot accurately identify encrypted VoIP traffic

Engineering Contradiction:
ImproveVoIP traffic identification accuracyVSAvoidclassification system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces deep packet inspection (DPI) as an intermediary mechanism that can penetrate encryption layers to identify VoIP traffic characteristics. The DPI system analyzes packet contents, timing patterns, and protocol behaviors even when traffic is encrypted, serving as a mediator between network operators and encrypted VoIP communications to enable accurate identification without requiring decryption of the actual voice data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the classification parameters from traditional metadata (IP addresses, port numbers) to behavioral parameters such as packet timing patterns, inter-packet intervals, and traffic flow characteristics. These parameter changes enable the system to identify VoIP traffic based on its temporal and structural patterns rather than relying on unencrypted metadata, thereby maintaining accuracy with encrypted traffic.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If deep packet inspection is performed on encrypted traffic, then VoIP classification accuracy improves, but processing time and computational resources increase

Engineering Contradiction:
Improveencrypted traffic classification accuracyVSAvoidpacket processing delay
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs partial deep packet inspection by focusing only on specific packet fields and timing characteristics rather than analyzing the entire encrypted payload. It extracts key behavioral parameters such as packet sizes, inter-arrival times, and sequence patterns, which are sufficient for VoIP identification without requiring full packet decryption or analysis, thereby reducing processing overhead while maintaining classification accuracy.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent implements preliminary classification actions by pre-establishing traffic profiles and behavioral baselines for VoIP communications. The system learns normal VoIP patterns during training periods and uses these profiles for rapid matching during operational traffic analysis, reducing real-time computational requirements and enabling faster classification decisions without compromising accuracy.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If comprehensive traffic data is collected for analysis, then billing and fraud detection capabilities improve, but data privacy concerns and security risks increase

Engineering Contradiction:
Improvebilling and fraud detection capabilityVSAvoiddata privacy risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system extracts only the necessary behavioral parameters and metadata required for VoIP identification and fraud detection, separating these essential features from the bulk of encrypted traffic data. By taking out only the critical timing patterns, packet characteristics, and connection metadata, the system enables billing and fraud analysis without requiring access to or storage of the actual encrypted communication contents, thereby minimizing privacy risks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary data processing layer that analyzes traffic patterns without accessing encrypted payloads. This intermediary system acts as a buffer between the network infrastructure and sensitive user data, enabling fraud detection and billing services to operate on anonymized behavioral characteristics rather than raw encrypted traffic, thus maintaining operational capability while reducing direct exposure to privacy vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250193306A1System and method for classifying and handling voice over IP traffic
Publication Date: 2025.06.12 SANDVINE CORP
  • US20250193306A1 patent drawing
  • US20250193306A1 patent drawing
  • US20250193306A1 patent drawing

AI summary

A system and method for handling Voice over Internet Protocol (VOIP) traffic flows on a computer network, and, in particular, encrypted VoIP traffic flows. The method including: collecting traffic flow data with respect to an IP session; collecting parameters associated with the IP session; determining whether the IP session is a VoIP session; correlating IP sessions having similar parameters to the collected parameters; and creating at least one Internet Protocol Detail Record (IPDR) or Call Detail Record (CDR) based on the correlated IP sessions. The system including: a collection module configured to collect traffic flow data; an analysis module configured to determine parameters and determine whether the IP session is a VoIP session; and a correlation module configured to correlate IP sessions having similar parameters; and create at least one Internet Protocol Detail Record (IPDR) or Call Detail Record (CDR) based on the correlated IP sessions.