RTP SIP Leak Protection via Data Domain Conversion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Real-time data transfer protocols like RTP and SIP are vulnerable to data smuggling, where non-real-time data is embedded and transmitted as real-time data, leading to potential losses for companies.

Innovation Solution

Implementing a network security appliance with RTP and SIP leak protection systems that modify and obscure non-real-time data within real-time data transfer packets by converting them between digital and analog domains, or using pattern recognition to identify and obscure mismatched data patterns, ensuring only genuine real-time data is transmitted.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If RTP and SIP protocols are used for real-time data transfer, then real-time audio and video data can be transmitted efficiently, but non-real-time data can be smuggled within the real-time data stream

Engineering Contradiction:
Improvereal-time data transmission speedVSAvoiddata smuggling risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by pre-establishing codec parameters and data patterns before real-time data transmission begins. The system pre-configures expected codec settings, data formats, and transmission characteristics, then compares incoming data against these pre-established parameters to detect smuggled data before it can be exfiltrated

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security appliance positioned between the RTP/SIP data stream and the network. This intermediary device intercepts real-time data packets, analyzes them against predefined codec parameters and patterns, and blocks or alerts on suspicious data that deviates from expected real-time media characteristics

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data inspection is performed on real-time data streams, then data smuggling can be detected, but the real-time transmission quality may be degraded

Engineering Contradiction:
Improvedata securityVSAvoidreal-time transmission efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial action by performing selective inspection on only critical portions of real-time data streams. Rather than analyzing every byte of audio/video data, the system focuses inspection on header information, codec parameter fields, and specific data patterns that are most indicative of smuggling attempts, allowing most legitimate real-time data to pass through with minimal processing

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent uses parameter changes by dynamically adjusting inspection depth and intensity based on data characteristics. The system modifies inspection parameters such as packet sampling rate, analysis depth, and threshold sensitivity according to the type of real-time data being transmitted, maintaining security while adapting to different transmission scenarios

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12003484B2Systems and methods for preventing data leaks over RTP or SIP
Publication Date: 2024.06.04 FORTINET INC
  • US12003484B2 patent drawing
  • US12003484B2 patent drawing
  • US12003484B2 patent drawing

AI summary

Systems, devices, and methods are discussed for avoiding data thefts in real-time transactions.