VoIP Anomaly Detection via SIP RTP Header Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting anomaly traffic in VoIP services, particularly in VoIP applications using Session Initiation Protocol (SIP) and Real-time Transport Protocol (RTP), are not effectively suited for the specific requirements of VoIP environments, especially in wireless Internet settings, where malicious attacks can degrade voice call quality and disrupt services.

Innovation Solution

A method and system for detecting VoIP application anomaly traffic by capturing IP packets, classifying them into SIP and RTP traffic, extracting and storing header information, and determining the presence of anomaly traffic based on specific criteria, including message types, sequence numbers, and MAC addresses, using standards like IPFIX for efficient detection and visualization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If general network anomaly detection methods are used for VoIP services, then detection coverage for general network threats is provided, but detection effectiveness for VoIP-specific anomaly traffic is insufficient

Engineering Contradiction:
Improveanomaly traffic detection effectivenessVSAvoiddetection method suitability for VoIP environment
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by designing detection rules specifically tailored for VoIP traffic characteristics. Instead of using generic anomaly detection methods, the system implements specialized detection mechanisms for SIP and RTP protocols, analyzing VoIP-specific parameters such as message types, sequence numbers, and timing patterns to accurately identify VoIP anomaly traffic.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent utilizes parameter changes by monitoring variations in VoIP traffic parameters over time. The system tracks parameters such as inter-arrival times of SIP messages, sequence number increments in RTP packets, and message type distributions. By detecting abnormal changes in these parameters compared to established baselines, the system can identify anomaly traffic specific to VoIP services.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If detailed header information is extracted and stored for all VoIP packets, then anomaly detection accuracy is improved, but system resource consumption increases

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoiddata storage requirement
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent applies taking out by selectively extracting only the essential header information from VoIP packets that is relevant for anomaly detection. Instead of storing complete packet data, the system extracts specific fields such as SIP message types, Call-ID, sequence numbers, and timing information. This selective extraction maintains detection accuracy while significantly reducing storage requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements partial action by focusing detection efforts on the most critical VoIP traffic characteristics. The system extracts and analyzes only the key parameters necessary for identifying common VoIP anomalies, such as abnormal message type sequences, unexpected sequence number patterns, and irregular timing intervals, rather than processing all possible packet attributes.

Inventive Principle:
Principle #16Partial or excessive action

3Loss of time

If real-time analysis of all VoIP traffic is performed, then anomaly detection timeliness is improved, but processing complexity and computational load increase

Engineering Contradiction:
Improveanomaly detection response timeVSAvoiddetection system complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-defining detection rules and thresholds for common VoIP anomaly patterns before actual traffic analysis begins. The system establishes baseline characteristics for normal SIP and RTP traffic in advance, including expected message type sequences, typical inter-arrival times, and valid sequence number ranges. This pre-prepared framework enables rapid real-time detection without complex on-the-fly analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements segmentation by dividing the anomaly detection process into separate modules for different VoIP protocols and anomaly types. The system independently analyzes SIP messages and RTP packets using protocol-specific detection rules, and separately monitors for different anomaly categories such as DoS attacks, protocol violations, and quality degradation. This modular approach reduces processing complexity while maintaining real-time detection capability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8218534B2VoIP anomaly traffic detection method with flow-level data
Publication Date: 2012.07.10 THE IND & ACADEMIC COOP IN CHUNGNAM NAT UNIV (IAC)
  • US8218534B2 patent drawing
  • US8218534B2 patent drawing
  • US8218534B2 patent drawing

AI summary

The present invention relates to a method and system of detecting anomaly traffic for VoIP applications, in which a router captures an IP packet of a VoIP flow being transmitted, the captured IP packet is classified into an SIP message and a RTP traffic, header information is extracted from the classified SIP message and RTP traffic, the extracted header information is stored in a database, and whether SIP-based anomaly traffic or RTP-based anomaly traffic is generated is determined based on the extracted and stored information, and to a system therefor.