VoIP Traffic Profiling via Packet Size and Arrival Time Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

VoIP networks face security threats such as Denial of Service, Service Theft, and unauthorized monitoring due to their openness and ubiquity, with existing monitoring systems struggling to effectively identify and mitigate these risks across entire infrastructures.

Innovation Solution

A method for profiling VoIP activity in network traffic by analyzing audio packets based on packet size and arrival time, identifying IP addresses associated with VoIP servers, and classifying traffic patterns using power spectral density features to distinguish VoIP activity from other network traffic, thereby detecting anomalies and identifying potential security threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If passive packet monitoring devices are deployed to capture network traffic, then monitoring capability is improved, but the ability to accurately identify VoIP activity amidst other traffic remains insufficient

Engineering Contradiction:
Improvemonitoring capabilityVSAvoidVoIP activity identification accuracy
Core Design Contradiction:
Difficulty of detecting and measuringVSMeasurement precision

Solution Approach 1:

The patent segments the monitoring process into distinct functional modules: packet capture module, VoIP detection module, anomaly detection module, and reporting module. Each module performs a specific function in the traffic analysis pipeline, allowing for specialized processing at each stage and improving overall detection accuracy while maintaining monitoring capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transforms raw packet data into meaningful parameters by extracting features such as packet size, inter-arrival time, and power spectral density. These transformed parameters enable more accurate VoIP activity identification compared to analyzing raw packets directly, resolving the contradiction between monitoring capability and identification accuracy.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If comprehensive monitoring of entire VoIP infrastructure is implemented, then security coverage is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs a universal monitoring system that can detect multiple types of VoIP activities and anomalies through a single integrated platform. The system handles various packet types, protocols, and threat scenarios using common detection mechanisms, reducing the need for separate specialized systems and thereby reducing overall complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary analysis layer between raw packet capture and security decision-making. This intermediate layer processes and characterizes traffic patterns, creating a simplified representation that feeds into anomaly detection algorithms. This mediator reduces the complexity of direct comprehensive monitoring by preprocessing data into manageable characteristics.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If detailed analysis of packet parameters is performed to identify VoIP activity, then classification accuracy is improved, but processing time increases

Engineering Contradiction:
Improvetraffic classification accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-calculating and storing characteristic parameters of VoIP traffic during normal operations. When monitoring, the system compares incoming traffic against these pre-established characteristics rather than performing full analysis on every packet. This preliminary preparation maintains high classification accuracy while significantly reducing real-time processing time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies partial action by selectively analyzing only the most discriminative packet parameters rather than examining all possible features. The system focuses on key characteristics such as power spectral density and inter-arrival time patterns that provide the most value for VoIP identification, achieving high accuracy without the computational overhead of complete packet analysis.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8284764B1VoIP traffic behavior profiling method
Publication Date: 2012.10.09 THE BOEING CO
  • US8284764B1 patent drawing
  • US8284764B1 patent drawing
  • US8284764B1 patent drawing

AI summary

The invention relates to a method for profiling VoIP activity in network traffic. The method includes obtaining a plurality of audio packets from a plurality of packets in the network traffic by analyzing a plurality of parameter sets based on a first pre-determined criterion, wherein each of the plurality of parameter sets corresponds to a packet of the plurality of packets and comprises a packet size and a packet arrival time associated with a corresponding packet of the plurality of packets, generating a count of an IP address by counting at least a portion of the plurality of audio packets, wherein each packet of the portion of the plurality of audio packets comprises the IP address, and identifying an endpoint corresponding to the IP address as a VoIP server and identifying the portion of the plurality of audio packets as VoIP activity associated with the VoIP server when the count exceeds a pre-determined threshold.