Publication Details
Fast RTP Detection and Codecs Classification in Internet Traffic
Ryšavý Ondřej, doc. Ing., Ph.D. (DIFS FIT BUT)
Kmeť Martin, Ing. (FIT BUT)
network forensics, RTP detection, codec identification, VoIP
This paper presents a fast multi-stage method for on-line detection of RTP streams and codec identification of transmitted voice or video traffic. The method includes an RTP detector that filters packets based on specific values from UDP and RTP headers. When an RTP stream is successfully detected, codec identification is applied using codec feature sets. The paper shows advantages and limitations of the method and its comparison with other approaches. The method was implemented as a part of network forensics framework NetFox developed in project SEC6NET. Results show that the method can be successfully used for Lawful Interception as well as for network monitoring.
@ARTICLE{FITPUB10641, author = "Petr Matou\v{s}ek and Ond\v{r}ej Ry\v{s}av\'{y} and Martin Kme\v{t}", title = "Fast RTP Detection and Codecs Classification in Internet Traffic", pages = "99--110", journal = "The Journal of Digital Forensics, Security and Law", volume = 2014, number = 2, year = 2014, ISSN = "1558-7215", doi = "10.15394/jdfsl.2014.1174", language = "english", url = "https://www.fit.vut.cz/research/publication/10641" }