首页> 外文会议>IEEE International Advance Computing Conference >A technique for classification of VoIP flows in UDP media streams using VoIP signalling traffic
【24h】

A technique for classification of VoIP flows in UDP media streams using VoIP signalling traffic

机译:使用VoIP信令流量对UDP媒体流中的VoIP流进行分类的技术

获取原文

摘要

VoIP applications are becoming popular these days. A lot of Internet traffic are being generated by them. Detection of VoIP traffic is becoming important because of QoS issues and security concerns. A VoIP client typically opens a number of network connection between VoIP client and VoIP client, VoIP client and VoIP server. In the case of peer to peer VoIP applications like Skype network, connections may be between client to client, client to Super Node, client to login server, Super Node to Super Node. Typically, VoIP media traffic are carried by UDP unless firewalls blocks UDP, in which case media and signalling traffic are carried by TCP. Many VoIP applications uses RTP to carry media traffic. Notable examples includes GTalk, Google+ Hangouts, Asterisk based VoIP and Apple's FaceTime. On the other hand, Skype uses a proprietary protocol based on P2P architecture. It uses encryption for end to end communications and adopts obfuscation and anti reverse engineering techniques to prevent reverse engineering of the Skype protocol. This makes the detection of Skype flows a challenging task. Although Skype encrypts all communications, still a portion of Skype payload header known as Start of Message (SoM) is left unecrypted. In this paper, we develop a method for detection of VoIP flows in UDP media streams. Our detection method relies on signalling traffic generated by VoIP applications and heuristics based on the information contained in Skype SoM and RTP/RTCP headers.
机译:这些天VoIP应用程序正在变得流行。他们产生了很多互联网流量。由于QoS问题和安全问题,VoIP流量的检测变得重要。 VoIP客户端通常在VoIP客户端和VoIP客户端,VoIP客户端和VoIP服务器之间打开许多网络连接。在对等体VoIP应用程序等Skype网络等的情况下,连接可以在客户端与客户端,客户端到超级节点,客户端到登录服务器,超级节点到超级节点。通常,除非防火墙阻止UDP,否则VoIP媒体流量由UDP携带,在这种情况下,介质和信令流量由TCP承载。许多VoIP应用程序使用RTP携带媒体流量。值得注意的例子包括GTalk,Google+ Hoogouts,基于星号的VoIP和Apple的FaceTime。另一方面,Skype使用基于P2P架构的专有协议。它使用Encryption实现端到端通信,采用混淆和反逆向工程技术,以防止Skype协议的逆向工程。这使得Skype的检测流动了一个具有挑战性的任务。虽然Skype加密所有通信,但仍然是Skype Payload标题的一部分称为消息的开始(SOM)留下了不冲击。在本文中,我们开发了一种检测UDP媒体流中VoIP流的方法。我们的检测方法依赖于根据Skype SOM和RTP / RTCP标头所包含的信息由VoIP应用程序和启发式产生的信令流量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号