Abstract
With the increasing volume of VoIP, IPTV, and other real-time traffic on the Internet in recent years, service providers and operators demand tools to effectively detect and manage such traffic in their networks. However, many such applications are not easy to detect by using conventional approaches based on packet header and payload inspections since they may use random ports and data encryption. In this paper, we propose a simple yet effective approach that can detect constant or near constant rate traffic based on statistical inference on packet timing behaviors. Through experiments with traffic collected from both lab controlled environment and actual field networks, we show that this approach is easier to implement and has much better performance compared to existing approaches.