Defensive labs About 1 min read
RTSP, RTP, RTCP, and SDP trace analysis
Follow session setup and packet flow in a synthetic media trace. Use the observations to identify which protocol layer needs further investigation.
Sources and scopeSource record 25 August 2026
Technical source record: 25 August 2026. Check the linked documentation for current product requirements.
Offline research and planning only; product or deployment acceptance belongs to separately governed environment validation.
On this page
Overview#
Lab class: Offline synthetic trace
RFC 7826 and RFC 8866 are the current RTSP 2.0 and SDP bases. RFC 2326 (RTSP 1.0) and RFC 4566 (older SDP) remain useful only when a captured or synthetic fixture explicitly uses those installed legacy versions.
Procedure#
- Identify RTSP version; don't assume RTSP 1.0 and 2.0 are interchangeable.
- Follow request/response pairs using CSeq and session identifiers; record authentication and URI exposure.
- Parse SDP media, connection, payload type, rtpmap/fmtp, control URI, direction and timing fields.
- Determine RTP over UDP, multicast, TCP interleaving or another negotiated path.
- Track one SSRC's sequence and timestamp space; distinguish packet loss, reordering, duplication and capture loss.
- Use RTCP sender/receiver reports to interpret timing and reported loss without treating them as authenticated truth in an unprotected session.
- Map payload format to codec/framing and confirm receiver limits.
- Identify whether control and media have confidentiality/integrity, and where credentials/tokens appear.
Expected artefacts#
- session flow diagram;
- SDP field table and resolved control/media endpoints;
- transport and port/multicast map;
- sequence/loss/reordering note;
- authentication/encryption boundary;
- explicit capture and version limitations.
Evidence checklist#
- Fixture provenance, digest, protocol versions, and codec mapping recorded
- RTSP 1.0 and 2.0 semantics not mixed
- SDP version and resolved control/media endpoints recorded
- Capture gaps distinguished from protocol loss and reordering
- Authentication, confidentiality, integrity, and interpretation limits documented
Sources#
- RFC 7826 RTSP 2.0, current RTSP base, accessed 25 August 2026.
- RFC 8866 SDP, current SDP base, accessed 25 August 2026.
- RFC 2326 RTSP 1.0, accessed 25 August 2026.
- RFC 3550 RTP, accessed 25 August 2026.
- RFC 4566 SDP, obsolete legacy baseline, accessed 25 August 2026.