Defensive labs About 1 min read

RTSP, RTP, RTCP, and SDP trace analysis

Follow session setup and packet flow in a synthetic media trace. Use the observations to identify which protocol layer needs further investigation.

Sources and scopeSource record 25 August 2026

Technical source record: 25 August 2026. Check the linked documentation for current product requirements.

Offline research and planning only; product or deployment acceptance belongs to separately governed environment validation.

Verification and testing

Overview#

Lab class: Offline synthetic trace

RFC 7826 and RFC 8866 are the current RTSP 2.0 and SDP bases. RFC 2326 (RTSP 1.0) and RFC 4566 (older SDP) remain useful only when a captured or synthetic fixture explicitly uses those installed legacy versions.

Procedure#

  1. Identify RTSP version; don't assume RTSP 1.0 and 2.0 are interchangeable.
  2. Follow request/response pairs using CSeq and session identifiers; record authentication and URI exposure.
  3. Parse SDP media, connection, payload type, rtpmap/fmtp, control URI, direction and timing fields.
  4. Determine RTP over UDP, multicast, TCP interleaving or another negotiated path.
  5. Track one SSRC's sequence and timestamp space; distinguish packet loss, reordering, duplication and capture loss.
  6. Use RTCP sender/receiver reports to interpret timing and reported loss without treating them as authenticated truth in an unprotected session.
  7. Map payload format to codec/framing and confirm receiver limits.
  8. Identify whether control and media have confidentiality/integrity, and where credentials/tokens appear.

Expected artefacts#

  • session flow diagram;
  • SDP field table and resolved control/media endpoints;
  • transport and port/multicast map;
  • sequence/loss/reordering note;
  • authentication/encryption boundary;
  • explicit capture and version limitations.

Evidence checklist#

  • Fixture provenance, digest, protocol versions, and codec mapping recorded
  • RTSP 1.0 and 2.0 semantics not mixed
  • SDP version and resolved control/media endpoints recorded
  • Capture gaps distinguished from protocol loss and reordering
  • Authentication, confidentiality, integrity, and interpretation limits documented

Sources#

Section overview · Wiki home