Week of August 24: VoIP troubleshooting and protocol fidelity
Added bounded call-quality and IPsec evidence, connected identity and network-path clues, and improved security-analysis accuracy.
platformsecuritybug fixesagentperformance
Platform
- Added bounded VoIP call-quality dossiers that connect signaling, RTP quality, NAT traversal, observed paths, and supporting packet evidence without turning measurements into automatic fault claims.
- Added IPsec coverage and quality context for encrypted VoIP paths, including explicit disclosure when the available capture cannot support a complete conclusion.
- Connected identity, DNS, service, STP, and path observations into focused troubleshooting chains for faster movement from symptoms to inspectable evidence.
Security
- Added bounded DNS behavior candidates and reconnect-aware cadence evidence while keeping promotion gates and coverage limits explicit.
- Added an approval flow for threat-intelligence feeds that require outbound access, making controlled enrichment easier to review before it runs.
- Improved security-analysis fidelity across web, email, file-sharing, authentication, tunneling, fragmentation, and protocol-transition traffic.
Agent
- Improved investigation evidence attribution so reports and follow-up analysis retain the correct connection, finding, and capture context.
- Kept optional path and correlation evidence nonblocking, allowing investigations to finish honestly when a supporting signal is unavailable.
Performance
- Bounded RTP quality analysis and reused compact signaling, identity, and transport evidence to avoid unnecessary capture-wide work.
- Improved stream and transaction handling for security analysis while keeping memory and evaluation work bounded on busy captures.
Bug fixes
- Restored RTP candidate discovery, aligned VoIP signaling across views, preserved SIP call-family relationships, and corrected illegal-packet accounting.
- Fixed VoIP and telecom evidence classification so observations are explained without being promoted into unsupported faults.
- Suppressed unattributed TCP matches, preserved customer-facing finding titles, and tightened affected-system scope for campaign corroboration.
