Mechanism for identifying malicious content, DoS attacks, and illegal IPTV
services. By monitoring the characteristics of various control messages
being transmitted within a network that services Internet protocol
television (IPTV) content to identify suspicious behavior (e.g., such as
that associated with malicious content, denial of service (DoS) attacks,
IPTV service stealing, etc.). In addition to monitoring control messages
within such a network, deep packet inspection (DPI) may be performed for
individual packets within an IPTV stream to identify malicious content
therein (e.g., worms, viruses, etc. actually within the IPTV stream
itself). By monitoring control messages and/or actual IPTV content within
a network (e.g., vs. at the perimeter of a network only), protection
against both outside and inside attacks can be effectuated. This network
level basis of operation effectively guards against promulgation of
malicious content to other devices within the network.