The Lync ALG using the classify media option on the ACL uses deep packet inspection to look at heuristic information about the flows. Heuristics can use things like packet length, packet types, source destination ports etc to create a picture of the traffic types.
Through this we can determine what kind of traffic is flowing and idetify it as Lync. It is actually pretty accurate and the best of its kind today.
In 6.3 we introduced a new feature that uses signaling between the Lync server and the controller to replace this classify media option. Check out the user guide for 6.3 pages 775-789 for more info on this.
John