From: Tim Durack (tdurack@yahoo.com)
Date: 03/06/03
Has any consideration been given to characterizing traffic flows using
L5-7?
Given that traffic samples are 100 bytes in length, is this enough data
to use more than just L4 ports for identification?
I suppose this would be a lot more expensive computation wise, but L4
could be used to map a flow, and then payload could be used for
confirmation. This would be very useful for identifying p2p apps, and
anything that relies on >1024 ports.
Any thoughts?
__________________________________________________
Do you Yahoo!?
Yahoo! Tax Center - forms, calculators, tips, more
//taxes.yahoo.com/
This archive was generated by hypermail 2.1.4 : 03/06/03 PST