• binom@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    ·
    1 year ago

    can you maybe link some ressources on how the protocol used can be detected? i did not know about this and would like to read into it some more :)

    • noride@lemm.ee
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 year ago

      Look up NBAR for the basic idea. Each vendor has their own ‘secret sauce’ implementation, Palo Alto only needs 9 bytes of payload for disambiguation, iirc.