<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NTP and Bittorrent traffic issue in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/500191#M2146</link>
    <description>&lt;DIV class="lia-quilt-row lia-quilt-row-message-main"&gt;
&lt;DIV class="lia-quilt-column lia-quilt-column-24 lia-quilt-column-single lia-quilt-column-message-main-content"&gt;
&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-single"&gt;
&lt;DIV class="lia-message-body-wrapper lia-component-message-view-widget-body"&gt;
&lt;DIV id="bodyDisplay_0" class="lia-message-body"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;Hello and sorry for my poor English.&lt;/P&gt;
&lt;P&gt;I wrote this question/feedback before &lt;A href="https://live.paloaltonetworks.com/t5/customer-resources/ntp-app-id-enhancement-release-plan/tac-p/498979#M603" target="_self"&gt;here&lt;/A&gt;, but no one wrote an answer. I decided to share it here as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are a member of pool.ntp.org&lt;/P&gt;
&lt;P&gt;Our time server url is ntp.cbu.edu.tr&lt;/P&gt;
&lt;P&gt;Beginning May 19th problem appeared on our NTP service. We started getting a lot of bittorrent requests. Of course, requests were denied. However, pool.ntp.org started reporting that we were not responding to ntp requests.&lt;/P&gt;
&lt;P&gt;We captured the packets that PaloAlto detected as bittorrent. When we examined the packages, we could not see anything other than ntp traffic.&lt;/P&gt;
&lt;P&gt;As a result, we think that PaloAlto mistakenly detected ntp traffic as bittorrent traffic.&lt;/P&gt;
&lt;P&gt;If you want to examine it, I'm putting a file here that the packages we capture.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;&lt;BR /&gt;&lt;BR /&gt;Please note you are posting a public message where community members and experts can provide assistance. Sharing private information such as serial numbers or company information is not recommended.</description>
    <pubDate>Mon, 06 Jun 2022 12:50:48 GMT</pubDate>
    <dc:creator>riza.emet</dc:creator>
    <dc:date>2022-06-06T12:50:48Z</dc:date>
    <item>
      <title>NTP and Bittorrent traffic issue</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/500191#M2146</link>
      <description>&lt;DIV class="lia-quilt-row lia-quilt-row-message-main"&gt;
&lt;DIV class="lia-quilt-column lia-quilt-column-24 lia-quilt-column-single lia-quilt-column-message-main-content"&gt;
&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-single"&gt;
&lt;DIV class="lia-message-body-wrapper lia-component-message-view-widget-body"&gt;
&lt;DIV id="bodyDisplay_0" class="lia-message-body"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;Hello and sorry for my poor English.&lt;/P&gt;
&lt;P&gt;I wrote this question/feedback before &lt;A href="https://live.paloaltonetworks.com/t5/customer-resources/ntp-app-id-enhancement-release-plan/tac-p/498979#M603" target="_self"&gt;here&lt;/A&gt;, but no one wrote an answer. I decided to share it here as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are a member of pool.ntp.org&lt;/P&gt;
&lt;P&gt;Our time server url is ntp.cbu.edu.tr&lt;/P&gt;
&lt;P&gt;Beginning May 19th problem appeared on our NTP service. We started getting a lot of bittorrent requests. Of course, requests were denied. However, pool.ntp.org started reporting that we were not responding to ntp requests.&lt;/P&gt;
&lt;P&gt;We captured the packets that PaloAlto detected as bittorrent. When we examined the packages, we could not see anything other than ntp traffic.&lt;/P&gt;
&lt;P&gt;As a result, we think that PaloAlto mistakenly detected ntp traffic as bittorrent traffic.&lt;/P&gt;
&lt;P&gt;If you want to examine it, I'm putting a file here that the packages we capture.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;&lt;BR /&gt;&lt;BR /&gt;Please note you are posting a public message where community members and experts can provide assistance. Sharing private information such as serial numbers or company information is not recommended.</description>
      <pubDate>Mon, 06 Jun 2022 12:50:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/500191#M2146</guid>
      <dc:creator>riza.emet</dc:creator>
      <dc:date>2022-06-06T12:50:48Z</dc:date>
    </item>
    <item>
      <title>Re: NTP and Bittorrent traffic issue</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/502132#M2147</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42596"&gt;@riza.emet&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Community Feedback area is dedicated to questions about the LIVEcommunity.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In order to get better traction for your question I've moved it to the VirusTotal discussions area.&amp;nbsp;&lt;SPAN&gt;This area is moderated by the threat team to check signatures and verdicts.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kiwi.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2022 09:37:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/502132#M2147</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2022-06-09T09:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: NTP and Bittorrent traffic issue</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/502519#M2148</link>
      <description>&lt;P&gt;did you get any proper solution for this problem&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 06:57:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/502519#M2148</guid>
      <dc:creator>Jerry748</dc:creator>
      <dc:date>2022-06-10T06:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: NTP and Bittorrent traffic issue</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/502523#M2149</link>
      <description>&lt;P&gt;No, we haven't found it yet. However, we have opened a case to PaloAlto Support for the issue. We're waiting.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 07:12:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/502523#M2149</guid>
      <dc:creator>riza.emet</dc:creator>
      <dc:date>2022-06-10T07:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: NTP and Bittorrent traffic issue</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/502771#M2150</link>
      <description>&lt;P&gt;Sorry but I don't believe this has anything to do with VirusTotal either. This forum is for non-customers. The Threat and Vulnerability forum may have been a better fit, however, posts in the LIVECommunity expect answers from other Palo Alto Networks customers. If you need a response from Palo Alto Networks Support, the correct avenue for help is filing a Support ticket.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 17:35:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/502771#M2150</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2022-06-10T17:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: NTP and Bittorrent traffic issue</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/502780#M2151</link>
      <description>&lt;P&gt;What is your Security policy for the incoming NTP traffic to your server? Are you using Application="ntp" and Service="application-default" in your allow rule? Or are you using a Service="udp_123" or something similar?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 18:22:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/502780#M2151</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-06-10T18:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: NTP and Bittorrent traffic issue</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/502783#M2152</link>
      <description>&lt;P&gt;We are using Application="ntp" and Service="application-default" in our allow rule.&lt;/P&gt;&lt;P&gt;Monitor show some udp-123 traffic "ntp", some udp-123 traffic "bittorrent". As expected bittorrent blocked but they are actually ntp.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 18:38:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/502783#M2152</guid>
      <dc:creator>riza.emet</dc:creator>
      <dc:date>2022-06-10T18:38:13Z</dc:date>
    </item>
    <item>
      <title>Re: NTP and Bittorrent traffic issue</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/502789#M2153</link>
      <description>&lt;P&gt;Seems like a false positive then. Looking thru my PaloAlto Apps and Threats release notes I don't see anything about bittorrent Application changes in the last year. I think you are going to have to get PaloAlto support to investigate/fix the false positive. If it is a serious problem for you, you could temporarily bypass the application filter and just allow UDP 123 in the mean time.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 19:04:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/502789#M2153</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-06-10T19:04:11Z</dc:date>
    </item>
    <item>
      <title>Re: NTP and Bittorrent traffic issue</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/502808#M2154</link>
      <description>&lt;P&gt;I replayed your PCAP to my lab. I see NTPv4 traffic detected as ntp-base, and NTPv1 traffic detected as ntp-non-rfc. I don't see any bittorrent traffic, but I am running 10.2.2, maybe your PAN-OS identifies it differently. Check the source ports of the sessions identified as bittorrent, and compare them to your packet capture to see if there is a correlation between NTPv1 and bittorrent, versus NTPv4 and correct identifification of ntp-base traffic. It is possible that your firewall is detecting ntp-non-rfc as bittorrent.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 19:42:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/502808#M2154</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2022-06-10T19:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: NTP and Bittorrent traffic issue</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/502811#M2155</link>
      <description>&lt;P&gt;Also check if the misdetection began around March 15, 2022, that's when the change was pushed in Content.&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/customer-resources/app-id-decoders-enhancement-plan/ta-p/469547" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/customer-resources/app-id-decoders-enhancement-plan/ta-p/469547&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can test adding ntp-non-rfc as an allowed app in your policy to see if it resolves the issue.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 19:49:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/502811#M2155</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2022-06-10T19:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: NTP and Bittorrent traffic issue</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/502812#M2156</link>
      <description>&lt;P&gt;Thanks for answer. I will compare.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 19:47:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/502812#M2156</guid>
      <dc:creator>riza.emet</dc:creator>
      <dc:date>2022-06-10T19:47:51Z</dc:date>
    </item>
    <item>
      <title>Re: NTP and Bittorrent traffic issue</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/507632#M2188</link>
      <description>&lt;P&gt;The problem to be fixed with App&amp;amp;Thread Update 8586. The release note says that false positive is fixed.&lt;/P&gt;&lt;P&gt;Thank you for your interest.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2022 09:02:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/ntp-and-bittorrent-traffic-issue/m-p/507632#M2188</guid>
      <dc:creator>riza.emet</dc:creator>
      <dc:date>2022-07-01T09:02:42Z</dc:date>
    </item>
  </channel>
</rss>

