<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: amount of traffic before &amp;quot;unknown application&amp;quot; is determined in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/amount-of-traffic-before-quot-unknown-application-quot-is/m-p/16678#M12164</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Page 2 at &lt;A href="http://media.paloaltonetworks.com/documents/App_ID_tech.pdf" title="http://media.paloaltonetworks.com/documents/App_ID_tech.pdf"&gt;http://media.paloaltonetworks.com/documents/App_ID_tech.pdf&lt;/A&gt; have a brief description on whats going on inside a PA device when a packet arrives.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have seen numbers of 14 and up to 20 packets being mentioned before final decision that a flow is unknown, but I dont know if these figures are true or not. However it can go faster to decide that a session is unknown.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;CS: SYN&lt;/P&gt;&lt;P&gt;SC: SYN+ACK&lt;/P&gt;&lt;P&gt;CS: ACK&lt;/P&gt;&lt;P&gt;CS: "a b c\n\n"&lt;/P&gt;&lt;P&gt;SC: HTTP ERROR 400/Bad Request&lt;/P&gt;&lt;P&gt;= unknown (if im not mistaken).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the above case there was only needed 2 packets (or 1 packet in each direction if we exclude the initial handshake) before the flow isnt recognised as any known application and because of that classified as unknown.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are other cases aswell. For example if you start a session like DNS but in the middle start to do other things then the DNS decoder will not recognise the traffic and because of that switch the flow out of the DNS decoder and identify it as unknown. When next packet arrives the PA unit can take a new decision what kind of traffic is passing through (so you in the log can see how a single session hops between identified applications).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 10 Jul 2012 17:55:53 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-07-10T17:55:53Z</dc:date>
    <item>
      <title>amount of traffic before "unknown application" is determined</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/amount-of-traffic-before-quot-unknown-application-quot-is/m-p/16677#M12163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my questions deals with the application detection. As far as I know the heuristic engine is the last possibility after application signature and decoders weren't successful.&lt;/P&gt;&lt;P&gt;But does anybody know how much traffic (bytes or packets) will/can run through a PAN before the heuristic engine gives and the application is set to "unknown"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Sylvia&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2012 16:35:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/amount-of-traffic-before-quot-unknown-application-quot-is/m-p/16677#M12163</guid>
      <dc:creator>sylvia</dc:creator>
      <dc:date>2012-07-10T16:35:45Z</dc:date>
    </item>
    <item>
      <title>Re: amount of traffic before "unknown application" is determined</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/amount-of-traffic-before-quot-unknown-application-quot-is/m-p/16678#M12164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Page 2 at &lt;A href="http://media.paloaltonetworks.com/documents/App_ID_tech.pdf" title="http://media.paloaltonetworks.com/documents/App_ID_tech.pdf"&gt;http://media.paloaltonetworks.com/documents/App_ID_tech.pdf&lt;/A&gt; have a brief description on whats going on inside a PA device when a packet arrives.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have seen numbers of 14 and up to 20 packets being mentioned before final decision that a flow is unknown, but I dont know if these figures are true or not. However it can go faster to decide that a session is unknown.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;CS: SYN&lt;/P&gt;&lt;P&gt;SC: SYN+ACK&lt;/P&gt;&lt;P&gt;CS: ACK&lt;/P&gt;&lt;P&gt;CS: "a b c\n\n"&lt;/P&gt;&lt;P&gt;SC: HTTP ERROR 400/Bad Request&lt;/P&gt;&lt;P&gt;= unknown (if im not mistaken).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the above case there was only needed 2 packets (or 1 packet in each direction if we exclude the initial handshake) before the flow isnt recognised as any known application and because of that classified as unknown.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are other cases aswell. For example if you start a session like DNS but in the middle start to do other things then the DNS decoder will not recognise the traffic and because of that switch the flow out of the DNS decoder and identify it as unknown. When next packet arrives the PA unit can take a new decision what kind of traffic is passing through (so you in the log can see how a single session hops between identified applications).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2012 17:55:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/amount-of-traffic-before-quot-unknown-application-quot-is/m-p/16678#M12164</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-07-10T17:55:53Z</dc:date>
    </item>
  </channel>
</rss>

