Skype false positive

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Skype false positive

L3 Networker

Hello guys,

About skype: how to know, when users realy use skype and when PA detects only false positive? Because now i have lot of log with "secure.skype.com" URL and PA detects it as skype application.. I would be grateful for an explanation.

1 accepted solution

Accepted Solutions

Explanation:

if the webpage contains a java script "detection_as3.swf", wich redirects to webpage "https://secure.skype.com", PA firewall this connection consider as a "skype" application. Case closed.

View solution in original post

10 REPLIES 10

L7 Applicator

Hi Ignas,

Users are using any other video/audio calling application into their machine...? Please follow below mentioned documents for more information about SKYPE.

Controlling Skype

Re: Skype IM Problem

Also I would recommend you to open a case with support.

Thanks

Skype not installed on users' computers. We checked this. But PA detects skype application. Detailed log shows "secure.skype.com" URL.

L4 Transporter

Could be a false positive. Is the firewall on the latest dynamic updates ?

Hi

The URL log as below is generated by accessing to secure.skype.com from IE10.

Do you mean you can't figure out this is actual skype session or just https session from browser?

If my understanding is correct, I guess there is no clue to figure out which pattern is it because the session is encrypted by ssl and PaloAlto device could not see the payload.

However, skype client send out skype-probe session, if you can see skype and skype-probe from one source address, you might be able to say that user is using skype client.

WS000003.jpg

Regards

Hi emr,

many thanks for your answer. I can't find skype-probe. So no skype client is being used. I think that users are redirected to a "secure.skype.com" page from some other page or something like that, though I can't say exactly. Because when I type in a web browser "secure.skype.com", i'm redirected to "login.skype.com" and PA log shows few records "secure.skype.com", "login.skype.com" and "apps.skypeassets.com".  And when I look at users log, I only see "secure.skype.com" records. I'm trying to figure out how this happens.

If the user is using skype client, you can find skype-probe in traffic log as below:

WS000004.jpg

I can see all URLs you mentioned. (URL category name might be different from you because I'm using PAN-DB instead of BrightCloud)

What is 'users log' you are pointing to?

Do you mean detail log for 'secure.skype.com'?

WS000005.jpg

URL log. I use filter: (url contains skype).

Untitled.png

Well, it looks like your PaloAlto device places between client PC and proxy server.

I'm not using proxy. This might causes different result.

Maybe. Anyway thank you for help Smiley Wink

Explanation:

if the webpage contains a java script "detection_as3.swf", wich redirects to webpage "https://secure.skype.com", PA firewall this connection consider as a "skype" application. Case closed.

  • 1 accepted solution
  • 4184 Views
  • 10 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!