- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-17-2024 07:18 AM
I need to understand exactly makes a TCP flow identified as the 'ms-update' application.
I found the Objects -> Applications -> ms-update app description. It shows the ports used, and other dependencies. But this does not explain exactly what makes one flow identified as the 'ms-update' application. And a second flow identified as some other application.
Details on this topic would be appreciated. Especially any info about specifically what parameters go into the decision to classify a flow as the 'ms-update' application. Thank you.
07-17-2024 09:09 AM
Hi @jebwilson ,
The primary method PANW uses to identify applications is application signatures. PANW does not reveal the specific details for each signature to my knowledge. In some cases, protocol decoders and heuristics are used. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/app-id-overview
Here is an example where App-ID has identified the traffic as ssl, but also uses the certificate to change it to a different app. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVSCA0
Enabling decryption will allow you to identify a lot more apps.
Thanks,
Tom
07-17-2024 09:09 AM
Hi @jebwilson ,
The primary method PANW uses to identify applications is application signatures. PANW does not reveal the specific details for each signature to my knowledge. In some cases, protocol decoders and heuristics are used. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/app-id-overview
Here is an example where App-ID has identified the traffic as ssl, but also uses the certificate to change it to a different app. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVSCA0
Enabling decryption will allow you to identify a lot more apps.
Thanks,
Tom
07-17-2024 11:54 AM
Thank you Tom. Really appreciate the clear information and the quick reply!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!