Network Based Application Recognition: Difference between revisions

Content deleted Content added
Caliper (talk | contribs)
Everybody should read the original for a textbook example of a terrible article. Then someone who knows what their talking about should read mine to make sure it's right.
Undid revision 1285706095 by Mike Holand102 (talk) Refspam
 
(33 intermediate revisions by 28 users not shown)
Line 1:
'''Network Based Application Recognition''' (NBAR)<ref>[https://web.archive.org/web/20050924161229/http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122newft/122t/122t8/dtnbarad.htm NBAR defined at Cisco website]</ref> is the mechanism used by some [[Cisco]] [[Router (computing)|router]]s and [[Network switch|switches]] to recognize a [[Traffic_flow_(computer_networking)|dataflow]] by inspecting some [[packet (information technology)|packets]] sent.
'''NBAR''', which stands for Network Based Application Recognition is the mechanism used to recognize a dataflow by the first [[packet]] sent.
 
The [[Computer network|networking]] equipment which uses NBAR does a [[deep packet inspection]] on thesome firstof packetthe packets in a dataflow, to determine which traffic category the flow belongs to. ItUsed in conjunction with other features, it may then programmesprogram the internal [[ASICapplication-specific integrated circuits]]s (ASICs) to handle this flow appropriatlyappropriately. The categorisationcategorization ismay usuallybe done with [[Application_layer|Open Systems Interconnection (OSI-layer4) layer 4]] info, packet content, signaling, and so on but some new applications have made it difficult on purpose to cling to this kind of tagging.<ref>[[BitTorrent protocol encryption|BitTorrent Encryption and Obfuscation]]</ref>
 
The NBAR approach is useful in dealing with malicious [[software]] using known [[PortTCP (computing)and UDP port|ports]] to fake being "priority traffic", as well as non-standard appsapplications using non-determinalydynamic ports.<ref>''[http://www.cisco.com/warp/public/63/nbar_acl_codered.shtml Using Network-Based Application Recognition and ACLs] for Blocking the "Code Red" Worm'', Cisco.</ref> That's why NBAR is also known as [[OSI layer 7]] categorization.
 
On Cisco routers, NBAR is mainly used for [[quality of service]] and [[network security]] purposes.
== External Links ==
 
*[http://www.cisco.com Cisco's website]
==References==
{{reflist}}
 
== External Linkslinks ==
*[http://whitepapers.zdnet.co.uk/0,39025945,60105500p-39000590q,00.htm ''Network Based Application Recognition: RTP Payload Classification''], Cisco.
*[http://www.cisco.com/en/US/products/ps5855/products_configuration_example09186a0080ac3082.shtml ''Block P2P Traffic on a Cisco IOS Router using NBAR Configuration Example''], Cisco.
 
[[Category:Computer network security]]
 
 
{{compu-network-stub}}