Network Based Application Recognition: Difference between revisions

Content deleted Content added
m spelling
m Disambiguation link repair - You can help!
Line 3:
The [[Computer network|networking]] equipment which uses NBAR does a [[deep packet inspection]] on the first packet in a dataflow, to determine which traffic category the flow belongs to. It then programmes the internal [[ASIC]]s to handle this flow appropriately. The categorisation is usually done with [[OSI-layer4]] info, but new applications have made it difficult to cling to this kind of tagging.
 
The NBAR approach is useful in dealing with malicious [[software]] using known [[PortTCP (computing)and UDP port|ports]] to fake being "priority traffic", as well as non-standard apps using non-determinaly ports.
 
== External links ==