[76557] in North American Network Operators' Group
identifying application type of network traffic
daemon@ATHENA.MIT.EDU (Joe Shen)
Wed Dec 15 21:52:59 2004
Date: Thu, 16 Dec 2004 10:52:33 +0800 (CST)
From: Joe Shen <joe_hznm@yahoo.com.sg>
To: NANGO <nanog@merit.edu>
Errors-To: owner-nanog-outgoing@merit.edu
Hi,
I'm trying to identify applications which generate
those traffic on our border routers. I use sampled
netflow as data source and some flow-tools as
analizer.
Currently, I use (protocol, port_number) as indicator
of application. Referring to rfc on wellknown protocol
and port allocation, I can only identity about 50% of
traffic type.
Is there a complete (protocol, port_number) list ? or
is there a better way to identify application type
based on netflow data?
regards
Joe
__________________________________________________
Do You Yahoo!?
Log on to Messenger with your mobile phone!
http://sg.messenger.yahoo.com