Tuesday, January 20, 2015

Palo Alto - Custom Signatures

Make a signature to identity the traffic

Patterns , Context , Decoders

Wireshark to identify signatures .

=============
Custom App-IDs
• To identify proprietary applications.
• To achieve granularity of visibility and control over traffic particular to your environment. If your traffic is classified as unkown-tcp/udp, HTTP or SSL, you could bring visibility by developing custom App-IDs.
• To identify ephemeral apps with topical interest.
o Ex: ESPN3-Video for soccer world cup, March Madness, Wikileaks.
• To identify nested applications.
o Further Identify Facebook-apps – Farmville, chat, marketplace, etc.
• To perform QoS for your specific application.
• URL filtering is incapable of providing control to administrators on websites that replicate on a different host, emulating the same look-n-feel as well as content. Example: wikileaks.com


-------Creating Custom Signature  DOC5534



Step1 : Packet Capture 

No comments:

Post a Comment