Shane Alcock
Abstract:
Shane Alcock's talk on Mildly Penetrative Packet Inspection describes how only a very small amount of packet payload can be used to effectively identify application protocols, as opposed to deep packet inspection methods. Using this approach, WAND has developed an OSS library that supports 178 different application protocols. The results of using this library to analyse a capture from a NZ ISP taken in 2010 will be presented.