mirror of
https://github.com/vel21ripn/nDPI.git
synced 2026-05-22 03:03:07 +00:00
If we have a valid HTTP sessions, we should ignore `flow->guessed_protocol_id` field (i.e. classification "by-port") altogheter. The attached trace was classified as "SIP/HTTP" only because the *client* port was 5060... As a general rule, having a classification such as "XXXX/HTTP" is *extremely* suspicious. |
||
|---|---|---|
| .. | ||
| dga | ||
| pcap | ||
| performance | ||
| result | ||
| unit | ||
| do-dga.sh | ||
| do-unit.sh | ||
| do.sh.in | ||
| Makefile.am | ||
| ossfuzz.sh | ||