Juniper NETWORK AND SECURITY MANAGER 2010.3 - ADMINISTRATION GUIDE REV1 Administration Manual page 955

Table of Contents

Advertisement

P2P:AUDIT:GNUTELLA-SEARCH
P2P:AUDIT:GNUTELLA-SVR-RESP
P2P:AUDIT:GNUTELLA-TTL
P2P:AUDIT:GNUTELLA-UNSUP-VER
P2P:BITTORRENT:TRACKER-QUERY
P2P:BITTORRENT:TRACKER-SCRAPE
P2P:DC:DC-PP-ACTIVE
P2P:EDONKEY:CLIENT-VER-CHECK
P2P:GNUTELLA:CONNECT
P2P:GNUTELLA:CONNECTION-OK
P2P:GNUTELLA:CONNECTION-OK-V06
P2P:MLDONKEY:CLIENT-ACTIVE
P2P:SKYPE:VERSION-CHECK
Copyright © 2010, Juniper Networks, Inc.
This protocol anomaly is a Gnutella message with a search
criteria field that does not end with a NULL character.
This protocol anomaly is a Gnutella server response that
does not use the expected syntax. Correct syntax for Gnutella
0.4 is: GNUTELLA OK<CR><LF>; correct syntax for Gnutella
0.6 is: GNUTELLA/0.6 200 OK<CR><LF>.
This protocol anomaly is a Gnutella message with a TTL
that exceeds the user-defined maximum. The default TTL
is 8. The Gnutella RFC recommends an 8 to 10 TTL maximum
for Gnutella messages.
This protocol anomaly is a Gnutella message with a connect
string that does not conform to Gnutella RFC or the
requesting Gnutella version is not 0.4 or 0.6.
This signature detects requests to a BitTorrent tracker
website. Users may be querying the tracker to look for files
to download.
This signature detects 'scrape' requests to a BitTorrent
tracker website. Users may be querying the tracker to look
for files to download.
This signature detects use of the Direct Connect Plus Plus
(DC++) file sharing client.
This signature detects version checks by eDonkey 2000, a
peer-to-peer file sharing client. The eDonkey client
occasionally checks its own version number to ensure that
the client is current.
This signature detects Gnutella client connection requests.
Because Gnutella does not use a fixed port number, this
signature searches TCP connections to port 1024 and higher
by default.
This signature detects GNUTella server responses to a
connection request. Because GNUTella does not use a fixed
port number, this signature searches TCP connections to
port 1024 and higher by default.
This signature detects Gnutella server responses to a
connection request. Because Gnutella does not use a fixed
port number, this signature searches TCP connections to
port 1024 and higher by default.
This signature detects activity by the peer-to-peer (P2P) file
sharing client MLDonkey, a multi-protocol P2P file sharing
application.
This signature detects a Skype client request (to a central
server) that checks for the latest version of the client
software.
Appendix E: Log Entries
info
sos5.1.0
info
sos5.1.0
info
sos5.1.0
info
sos5.1.0
info
sos5.1.0
info
sos5.1.0
info
sos5.1.0
info
sos5.1.0
info
sos5.1.0
info
sos5.1.0
info
sos5.1.0
info
sos5.1.0
info
sos5.1.0
905

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network and security manager 2010.3

Table of Contents