Suspicious Conversation Analysis

We know normal HTTP traffic goes by port 80 and FTP 21, etc. Chances are you may block a instant messenger port while HTTP port 80 is open, and one user in your network may change his messenger's port to 80. Then he can use his messenger to chat again.

To your firewall, its traffic may seem legal but Capsa will analyze all the HTTP, POP3, FTP and SMTP traffic. If the traffic doesn't match the original format of the protocol, it's reported as suspicious conversation.

Back

Copyright © 2001 - 2011 Colasoft. All rights reserved.