Hi,
I'm trying to identify applications which generate
those traffic on our border routers. I use sampled
netflow as data source and some flow-tools as
analizer.
Currently, I use (protocol, port_number) as indicator
of application. Referring to rfc on wellknown protocol
and port allocation, I can only identity about 50% of
traffic type.
Is there a complete (protocol, port_number) list ? or
is there a better way to identify application type
based on netflow data?
regards
Joe