IDS mailing list archives

bittorrent file transfer - rate limit


From: "Ravi Chunduru" <ravi.is.chunduru () gmail com>
Date: Sun, 7 Oct 2007 09:27:29 -0700

i am trying to use IntroPro-IPS to limit bittorrent traffic to 20% of
my bandwidth.

it is able to detect file transfer traffic in many cases using rules
given as part of product distribution. if i use bittorrent (downloaded
from www.bittorrent.com) i could see that this p2p traffic is not
exceeding 20% limit (100kbps). but if i use other client application
such as azureus or uTorrent, i find that bittorrent data traffic is
not recognized for some torrents.

this product has facility to add new rules to detect application
traffic. i tried to add new rules with patterns from bleedingthreats
and l7 filters and results are same. does anybody have right patterns
to detect all kinds of bittorrent file transfer connections?

thanks
Ravi

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it 
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw 
to learn more.
------------------------------------------------------------------------


Current thread: