Detecting TOR Communication in Network Traffic
April 7th, 2013That’s a pretty good one. I wonder what it can tell about what’s running over VPN links…
Via: Netresec:
Notice how the flows to TCP ports 80, 9101 and 443 are classified as Tor? The statistical method for protocol detection in CapLoader is so effective that CapLoader actually ignores port numbers altogether when identifying the protocol.
