nDPI
nDPI copied to clipboard
Monitoring: improvements
https://github.com/ntop/nDPI/pull/2588 added "monitoring" feature to nDPI. Let use this ticket to keep track of some possible improvements:
From @utoni
use that specific behavior for other protocols e.g. suspicious TLS or BitTorrent flows
Do you think that it would make sense to also provide an API in which makes it possible to dynamically add a certain flow to the "special observation treatment" and dissect literally all packets of it?