[Security Concepts]
Which telemetry data captures variations seen within the flow, such as the packets TTL, IP/TCP flags, and payload length?
The telemetry information consists of three types of data:
+ Flow information: This information contains details about endpoints, protocols, ports, when the flow started,
how long the flow was active, etc.
+ Interpacket variation: This information captures any interpacket variations within the flow. Examples include
variation in Time To Live (TTL), IP and TCP flags, payload length, etc
+ Context details: Context information is derived outside the packet header. It includes details about variation in buffer utilization, packet drops within a flow, association with tunnel endpoints, etc.
Leonida
Tashia
5 days agoElmira
10 days ago