Previous Topic: Filter Groups

Next Topic: Installing the NBA Software

Application Protocols

NBA application filters can detect data packets transmitted using the following protocols:

IM protocols

IM_ALL

All recognized instant message formats.

AOLIM, ICQIM

AOL and ICQ instant messages.

Both these protocol options detect the same protocol in the NBA because AOL instant messages use the ICQ protocol. AOL instant messages are usually encrypted.

JABBERIM

Jabber (XMPP) instant messages. Can be decrypted from SSL sessions.

MSNIM

MSN instant messages.

SIPIM

Instant messages sent using an application that uses the Session Initiation Protocol (SIP).

YAHOOIM

Yahoo! instant messages.

Note: Many of these protocols may be encrypted and some cannot currently be detected by the NBA. However, the presence or absence of encryption varies from one IM client version to another and may also depend on account preference settings.

Email and Webmail protocols

AOLMAIL

Outbound messages sent using AOL Mail.

DELTASYNC

Outbound messages sent using Windows LiveMail.

To capture all Windows LiveMail messages, you must also use the HOTMAIL protocol.

GMAIL

Outbound messages sent using Gmail (or Google Mail). These messages can be decrypted from SSL sessions.

HOTMAIL

Outbound messages sent using Microsoft Hotmail or Windows LiveMail. These messages can be decrypted from SSL sessions.

To capture all Windows LiveMail messages, you must also use the DELTASYNC protocol.

POP3

Messages received using an email client that uses the POP3 protocol (most commonly, Outlook Express).

SMTP

Messages sent using SMTP (Simple Mail Transfer Protocol). This typically includes messages sent over the Internet from an Exchange or Domino server, or sent from an email client such as Outlook Express. These messages can be decrypted from SSL sessions.

SMTPDEST

Messages sent to specified destinations using SMTP. These messages can be decrypted from SSL sessions.

You must list the destination IP addresses in the filter definition.

SMTPSRC

Messages received from specified destinations using SMTP. These messages can be decrypted from SSL sessions.

You must list the source IP addresses in the filter definition.

WEBMAIL

Messages sent using a Webmail protocol that is decoded by the NBA. These include AOL Mail, Gmail (or Google Mail), Hotmail, Windows Live Mail and Yahoo! Mail.

Note the NBA can only detect outbound (sent) messages. It cannot detect inbound messages, arriving in a user’s Webmail inbox.

YAHOOMAIL

Outbound messages sent using Yahoo! Mail.

File protocols

FTP

Files transferred using FTP (File Transfer Protocol).

FTPGET

File transfers over FTP downloaded from a server.

FTPPUT

File uploads over FTP.

HTTPGET

Files downloaded from a Web site. These messages can be decrypted from SSL sessions.

HTTPPOST

Files uploaded to a Web site. These messages can be decrypted from SSL sessions.

HTTPURL

Web browsing. The NBA detects HTML Web pages requested from a Web site, including a URL plus the first HTML packet downloaded. These messages can be decrypted from SSL sessions.

SMB

Files accessed on a remote server using the SMB protocol.

The NBA can detect and block attempts to browse remote files, but it cannot analyze the contents of those files.

Other protocols

ALL

You can configure the NBA to detect all known application protocols.

SKYPE

Instant messages, file transfers, SMS messages and streamed audio or video transmitted using Skype software.

The NBA can detect the start of Skype sessions, but it cannot analyze their content or block the packets.

NNTPGET

Messages read from a news group using the Network News Transfer Protocol (NNTP).

NNTPPOST

Messages posted to a news group using the Network News Transfer Protocol (NNTP).