High Entropy is a virtual protocol used to detect potentially encrypted payloads. Important note: the classification of this layer is effective since the 4.18.0 version of the ixEngine framework. The classification is based on two methods: entropy value computation, and printable strings detection. This concerns only unknown sessions over tcp and udp.
Family: | Behavioral |
Over: | unknown |
Revision: | 3 |
Risk level: | 1 |
Tag: | Not Used |