NEW

2024 True Cost of a Security Breach

Arrow pointing right
ExtraHop Logo
  • Productschevron right
  • Solutionschevron right
  • Why ExtraHopchevron right
  • Blogchevron right
  • Resourceschevron right

Network Protocols Glossary

What is a network protocol? Protocols are the rules of the road for how data exists and moves on the network. They allow many different systems and computers to communicate.

Protocol Supported

ActiveMQ Protocol

September 4, 2024

ActiveMQ is an open source protocol developed by Apache which functions as an implementation of message-oriented middleware (MOM).

Protocol Supported

BGP Protocol

September 4, 2024

The Border Gateway Protocol is a mechanism by which autonomous systems exchange routing and reachability information on the internet

Protocol Supported

CIFS Protocol

September 5, 2024

It is a specific version of SMB which was developed by Microsoft in 1996 and rebranded as the Common Internet File System.

Protocol Supported

Citrix ICA Protocol

September 4, 2024

Citrix Independent Computing Architecture (Citrix ICA) is a proprietary protocol for an application server system.

Protocol supported

Constrained Application Protocol

September 6, 2024

CoAP is a specialized web transfer protocol designed specifically for nodes and networks with very limited compute, memory, or battery resources, such as those found in the Internet of Things (IoT).

Protocol supported

DB2 Protocol

September 5, 2024

DB2 is family of data management protocols designed to work with IBM’s RDMS.

Protocol supported

Diameter Protocol

September 5, 2024

Diameter Protocol is a messaging protocol used in telecommunications networks, primarily for authentication, authorization, and accounting (AAA) functions.

Protocol supported

Doman Name System (DNS) Protocol

September 5, 2024

DNS Protocol is a network protocol that translates human-readable domain names (like extrahop.com) into machine-readable IP addresses (like 142.250.184.147).

Protocol supported

Dynamic Host Configuration (DHCP) Protocol

September 5, 2024

DHCP a network protocol that automatically assigns IP addresses and other network configuration parameters to devices on a network.

Protocol supported

Financial Information Exchange (FIX) Protocol

September 5, 2024

FIX protocol is a standardized messaging protocol used in the financial industry for electronic communication between financial institutions, such as broker-dealers, exchanges, and clearing houses.

Protocol supported

Hypertext Transfer (HTTP) Protocol

September 5, 2024

The Hypertext Transfer Protocol is an application protocol for distributed, collaborative, hypermedia information systems that allows users to communicate data on the World Wide Web.

Protocol supported

HealthLevel 7 (HL7) Protocol

September 5, 2024

HL7 (Health Level 7) is a standardized messaging protocol used in healthcare to exchange electronic health information (EHI) between different healthcare systems and applications.

Protocol supported

Internet Control Message (ICMP) Protocol

September 5, 2024

ICMP is a transport layer protocol within TCP which communicates information about network connectivity back to the source of the compromised transmission.

Protocol supported

Internet Inter-ORB Protocol

September 6, 2024

Internet Inter-ORB Protocol, is a network protocol used for communication between distributed objects. It serves as the underlying mechanism for the Common Object Request Broker Architecture (CORBA). CORBA is a standard for distributed object computing that allows software components written in different languages and running on different platforms to interact with each other seamlessly.

Protocol supported

Internet Protocol Flow Information Export

September 6, 2024

IPFIX is a standardized protocol that enables network devices like routers, switches, and firewalls to export aggregated information about network traffic to a central collector for analysis.

Protocol supported

Java RMI

September 6, 2024

Java Remote Method Invocation (RMI) is a mechanism that allows an object residing in one Java Virtual Machine (JVM) to invoke methods on an object running in another JVM.

Protocol supported

Kerberos Protocol

September 5, 2024

Kerberos is an authentication protocol that uses mutual authentication, requiring both the user and server to provide their identities.

Protocol supported

Layer 2 Tunneling (L2TP) Protocol

September 6, 2024

Used to create a tunnel for Layer 2 traffic over a layer 3 network - like building a virtual pipe inside a larger pipe.

Protocol supported

Lightweight Directory Access (LDAP) Protocol

September 5, 2024

LDAP is a standards based application protocol used access and updated distributed directory information services.

Protocol supported

Link-Local Multicast Name Resolution (LLMNR) Protocol

September 6, 2024

LLMNR is a protocol designed to allow devices on a local network to resolve hostnames without relying on a DNS server. It operates at the link layer (Layer 2) of the OSI model, hence the name.

Protocol supported

Memcache Protocol

September 5, 2024

Memcache is a key-value store used by websites to store and retrieve information rapidly, without reloading the information.

Protocol supported

Microsoft NMF

September 6, 2024

Microsoft .NET Message Framing Protocol provides a standardized way to encapsulate messages for transmission. While it's primarily designed to frame SOAP messages, its versatility allows it to be used for other message types as well.

Protocol supported

Microsoft Remote Procedure Call (MSRPC) Protocol

September 5, 2024

Microsoft Remote Procedure Call, also known as a function call or a subroutine call, is a protocol that uses the client-server model that enables one program to request a service from a program on another computer, without having to understand the details of that computer's network

Protocol supported

Mongo DB Protocol

September 5, 2024

MongoDB Protocol is a proprietary network protocol used by MongoDB, a popular NoSQL database. It provides a way for client applications to connect to a MongoDB server and perform database operations.

Protocol supported

MySQL Protocol

September 5, 2024

MySQL Protocol is a proprietary network protocol used by MySQL, a popular relational database management system (RDBMS).

Protocol supported

NT Lan Manager (NTLM) Protocol

September 6, 2024

NTLM is a suite of authentication protocols developed by Microsoft to verify user identities within a network environment.

Protocol supported

NetFlow and SFlow

September 6, 2024

NetFlow, developed by Cisco, is a protocol for collecting and reporting information about IP network traffic. It's a cornerstone of network monitoring, providing granular visibility into network behavior. SFlow is a more open and vendor-neutral alternative to NetFlow.

Protocol supported

Network Basic Input/Output System (NetBIOS) Protocol

September 6, 2024

NetBIOS is widely used in the Microsoft Windows O/S for communication within a local area network for resolving device names to network addresses, file and print sharing, and some applications communication.

Protocol supported

Network File System (NFS) Protocol

September 5, 2024

NFS (Network File System) is a distributed file system protocol that allows clients to access files and directories on a remote server as if they were local to the client machine.

Protocol supported

Oracle Database Protocol

September 5, 2024

Oracle Database Protocol is a proprietary network protocol used by Oracle Database, a popular relational database management system (RDBMS).

Protocol supported

Point-to-Point Tunneling (PPTP) Protocol

September 6, 2024

PPTP is used to establish VPN connections. It creates a virtual private network by encapsulating Point-to-Point (PPP) packets within IP packets.

Protocol supported

QUIC and GQUIC

September 6, 2024

QUIC (Quick UDP Internet Connections) is a modern network protocol designed to provide faster and more reliable internet connections. GQUIC is the original implementation of QUIC developed by Google. It served as the foundation for the standardized QUIC protocol.

Protocol supported

Real-Time Control Protocol with Extended Reports (RTCP XR)

September 5, 2024

RTCP XR is a feature of the Real-time Transport Protocol (RTP) that provides additional information about the quality of a multimedia session.

Protocol supported

Real-Time Transport Protocol (RTP)

September 5, 2024

Real-time Transport Protocol (RTP) is a network protocol used for delivering audio and video data over the internet in real time.

Protocol supported

Remote Authentication Dial-In User Service (RADIUS) Protocol

September 5, 2024

RADIUS (Remote Authentication Dial-In User Service) is a network access control protocol used to authenticate, authorize, and account for users who connect to a network.

Protocol supported

Remote Shell (RSH) Protocol

September 6, 2024

Remote Shell is a legacy protocol used to execute commands on a remote host. It was a popular tool in the early days of networking, providing a basic method for remote administration.

Protocol supported

SAP Adaptive Server Enterprise (SAP ASE) Protocol

September 5, 2024

SAP ASE (Adaptive Server Enterprise) Protocol is a proprietary network protocol used by SAP's Adaptive Server Enterprise database management system (DBMS).

Protocol supported

Secure Sockets (SOCKS) Protocol

September 6, 2024

SOCKS stands for "Socket Secure" and is a networking protocol that allows clients and servers to communicate through a proxy server. The term "secure" refers to the protocol's role in managing and securing network connections.

Protocol supported

Session Initiation Protocol (SIP)

September 5, 2024

Session Initiation Protocol (SIP) is a signaling protocol used to establish, manage, and terminate multimedia sessions, such as voice calls, video conferences, and instant messaging.

Protocol supported

Simple Mail Transfer Protocol (SMTP)

September 6, 2024

SMTP is an asymmetrical protocol that is used to send and receive email by sending messages to a server for forwarding.

Protocol supported

Splunk Protocol

September 6, 2024

Splunk actually utilizes several underlying protocols such as DNS, HTTPS, Netflow and SNMP for numerous functions related to ingesting, processing, and correlating data from various sources, including network devices.

Protocol supported

Teletype Network Protocol (Telnet)

September 6, 2024

Telnet provides command line interface for communication with remote devices or servers, used for remote management and initial setup of devices like network hardware.

Protocol supported

Transmission Control Protocol (TCP)

September 6, 2024

TCP (Transmission Control Protocol) is a reliable, connection-oriented protocol used for transporting data over the internet.

Protocol supported

Trivial File Transfer (TFTP) Protocol

September 6, 2024

Trivial File Transfer Protocol (TFTP) is a basic, lightweight protocol designed for transferring files between a client and a server over a network.

Protocol supported

Web Services Management (WSMAN) Protocol

September 6, 2024

Web Services Management is a standardized protocol for managing computer systems and network devices. It's essentially a framework for exchanging management data between different systems.

Protocol supported

Windows Management Instrumentation (WMI) Protocol

September 6, 2024

WMI is a Microsoft-specific implementation of the Web-Based Enterprise Management (WBEM) standard. WMI allows you to gather information about and control various components of a Windows system.

Protocol supported

Windows New Technology Lan Manager (NTLM) Protocol

September 6, 2024

NTLM is a common authentication protocol used on networks running Windows.

Protocol supported

Windows Update Delivery Optimization WUDO Protocol

September 6, 2024

Windows Update Delivery Optimization (WUDO) protocol is built into Windows operating systems and was designed to optimize the distribution of updates and applications.

Protocol supported

Wireguard Protocol

September 6, 2024

WireGuard is a modern, open-source VPN protocol designed with simplicity, performance, and security in mind.

Protocols we decode

ExtraHop decodes the following enterprise protocols with real-time fluency at the application layer. Protocol modules offer varying levels of analysis, starting with L7 classification, and Application Inspection Triggers allow you to create a custom metric.

AAA: Diameter

AAA: RADIUS

ActiveMQ

AJP

ARP

BitTorrent

CFP

CIFS

Citrix ICA*

CoAP

Cryptocurency mining protocols

Database: DB2

Database: Informix

Database: Microsoft SQL

Database: MongoDB

Database: MySQL

Database: Oracle

Database: Postgres

Database: Redis

Database: Riak

Database: Sybase

Database: Sybase IQ

DHCP

DICOM*

DNS

DSCP

FIX*

FTP

GENEVE

GRE

HL7 (including FHIR and ICD-0-10)*

HTTP-AMF

HTTP/S

IBM MQ

ICMP

ICMP6

IEEE 802.1X

IIOP

IKE

IMAP

IPFIX

IPSEC

IPX

IRC

ISAKMP

iSCSI

Java RMI

Kerberos

L2TP

LACP

LDAP

LLDP

LLMNR

Memcache

Microsoft NMF

Modbus

MPLS

MS-RPC

MSMQ

Netbios

NetFlow and SFlow

NFS

NTLM

NTP

NVGRE

OpenVPN

PCoIP

POP3

PPTP

QUIC and GQUIC

RDP

RFB (VNC)

RSH

Skinny (SCCP)

SMPP*

SMTP

SNMP

SOCKS

Splunk

SSH

SSL

STP

Syslog

TCP

Telnet

TFTP

TRILL

VNC

VoIP: RTCP*

VoIP: RTCP XR*

VoIP: RTP*

VoIP: SIP*

VXLAN

Websocket

Windows Update Delivery Optimization

WireGuard

WMI

WSMAN

*Not included in Reveal(x) 360 base license

Is ExtraHop the right solution for your IT infrastructure?