Using PDLM in Conjunction with NBAR to Classify Network Attacks

Protocol Description Language Module (PDLM) is used to allow support for new protocols that are not supported natively by the Cisco IOS Software NBAR code that a router is running. There are three main reasons for having PDLMs available:

  • They allow the capabilities of the native Cisco IOS Software NBAR to be enhanced without the need for a complete reimaging or reload of the router.

  • Support for new protocols becomes available more quickly to Cisco customers through PDLMs, without their having to wait for a new Cisco IOS Software release incorporating the new protocols in its NBAR code.

  • Custom PDLMs allow network administrators to define their own protocol and port number pairs. NBAR ...

Get Network Security Principles and Practices now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.