Skip to main content
Version: Version 8.0

P2P Analytics

The P2P Analytics dashboard provides a breakdown of peer-to-peer traffic detected on your network. It correlates traffic-level data with IDS and blacklist alerts to give both a volume view and a security view of P2P activity.

navigation

šŸ‘‰ Go to NBAD → P2P Analytics

P2P Analytics Dashboard Figure: P2P Analytics: alert counts, BitTorrent, Tor, Gnutella, eMule traffic charts, and live IDS/BL alerts

Breakdown of peer-to-peer traffic on the network. Correlates traffic-level data with IDS and blacklist alerts to provide both a volume view and a security view of P2P activity.

Alert count tiles​

TileSourceDescription
User Alerts CountTrisul user alertsTotal number of active user-defined alerts currently configured in the system.
System Alerts CountTrisul self-monitoringSystem-generated alerts from Trisul internal monitoring, including events such as packet drops, memory pressure, or resource exhaustion.
BL Alert CountThreat intelligence feedsBlacklist alerts triggered by connections matching known malicious IPs, domains, or Tor exit nodes.
IDS Alert CountIDS (e.g. Suricata)Intrusion detection alerts generated by the integrated IDS engine.

Traffic modules​

ModulesProtocols / PortsDescription
BitTorrent Client Traffic6881, 51413, 51414Time-series view of BitTorrent traffic across tracked ports. Traffic spikes typically indicate active torrent sessions. Different traffic phases such as DHT activity, peer exchange, and payload transfer can often be inferred from port behaviour.
Tor (Onion)9050, 9150, 9001, 9030Traffic observed on commonly used Tor ports. Persistent Tor communication originating from internal hosts is often considered a high-confidence indicator of policy violations, anonymization attempts, or evasion activity.
Gnutella Traffic6346, 6347Time-series monitoring of Gnutella peer-to-peer traffic activity.
eMule/eDonkey Traffic4661, 4662, 4665, 4672Tracks eMule/eDonkey traffic across characteristic protocol ports including kar2ouche (4661), oms (4662), contclientms (4665), and rfa (4672).
D²D / P2PVariousGeneric peer-to-peer traffic counter tracking aggregate P2P communication flows across multiple protocols and ports.

Alert feed Modules​

ModulesAlert typeDescription
IDS P2P AlertsIDS signaturesLive feed of IDS alerts classified as peer-to-peer activity. Entries include alert signature, description, timestamp, source and destination IPs/ports, and probe information. Example signatures include ET P2P BitTorrent DHT announce_peers request and ET P2P BitTorrent DHT nodes reply.
BL AlertsBlacklist / threat intelDisplays connections matching known Tor nodes or blacklisted infrastructure. Entries include indicator type (such as TOR-NODE), remote IP, destination port, resolved hostname, timestamp, probe, and endpoint details.