1. There are two kinds of bittorrent traffic: encrypted and unencrypted. OpenDPI can only detect the unencryted bittorrent traffic. The commercial Version of OpenDPI, PACE, also provides a detection for encrypted bittorrent traffic. For the encrypted bittorrent detection statistical analysis is necessary.
Bittorrent behaves like this: when the unencrypted traffic is blocked, bittorrent traffic becomes encrypted. That is why blocking with OpenDPI cannot work so well.
The commercial version PACE is able to detect and to block all bittorrent traffic correctly.
2. This depends on the traffic that you have captured: when it contains many encrypted bittorrent traffic, OpenDPI will mark this traffic as unknown. Another thing is that OpenDPI cannot classify connections that do not start with the first packet. If you want, you can send your pcap to me, I could have a quick look into it and tell you why it contains so many unknown traffic.
Best Regards, Katrin
--
Katrin Pflugfelder | Product Manager | ipoque
Mozartstr. 3 | 04107 Leipzig | Germany
phone + 49-341 - 59 40 3 - 0
fax +49-341 59 40 3 - 019 | web www.ipoque.com
trade register Amtsgericht Leipzig HRB21462
Gesellschaft mit beschränkter Haftung (GmbH)
board Klaus Mochalski, Hendrik Schulze, Dr. Frank Stummer
Networkshop 39, Hertfordshire, 12 - 14 April 2011
ipoque Executive Blog at http://blog.ipoque.com