A partner protocol has no analyzer: do you parse it or byte-match it, and what does each cost when an intruder adapts?
answer
- what survives after the adversary adapts
- alerts answer only pre-asked questions
- records outlive the question that motivated them
- a parser is attack surface you maintain
- partial parser extracting three fields
basics
~20 sByte matching ships this week, costs almost no state, and dies silently the day a byte changes. An analyzer gives durable session facts and answers to questions you never anticipated, but costs per-session state and permanent maintenance on a format the partner controls.
solid answer
~50 sFrame it as what each posture still gives you after the adversary adapts. A `content` rule over the raw payload is cheap and immediate, but it answers only the question you asked in advance: change the marker, pad it, split it across segments or compress the payload and the rule is silently retired, with no signal that it stopped matching. An analyzer converts the stream into typed session facts - what was requested, which files moved, how large, hashed - so you can ask new questions later, over traffic already recorded. Its price is per-session and per-file state, CPU, and a parser you must maintain against a format the partner can change without telling you, in code that consumes hostile input by design. The defensible answer is staged: byte-match now for the behaviour you can name, and invest in an analyzer only if the interface needs records rather than alerts.
go deeper
Know that a byte rule is quick and fragile while a parser produces records for every session, and that only one of the two needs someone to understand the protocol.
Explain the state and maintenance cost of an analyzer and the silent-failure mode of a content match, and be able to say what each still gives you after the traffic changes.
Stage the answer - free connection records, then instrumented byte rules, then a scoped partial parser only where the interface earns it - and name the failure design for each stage.
Be ready to argue the ongoing ownership: who maintains a parser for a format a counterparty controls, what you do when that person leaves, and what you tell the business when the parser breaks and takes the interface's records with it.
## The decision, stated honestly A partner extranet carries a bespoke protocol. No vendor analyzer exists. You have a sensor and a week. The interview question is not which tool is better; it is what you still have three months later when the traffic has changed and an intruder has noticed you. ## What byte matching buys and what it costs **Buys:** a working detection within hours. No protocol understanding required, no state beyond what the engine already keeps, and it applies to any protocol including ones nobody has named. It is also the only option that survives when you cannot get a specification out of the partner. **Costs:** - *Brittleness with no signal.* The rule is a search for bytes you chose. A version bump that reorders a field, an added length prefix, compression turned on, or an intruder padding their payload retires the rule silently. Nothing errors; the alert count simply goes to zero, which looks exactly like a clean environment. - *It answers only the question you asked.* When an investigator asks in October what moved through this interface in August, an alert-only posture has nothing to offer unless a rule happened to fire. - *Evasion is cheap.* Splitting a marker across segments, or varying it, defeats an anchored content match without any sophistication. ## What an analyzer buys and what it costs **Buys:** typed records for every session, produced before anyone is suspicious. That changes the class of question you can answer - volumes per file, hashes you can compare against a later indicator, unusual request types, a transfer at an hour the partner never uses - and it lets you write new detections over history rather than only over the future. **Costs, and be explicit about all four:** - *State.* A record per connection and per file in flight; the ceiling arrives on concurrency, and it is your memory budget. - *Maintenance on someone else's schedule.* The partner owns the format. A change breaks your parser, and unlike a signature, a broken parser can fail loudly and stop producing records for the whole interface. - *Attack surface.* A parser consumes hostile input by design. A bug in it is a vulnerability in a device that sits on your monitoring path, and the fix is yours to write. - *Skills and continuity.* One engineer who understands both the wire format and the analyzer framework is a single point of failure that outlives their tenure. ## The framing that scores Say the two failure modes out loud, because they are not symmetric: | Posture | What an intruder does to defeat it | What you have left afterwards | | --- | --- | --- | | Byte match | Changes or splits the matched bytes | A connection record; no alert, no signal that the rule died | | Analyzer | Speaks the protocol correctly and hides in legitimate volume | Full session and file records to hunt over later | The analyzer does not stop a determined adversary either - it makes them use the protocol properly, which is precisely what leaves evidence. That is the argument for parsing, and it is stronger than any claim about detection rates. ## Staging the decision A good answer does not pick one and stop. It stages: 1. **Now:** connection records for the interface, which you already get free, plus baselines on volume, timing and peer set. Most partner-integration surprises are visible at that layer. 2. **This week:** byte rules for the specific behaviours you can name, understood as temporary and instrumented - track match counts over time so a silent drop to zero is itself an alert, rather than a comfort. 3. **Only if the interface earns it:** an analyzer, scoped to extract a handful of facts you have decided you need - file boundaries, sizes, names, hashes - rather than a complete implementation of the protocol. A partial parser that extracts three fields and refuses everything else is cheaper, safer and easier to maintain than a faithful one. ## The thing candidates most often get wrong They argue parsing is strictly superior. It is not, and the extranet is the case that proves it: for a protocol nobody has parsed, the byte matcher still has a usable hook and the parser has only a connection record. The two postures fail differently, and the reason to prefer parsing where you can afford it is not detection power - it is that records outlive the questions that motivated them, and alerts do not.
- How do you detect that a byte rule on the partner protocol has silently stopped matching?Trend the rule's own match count as a metric and alarm on a sustained drop to zero on an interface whose traffic volume has not fallen. Pair that with the connection records for the same interface, so you can say the sessions are still happening while the rule is no longer firing. Without that pairing, zero alerts and a healthy environment are indistinguishable.
- Your parser breaks when the partner changes their format. What is the failure mode you must design against?Losing records for the entire interface rather than losing one detection. Design the analyzer to fail closed on parsing but open on logging: if the grammar does not match, still emit the connection record and a marked parse-failure count, so the outage is visible and bounded. A parser that dies quietly is worse than never having written one, because everyone downstream assumes the records are complete.
- What would make you refuse to write an analyzer at all for this interface?If the traffic is end-to-end encrypted so there is nothing above transport to parse; if the interface carries low value or low volume relative to the maintenance debt; if no one can commit to owning the parser after the person who wrote it leaves; or if the partner will not commit to notifying you of format changes, which makes the parser a permanently unstable dependency on someone else's release schedule.
saying these in an interview costs you the question
- Argues protocol parsing is strictly better in every case
- Ignores that a broken byte rule fires no error
- Forgets a parser is attack surface consuming hostile input
- Treats analyzer maintenance as a one-off project cost
- Assumes the partner will announce wire-format changes