Question : ntopng application traffic breakdown

I’ve been experimenting with ntopng’s feature that lets you view application usage on a particular host. In this case my Apple TV to view the amount of traffic certain streaming services are consuming.

I have attached a screen shot, and you’ll see the top 4 are :

  1. TLS
  2. Netflix
  3. YouTube
  4. DisneyPlus

Through process of elimination and monitoring the data usage while it’s happening, I think I can safely assume that the TLS is actually coming from DisneyPlus.
I have 2 conclusions in particular :

  1. The 51.06 MB is being calculated from navigating through the menu’s of the app, which leads me to believe the data comes from loading thumbnail images and other associated information you can view while you’re deciding which video content to stream.
  2. The 6.61 GB is calculated from the video content itself being streamed.

My Question : why would there be these 2 categories for the same app, and more specifically, why would the actual streaming of the content be categorized as TLS?

Thanks in advance!

TLS traffic is encrypted. Which means the headers are encrypted. Which is why you are seeing a lot of traffic being categorized as TLS.

1 Like

As @xMAXIMUSx explained TLS stands for TLS-encrypted traffic. As a result ntopng cannot give you more details on that traffic. As a result, TLS basically is a catchall for traffic where ntopng cannot give you details because the traffic is encrypted.