Johannes B. Ullrich jullrich at sans.org
Thu Jun 5 04:37:58 GMT 2003

Good catch. Microsoft does use Akamai for it's updates. The connection
looks like a regular http access otherwise (from port 80 to port 3154... just the return packet from the server)

Depending on the firewall used, this may be a case of 'expired state'.
If the server (Akamai in this case) was slow to respond, the firewall
forgot about the outgoing request by the time the reply comes back.
As a result, the reply is flagged as a new connection attempt.

