Decryption of internet traffic against Man-in-the-middle attacks, among others, along with TLS 1.3 server certificate encryption, creates a significant load on firewalls. To reduce this, Snort 3 utilizes machine learning to determine the application (client process) generating the Client Hello packet, identifies known processes/browsers – thereby providing a path from now on to reduce the number of decryption events needed.