Title | DPI Solutions in Practice: Benchmark and Comparison |
Publication Type | Conference Paper |
Year of Publication | 2021 |
Authors | Rescio, Tommaso, Favale, Thomas, Soro, Francesca, Mellia, Marco, Drago, Idilio |
Conference Name | 2021 IEEE Security and Privacy Workshops (SPW) |
Date Published | may |
Keywords | deep packet inspection, DPI, Inspection, Malware, privacy, Protocol Recognition, Protocols, pubcrawl, resilience, Resiliency, Scalability, security, Steady-state, Tools, Traffic analysis |
Abstract | Having a clear insight on the protocols carrying traffic is crucial for network applications. Deep Packet Inspection (DPI) has been a key technique to provide visibility into traffic. DPI has proven effective in various scenarios, and indeed several open source DPI solutions are maintained by the community. Yet, these solutions provide different classifications, and it is hard to establish a common ground truth. Independent works approaching the question of the quality of DPI are already aged and rely on limited datasets. Here, we test if open source DPI solutions can provide useful information in practical scenarios, e.g., supporting security applications. We provide an evaluation of the performance of four open-source DPI solutions, namely nDPI, Libprotoident, Tstat and Zeek. We use datasets covering various traffic scenarios, including operational networks, IoT scenarios and malware. As no ground truth is available, we study the consistency of classification across the solutions, investigating rootcauses of conflicts. Important for on-line security applications, we check whether DPI solutions provide reliable classification with a limited number of packets per flow. All in all, we confirm that DPI solutions still perform satisfactorily for well-known protocols. They however struggle with some P2P traffic and security scenarios (e.g., with malware traffic). All tested solutions reach a final classification after observing few packets with payload, showing adequacy for on-line applications. |
DOI | 10.1109/SPW53761.2021.00014 |
Citation Key | rescio_dpi_2021 |