Deep packet inspection (DPI) is a way for a network device to look inside the traffic passing through it, not just at the addresses and port numbers on the outside. By examining the contents and behaviour of the traffic, the device can tell which application it belongs to and spot known attack patterns or malware, then allow, block, log or prioritize it. DPI is a technique built into many products rather than a product of its own, most often found in next-generation firewalls, intrusion prevention systems and SD-WAN appliances.
At a glance
- DPI inspects traffic contents and behaviour, where basic filtering looks only at source, destination and port.
- It is a capability inside products such as firewalls, intrusion prevention systems, secure web gateways and SD-WAN devices.
- Security uses include identifying applications, matching threat signatures and enforcing content rules; network uses include traffic prioritization.
- Encrypted traffic limits what DPI can see unless the device also decrypts it.
- It takes significant processing power, so performance with DPI features turned on is a key sizing question.
What problem it solves
Older firewalls made decisions based on ports and addresses: web traffic on port 443 was allowed, other ports were blocked. Today almost everything, from file sharing and video calls to remote access tools and malware command channels, runs over the same few web ports. A port-based rule can’t tell a business application from a risky one, or a normal download from a malicious one.
DPI closes that gap by recognizing what the traffic actually is. That lets a business write rules such as “allow the video conferencing app, block personal file sharing,” and lets security features match traffic against known exploit and malware patterns. On the network side, it lets an SD-WAN device recognize voice and video and send them over the best available link, instead of treating every packet the same.
How it works
Reassembly. Traffic crosses the network in many small packets. The inspecting device puts related packets back into a conversation (a flow) so it can examine the content as a whole rather than one fragment at a time.
Application identification. The device compares the flow against a library of application signatures and behaviours: protocol details, the destination name requested during connection setup, certificate data and patterns in the traffic. The vendor updates this library as applications change.
Threat matching. Security features check the content against signatures for known exploits, malware and suspicious behaviour. This is the core of an intrusion prevention system (IPS), and many network firewalls include the same function.
Policy action. Based on what it finds, the device allows, blocks, logs, rate-limits or prioritizes the traffic, for example marking voice traffic for quality of service (QoS) handling.
Encrypted traffic. Most traffic is now encrypted, which hides its contents. DPI can still classify much of it from unencrypted metadata, but full content inspection requires TLS inspection, where the device decrypts, inspects and re-encrypts the traffic.
When it matters for buyers
- When replacing or sizing a firewall. Throughput with application control, threat prevention and decryption enabled is often much lower than the headline figure on a datasheet. Our network firewalls overview covers how to compare models on equal terms.
- When rolling out SD-WAN. Application-aware routing depends on how well the device recognizes the applications you use.
- When the security team wants application control. Blocking or limiting categories of applications depends on DPI accuracy and on how current the vendor’s signatures are.
- When privacy or regulation is a concern. Content inspection may need policy, employee notice and exclusions, depending on where you operate.
- When a cyber insurer or auditor asks about intrusion prevention. DPI-based threat prevention is often how that control is met.
Questions to ask vendors
- What is the throughput with application control, intrusion prevention and TLS inspection all enabled, at our expected traffic mix?
- How many applications can you identify, how often are signatures updated, and what does the update subscription cost?
- How do you classify encrypted traffic without decrypting it, and how accurate is that?
- Can we create custom application signatures for in-house or niche software?
- How do you handle traffic you can’t identify: allow, block or flag it?
- What visibility and reporting do we get on applications and threats seen?
- How do we exclude sensitive traffic categories from inspection?
How it differs from an intrusion prevention system (IPS)
DPI is the technique; an IPS is one product or feature that uses it. An IPS uses deep packet inspection specifically to detect and block attacks, matching traffic against exploit signatures and suspicious behaviour. DPI is also used for purposes that have nothing to do with attacks, such as identifying applications for SD-WAN routing or for reporting on bandwidth use. Many next-generation firewalls and unified threat management (UTM) appliances bundle IPS, application control and other DPI-based features in one device, usually licensed through a security subscription.
