What Is DPI (Deep Packet Inspection)?

Also called: Packet content inspection

Related problems: Our firewall only sees ports and IP addresses, not what the traffic actually is; Need to block risky applications that all run over the same web ports; Want SD-WAN to prioritize voice and video over everything else; Firewall slows down badly when security features are switched on

Deep packet inspection (DPI) is a way for a network device to look inside the traffic passing through it, not just at the addresses and port numbers on the outside. By examining the contents and behaviour of the traffic, the device can tell which application it belongs to and spot known attack patterns or malware, then allow, block, log or prioritize it. DPI is a technique built into many products rather than a product of its own, most often found in next-generation firewalls, intrusion prevention systems and SD-WAN appliances.

At a glance

  • DPI inspects traffic contents and behaviour, where basic filtering looks only at source, destination and port.
  • It is a capability inside products such as firewalls, intrusion prevention systems, secure web gateways and SD-WAN devices.
  • Security uses include identifying applications, matching threat signatures and enforcing content rules; network uses include traffic prioritization.
  • Encrypted traffic limits what DPI can see unless the device also decrypts it.
  • It takes significant processing power, so performance with DPI features turned on is a key sizing question.

What problem it solves

Older firewalls made decisions based on ports and addresses: web traffic on port 443 was allowed, other ports were blocked. Today almost everything, from file sharing and video calls to remote access tools and malware command channels, runs over the same few web ports. A port-based rule can’t tell a business application from a risky one, or a normal download from a malicious one.

DPI closes that gap by recognizing what the traffic actually is. That lets a business write rules such as “allow the video conferencing app, block personal file sharing,” and lets security features match traffic against known exploit and malware patterns. On the network side, it lets an SD-WAN device recognize voice and video and send them over the best available link, instead of treating every packet the same.

How it works

Reassembly. Traffic crosses the network in many small packets. The inspecting device puts related packets back into a conversation (a flow) so it can examine the content as a whole rather than one fragment at a time.

Application identification. The device compares the flow against a library of application signatures and behaviours: protocol details, the destination name requested during connection setup, certificate data and patterns in the traffic. The vendor updates this library as applications change.

Threat matching. Security features check the content against signatures for known exploits, malware and suspicious behaviour. This is the core of an intrusion prevention system (IPS), and many network firewalls include the same function.

Policy action. Based on what it finds, the device allows, blocks, logs, rate-limits or prioritizes the traffic, for example marking voice traffic for quality of service (QoS) handling.

Encrypted traffic. Most traffic is now encrypted, which hides its contents. DPI can still classify much of it from unencrypted metadata, but full content inspection requires TLS inspection, where the device decrypts, inspects and re-encrypts the traffic.

When it matters for buyers

  • When replacing or sizing a firewall. Throughput with application control, threat prevention and decryption enabled is often much lower than the headline figure on a datasheet. Our network firewalls overview covers how to compare models on equal terms.
  • When rolling out SD-WAN. Application-aware routing depends on how well the device recognizes the applications you use.
  • When the security team wants application control. Blocking or limiting categories of applications depends on DPI accuracy and on how current the vendor’s signatures are.
  • When privacy or regulation is a concern. Content inspection may need policy, employee notice and exclusions, depending on where you operate.
  • When a cyber insurer or auditor asks about intrusion prevention. DPI-based threat prevention is often how that control is met.

Questions to ask vendors

  • What is the throughput with application control, intrusion prevention and TLS inspection all enabled, at our expected traffic mix?
  • How many applications can you identify, how often are signatures updated, and what does the update subscription cost?
  • How do you classify encrypted traffic without decrypting it, and how accurate is that?
  • Can we create custom application signatures for in-house or niche software?
  • How do you handle traffic you can’t identify: allow, block or flag it?
  • What visibility and reporting do we get on applications and threats seen?
  • How do we exclude sensitive traffic categories from inspection?

How it differs from an intrusion prevention system (IPS)

DPI is the technique; an IPS is one product or feature that uses it. An IPS uses deep packet inspection specifically to detect and block attacks, matching traffic against exploit signatures and suspicious behaviour. DPI is also used for purposes that have nothing to do with attacks, such as identifying applications for SD-WAN routing or for reporting on bandwidth use. Many next-generation firewalls and unified threat management (UTM) appliances bundle IPS, application control and other DPI-based features in one device, usually licensed through a security subscription.

Frequently Asked Questions

Can DPI see inside encrypted traffic?
Not the contents, unless the traffic is decrypted first. Without decryption, DPI can still use unencrypted details such as the destination name in the connection setup, certificate information and traffic patterns to identify many applications. To inspect the actual content for threats, the device has to decrypt it, which is what TLS inspection does.
Does DPI slow down the network?
It can. Inspecting content takes far more processing than checking addresses, so throughput with DPI-based features turned on is often much lower than a device's headline firewall figure. Size devices on the vendor's published throughput with the features you will use enabled, and test with your own traffic where you can.
Is DPI only a security feature?
No. The same technique identifies applications so SD-WAN and other network devices can route and prioritize traffic, for example giving voice calls priority over large downloads. Service providers have also used it for traffic management and reporting.
Do we need to tell employees we use DPI?
Inspecting traffic content can raise privacy and employment-law questions, and the rules vary by country and state. Many organizations cover network monitoring in an acceptable use policy and exclude sensitive categories such as banking or health sites from decryption. Check with counsel for the places where you have staff.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.