The outdated concept of perimeter security is incompatible with today's organizations, and signature/content based security is ineffective. Deep Packet Inspection (DPI) is a crucial technology that's answering a question that's been gnawing at the network security community: Is DPI network security really multiple layers of defense? The solution today is in the evolution of DPI, now focusing on more than just "reading the header" to be able to understand the content and communications within today's networks.
Growing Complexity of Modern Network Threats
Spam and simple malware are not the only threat that is part of the threat landscape. The job of it is to give administrators the tool for which is needed -- especially when it comes to encrypted tunnels, application-layer attacks, zero-day and data exfiltration all look like normal traffic. Most firewalls and simple packet filters are not able to prevent attacks in encrypted protocols or when using ports that are not in their configuration. Attack surface has also scaled significantly with cloud services, IoT devices and remote workers. Therefore, there should also be a multi-dimensional barrier at a packet header level, and in the payload. That's where DPI network security will come into play.
Basic Functions of DPI in Network Security
In a network, DPI is able to offer a number of fundamental and necessary security services. Identification of applications is important. DPI can determine what application is causing the flow, such as a web browser, e-mail application, a file sharing application or a dropper for malware. This identification is possible despite the absence of the standard ports or even in case of encryption. There's also protocol decoding which is used to see what is in every application exchange. DPI can handle the parsing of hundreds of different protocol formats, including HTTP requests/response, DNS queries and SMTP commands. Payload inspection is the process of looking at the contents of packets for the presence of threat signatures, and determining if a packet contains exploit code, malicious code strings, or phishing URLs. Behavioral analysis looks at multiple packets for indications of malicious behavior, such as packet size, timing, direction and destination patterns that don't match a known signature. Metadata extraction creates information for each flow that can be used for search, and forensic analysis and for compliance reporting.
How DPI Forms Multi-layered Protection
For multi-dimensional defense barriers there is no need for multiple layers of the network stack, DPI does it all. The network layer will be able to detect unusual IP addresses, port scanning, and DoS attacks. The transport layer has detection capabilities for SYN floods, connection hijacking and unexpected TCP state change. The unique value of DPI on the application layer is monitoring for SQL injection and XSS traffic on web traffic, phishing links in email traffic, as well as unauthorized data exfiltration in file transfers, DGA in DNS traffic, and tunneling in DNS traffic. As well as the protocol layers, DPI also includes a behavioral layer which can detect patterns of traffic that could indicate botnets, staging of data or command and control traffic. It's designed to be multi layered; if one layer misses it, another layer detects it. A simple inspection may not be able to recognize the download of a malware that is embedded in an encrypted (HTTPS) flow, but DPI can recognize it by analyzing the behavior of the traffic pattern.
Real-time Risk Recognition and Early Warning
The DPI network security has an outstanding capability to recognize risks in real time. As packets travel through the network, DPI engines constantly rebuild and scrutinize the packets, matching the patterns with the threat intelligence feeds, behavioral baseline and custom rules. If the anomalies are noticed the system automatically sends alerts, such as when a massive amount of an encrypted traffic is sent to a high-risk geolocation, or when a user tries to log into several servers in a row. These alerts can be used to limit potential threats as they can come before they become larger intrusions. This is a vital feature in DCI and service provider networks.
Streamline Daily Defense Work for Operators
With DPI network security, alert noise is flattened, responses to mundane alerts are automated and useful actionable intelligence is provided to help streamline daily defense tasks. Thousands of alerts can be generated each day, with many of them being false or inconsequential, using the same security products. To eliminate this noise, DPI applies it in the context of the application. For instance, the traffic from a known malicious domain is given a high priority unless it comes from an automated security scanner, then it will be given a low priority. This context is automatically provided by DPI. Routine threats are dealt with by automated responses. A flow with a detected phishing URL can be automatically blocked by DPI, giving more time for the security analysts to work with more complex events. DPI's detailed flow records support a faster forensic investigation. Analysts can now use the DPI metadata to identify exactly what the series of events were before, during and after an incident, without having to stitch together events from multiple logs. For operators with small security teams, these streamlining benefits are no luxury, but a must.
Sino-Telecom DPI Security Deployment Strengths
For multi-dimensional defense barriers, Sino-Telecom offers DPI network security solutions. These DPI platforms support up to 1200 Gbps traffic processing per system, featuring native support for 400GE ports and their DPI signature files can process thousands of apps, and are constantly updated to support the latest apps and protocols. Real-time detection notifies and blocks instantly, in millseconds. Behavioral analysis is able to detect encrypted threats and zero day exploits without signatures. In-line blocking with hardware bypass, out-of-band monitoring and virtualized instances for elastic scaling are options. Sino-Telecom's DPI security solutions are based on more than 240+ patents and 150+ software copyrights. They have been used in over 30 countries including France, Indonesia, Brazil and Australia to demonstrate their performance in various operator environments.
Conclusion
Is it possible to construct a multi-layered security barrier with DPI? Absolutely. DPI penetrates deeply into the payloads of packets, correlates multiple protocol layers, provides real-time early warning, and simplifies everyday tasks, thus turning a passive network into an active, intelligent guard. But its effectiveness is highly dependent on the performance, precision and integration of the underlying platform. Designed for high speed optical networks, data centre interconnects and carrier service provider settings, Sino-Telecom's DPI offerings offer robust, multi-dimensional protection against the modern threats faced by these networks. Request A Quote If you'd like to learn more about securing your infrastructure with Sino-Telecom's DPI network security capabilities, contact our sales team for a product data sheets, quote, deployment case study, or live demonstration. From comprehensive DCI security solution to single DPI deployments, Sino-Telecom can help you establish your defence perimeter.