Tuesday, March 11, 2014

DPI (Deep Packet Inspection) and DCI (Deep Content Inspection)

Dissecting DPI / DCI (Deep content inspection) and available options

http://en.wikipedia.org/wiki/Deep_packet_inspection

In the computer network L2 to L7 are all  various information floating around a link, various security applications providing intrusion prevention and intrusion detection (IP/ID)

I came across various solution in the past , each product specializing in it own way and does one better than other.

In an ideal network world monitoring and reporting are in done in two segments on a same network pipe(link)

Monitoring on a 1/10/40/100G interface in-line is possible only with a hardware based solution.

  • Filtering traffic on-the-fly is possible here from the same hardware, which decides what traffic to be passed-thru based on a policy rule
  • Trigger to apply policy to change the QOS or traffic type 

Reporting of statistics can be feed into multiple software based appliances (tools).

High-ranking websites blocked in mainland China using Deep Packet Inspection
Alexa Rank Website Domain URL Category Primary language
6 Wikipedia wikipedia.org www.wikipedia.org Censorship-Free Encyclopedia English
1 Google google.com www.google.com World-wide Internet Search Engine English
1 Google Encrypted google.com encrypted.google.com Search English
2 Facebook facebook.com www.facebook.com Social network English
3 YouTube youtube.com www.youtube.com Video English
24693 OpenVPN openvpn.net www.openvpn.net Avoid political internet censorship English
33553 Strong VPN strongvpn.com www.strongvpn.com Avoid political internet censorship English
78873 Falun Dafa falundafa.org www.falundafa.org Spiritual English
1413995 VPN Coupons vpncoupons.com www.vpncoupons.com Avoid political internet censorship English
2761652 ElephantVPN elephantvpn.com www.elephantvpn.com Avoid political internet censorship English


IPOQUE
http://www.ipoque.com/en/products/prx-g-series

PRX G-Series
The Next Generation of Network Intelligence
Traffic Management and Policy Enforcement

The PRX G-Series product line is a carrier-class bandwidth management, policy enforcement and network intelligence system. It identifies all traffic on the operator network based on deep packet inspection and provides an extensive suite of capabilities to monitor, manage, and monetize network application traffic.
As a network operator the ipoque PRX G-Series helps you to reduce operational costs of your network as well as to identify and eliminate revenue leakage. Additionally, it allows you to introduce new application-based services models that subscribers are demanding in an all-IP world.

Some deployment scenarios of these products
PACE (Protocol and application classification engine) and PADE (Protocol Application Decoding Engine) are their proprietary software stack (tools) for building application in OSS.










As the world changing towards application aka "apps", there are various newer types of traffic allover in the TCP/IP pipe.

MANAGE AND ENSURE THE RESPONSE TIME & THROUGHPUT
OF EVERY APPLICATION YOU OWN IN EVERY LOCATION YOU RUN IT

AppEnsure delivers an enterprise view of all apps running; legacy, custom and purchased, in all locations; physical, virtual, private and public cloud. This is a dynamic view that will update in real time to show all instances in all locations with each transaction response time. The overall throughput of all instances of an app delivers a deterministic demand load profile, not an inferred one from resource utilization. Manage your performance!

No comments:

Post a Comment

bee-social