iTnews
  • Home
  • News
  • Technology
  • Networking

Analysis: The murky world of deep packet inspection

By Juha Saarinen
Jan 7 2010 7:07AM
Follow google news

One of the internet's most useful technologies makes for a scary weapon.

Three words, "Deep Packet Inspection," strike fear into the hearts of privacy advocates and net neutrality supporters alike.

Analysis: The murky world of deep packet inspection

Using DPI on your network is something of a double-edged sword: on the one hand, the technology allows for fine-grained control over network data flows and can boost security as well as prioritise services or even create new ones.

However, DPI can also block certain data deemed undesirable and even modify it for purposes such as censorship, copyright monitoring and enforcement, and intrusive marketing and advertising.

ISPs tend to keep quiet about their use of DPI on their networks so as not to raise users' hackles and to avoid thorny legal issues on whether or not such packet peeking amounts to wiretapping.

In other words, DPI remains a controversial technology that has the potential to do good but also carries the risk of turning customers away.

As the Internet law evolves however, DPI could become mandatory for ISPs soon, to comply with statutory filtering requirements and copyright laws.

Indeed, DPI was raised by the film industry's barristers in the iiNet trial as a way for the Perth ISP to measure the volume of peer-to-peer traffic passing across its network. iiNet argued the Telecommunications Act prevented it from examining the content of data packets. That will be tested when the Federal Court hands down its decision later this year.

The case raises the prospect of DPI playing a larger - possibly mandated - role in ISP networks.

What advice do vendors offer for ISPs looking at heading down the DPI route? iTNews spoke to Arbor Networks and Procera Networks to get some ideas about the costs, and what the technology can and can't do.

Uses

Procera Networks' vice president of global marketing, Jon Lindén says Procera's customers use DPI for four purposes - traffic intelligence, congestion management, network protection and creating different service options for customers.

As DPI provides a much greater insight into data traffic streams and potential threats contained in them, the technology can replace stateful network firewalls for ISPs, Lindén says.

Senior product manager Paul Varley at Arbor Networks says its ISP customers use the company's eSeries DPI products for a number of different applications. These include subscriber and application reporting, bandwidth management, service tier enforcement, usage quota tracking and usage-based billing.

Costs

DPI doesn't come cheap, however: implementing DPI represents a serious investment for providers, with for instance the Arbor Networks eSeries DPI solution starting at  under US$50k and reaching several hundreds of thousands of dollars depending on the speed of the interface such as Gigabit Ethernet or 10 Gigabit Ethernet and the overall system capacity and feature set, Varley says.

Lindén says "we don't provide public pricing" but technology site Ars Technica reported in 2008 that Procera's PacketLogic PL1000 unit capable of 80Gbps total bandwidth, five million users and tracking 48 million data flows for Tier-1 networks costs US$800,000, with integration costs on top.

Varley says that Arbor Networks customers "must purchase the eSeries Command Center (eCC) appliance, which provides centralised configuration and reporting for many e100s in the network". This costs between US$50,000 to US$90,000, depending on the licensing says Varley.

For subscriber management, Arbor also offers the eSeries Subscriber Center (eSC) appliance with a list price of US$90,000 plus a subscriber management software license in blocks from 100,000 to five million subscribers, according to Varley.

How deep?

How far does the DPI "snooping" go then? Can the companies' solutions peek into any packets, even encrypted ones? The answers from the two vendors were cagey:

"We don't decrypt any traffic. We identify and classify traffic, even encrypted, based on heuristics like packet sequence, packet size and other common patterns," says Procera's Lindén.

Varley says that DPI platforms like the eSeries "cannot decrypt packets at wire speed but they do perform heuristic analysis on encrypted traffic flows that provide very accurate classification without knowing what the content is."

According to Varley, the e100 can identify encrypted BitTorrent flows even though it does not know which file the subscriber is sharing.

Both Lindén and Varley say their products are capable of filtering and managing data flows across entire networks, depending on how they're deployed.

"DPI is a technology with different applications," Varley says. "For applications such as subscriber security, traffic management and policy enforcement yes, [it] can be a network-wide solution," according to Varley.

Procera's DPI solution can manage all traffic traversing the network, Lindén says. He adds that it can basically be placed anywhere in the network topology.

There are some blind spots for DPI solutions however. Varley says most service providers install DPI at the subscriber edge where it can see most if not all of the traffic, but there are exceptions to this. 

Some providers have separate overlay networks for services like VoIP which may not have DPI. In some network architectures such as DOCSIS in cable, subscribers in the same neighbourhood can communicate with each other directly on the access network, and their traffic would not pass through the DPI, says Varley.

Procera's Lindén agrees that DPI doesn't necessarily cover everything.

"Sure. It's not a 'God box' says Lindén. "But it's an intelligent layer on top of an IP network that offers capabilities to manage traffic in a smart way to achieve best possible results and quality," he adds.

An ISP's DPI solution cannot completely control traffic on its network however, says Varley. The provider can gain enhanced subscriber visibility and security, be able to quickly identify and mitigate distributed denial of service attacks, as well as time-shifting, Varley says.

Lindén says that the main thing DPI provides is awareness of applications, subscribers, locations and devices.

This, he says, "enables better planning for what network investments are required, pro-actively identify potential issues, and the ability to best accommodate different needs."

A question of ethics

Being ethical and straight about the use of DPI on a network seems paramount. 

"Greed is not an acceptable reason to implement DPI," says Lindén.

Not being transparent about the use of technology will come back and bite providers, says Lindén, so he recommends ISPs be open with customers and tell them why DPI is being implemented.

"People aren't stupid and will notice," says Lindén.

A DPI solution should not be kept secret from subscribers. Instead, Lindén says providers need to be clear about the use of DPI and point out its positive effects to customers, such as better, more consistent level of service. 

"You have to avoid the '1984' stigma."

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Tags:
afactdeep packet inspectiondpiiinetinternet service providerispnet neutralitynetworkingtelco/isp

Related Articles

  • Federal Parliamentary Computer Network set for its "most significant" upgrade Federal Parliamentary Computer Network set for its "most significant" upgrade
  • Marathon OAIC investigation finds Optus breached 51,000 customers' privacy Marathon OAIC investigation finds Optus breached 51,000 customers' privacy
  • Kmart Group to expand RFID tagging to more products and to Target Kmart Group to expand RFID tagging to more products and to Target
  • Superloop self-serve AI resolutions top 330,000 cases Superloop self-serve AI resolutions top 330,000 cases
Join our WhatsApp Channel

Partner Content

Agile isn’t the problem: why projects still fail, and what’s missing
Partner Content Agile isn’t the problem: why projects still fail, and what’s missing
Onel Consulting Strengthens Its White-Glove Services With Strategic COO Appointment
Promoted Content Onel Consulting Strengthens Its White-Glove Services With Strategic COO Appointment
The hidden economics of AI: Why token usage matters more than you think
Partner Content The hidden economics of AI: Why token usage matters more than you think
Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
Partner Content Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026

Sponsored Whitepapers

Are Australian organisations as cyber-ready as they think?
Are Australian organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
From visibility to execution:  Fixing the SaaS management gap
From visibility to execution: Fixing the SaaS management gap
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Kmart Group to expand RFID tagging to more products and to Target

Kmart Group to expand RFID tagging to more products and to Target

Federal Parliamentary Computer Network set for its "most significant" upgrade

Federal Parliamentary Computer Network set for its "most significant" upgrade

WA man jailed for at least five years for evil twin attack

WA man jailed for at least five years for evil twin attack

Optus fast-tracks network operations insourcing from Nokia

Optus fast-tracks network operations insourcing from Nokia

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.