Themis Deep Packet Inspection (DPI) Evasion Detection
Report Number:
ARL-TN-1193
Publish Date:
February 27, 2024
Distribution:
Approved for public release: distribution is unlimited.
Author(s):
Jaime Acosta, Michael De Lucia, and Kelly Toppin
Abstract:Open-source network intrusion detection systems (NIDS) such as Snort, Suricata, and Zeek rely primarily on signature- and anomaly-based detection techniques. These systems also deploy deep packet inspection (DPI) to analyze the data as it would be used by its final application layer. Malicious actors often use evasion techniques to avoid these NIDS. This study analyzed several DPI methods versus Themis DPI and Zeek detection capabilities.
File Size:
531 KB
