Themis Deep Packet Inspection (DPI) Evasion Detection

Report Number:
ARL-TN-1193

Publish Date:

February 27, 2024

Distribution:

Approved for public release: distribution is unlimited.


Author(s):

Jaime Acosta, Michael De Lucia, and Kelly Toppin

Abstract:

Open-source network intrusion detection systems (NIDS) such as Snort, Suricata, and Zeek rely primarily on signature- and anomaly-based detection techniques. These systems also deploy deep packet inspection (DPI) to analyze the data as it would be used by its final application layer. Malicious actors often use evasion techniques to avoid these NIDS. This study analyzed several DPI methods versus Themis DPI and Zeek detection capabilities.

File Size: 531 KB
Scroll to Top

Copyright © 2026 All Rights Reserved.