Deep Packet Inspection
What is Deep Packet Inspection?
Deep packet inspection (DPI) is a type of network packet filtering. It evaluates both data and the header of a packet that is going through an inspection point. Simultaneously, it extracts data from packets.
How does DPI apply to threat detection?
DPI examines the content of the payload and extracts all the metadata that can be extracted. This information will be used by the threat detection engine to make accurate detection. This contextual information is also presented to the analyst on the dashboard so that the human analyst can have a better understanding of the threats and make informed decisions.
Intelligent Detection
With heuristics and behavioural based rule sets, DPI can provide intelligent security threat detection.
Advanced Detection
DPI provides the ability for full parsing of content layers of the packet which allows the detection of most dangerous attacks