Themis Deep Packet Inspection (DPI) Evasion Detection

Jaime C. Acosta, Michael J. De Lucia, Kelly Toppin · 2024

Open-source network intrusion detection systems (NIDS) such as Snort, Suricata, and Zeek rely primarily on signature- and anomaly-based detection techniques. These systems also deploy deep packet inspection (DPI) to analyze the data as it would be used by its final application layer. Malicious actors often use evasion techniques to avoid these NIDS. This study analyzed several DPI methods versus Themis DPI and Zeek detection capabilities.

Read the paper · More papers on PaperTik