{"title":"On Detection Accuracy of L7-filter and OpenDPI","authors":"Chaofan Shen, Leijun Huang","doi":"10.1109/ICNDC.2012.36","DOIUrl":null,"url":null,"abstract":"Traffic identification is an important issue in the network industry. Due to the rapid increase of applications and protocols in the Internet, traffic identification based on TCP/UDP port numbers is no longer a practical approach. Deep packet inspection (DPI) thus becomes necessary, which scans the payload of a flow for certain patterns. In this paper, we analyze the architectures of two popular open-source DPI solutions, L7-filter and OpenDPI, along with their capabilities and limitations. Our extension to L7-filter, called L7-filter-U, which improves the detection accuracy on UDP flows, is also presented. Experiments on real-world traces show that OpenDPI has higher detection accuracy than L7-filter-U, which in turn performs better than L7-filter.","PeriodicalId":151593,"journal":{"name":"2012 Third International Conference on Networking and Distributed Computing","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2012-10-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"12","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2012 Third International Conference on Networking and Distributed Computing","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICNDC.2012.36","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 12
Abstract
Traffic identification is an important issue in the network industry. Due to the rapid increase of applications and protocols in the Internet, traffic identification based on TCP/UDP port numbers is no longer a practical approach. Deep packet inspection (DPI) thus becomes necessary, which scans the payload of a flow for certain patterns. In this paper, we analyze the architectures of two popular open-source DPI solutions, L7-filter and OpenDPI, along with their capabilities and limitations. Our extension to L7-filter, called L7-filter-U, which improves the detection accuracy on UDP flows, is also presented. Experiments on real-world traces show that OpenDPI has higher detection accuracy than L7-filter-U, which in turn performs better than L7-filter.