Deep Packet Inspection

HPE Aruba Networking uses Deep Packet Inspection (DPI) technology in our Access Points (APs), gateways, and some Aruba CX switches to identify and classify network traffic, including applications, protocols, and services, in real-time.

APs, gateways, and switches that perform DPI leverage the Enea Qosmos ixEngine to provide real-time visibility of thousands of applications (~4000 as of January 2024) in more than 30 different categories.

HPE Aruba Networking constantly updates the protocol database available with every software release with the latest application signatures, behavioral patterns, and protocols to adapt to evolving applications and ensures accurate identification with software updates of APs, gateways, and switches. This information is crucial for network management, security, Quality of Service (QoS) enforcement, and application-level visibility.

Additionally, the DPI engine includes the ability to deliver first-packet classification, a key aspect in order to define Policy-Based Routing based on the applications being used. To do this, the DPI engine caches the classification for any destination IP and port to have it readily available from the very first packet of any subsequent session (with an initial cache of the most popular IP addresses pre-loaded into the system).

To identify the applications traversing the network, the DPI engine leverages the following techniques:

  • Packet Inspection—The DPI Engine inspects the contents of network packets at various layers of the OSI model, analyzing packet payloads, headers, and metadata.

  • Signature-based Recognition—The DPI Engine employs signature-based analysis, where it compares packet data against a database of known patterns, signatures, or characteristics associated with specific applications, services, or protocols.

  • Protocol Heuristics—Beyond signatures, the DPI Engine utilizes protocol heuristics to recognize and classify traffic based on behavioral patterns, even when specific signatures or port numbers are not readily identifiable.

  • Metadata and Flow Analysis—The DPI Engine looks beyond packet inspection, utilizing flow analysis, and metadata extraction to gain insights into traffic patterns, session information, and communication behavior, aiding in application identification.

  • Traffic Context and Behavior Analysis—The DPI Engine considers the context and behavior of traffic, examining characteristics such as packet sizes, frequencies, and sequences to enhance its identification accuracy.

  • Machine Learning and Pattern Recognition—The DPI Engine incorporates machine learning algorithms to enhance its traffic classification capabilities. This involves training models to recognize and classify traffic based on learned patterns and behaviors.

To identify encrypted traffic, the DPI Engine employs several techniques to infer information about encrypted applications.

  • Metadata Analysis—Even though the content of encrypted packets is not visible, the DPI engine can analyze metadata associated with the traffic. This metadata might include packet sizes, transmission patterns, communication endpoints, timing, and protocol behavior, offering clues about the nature of the encrypted application. DPI technology also leverages Server Name Indication (SNI) information as part of its analysis to identify and classify encrypted traffic.

  • Protocol Heuristics—Some encrypted applications follow specific protocols or communication patterns that might be identifiable even if the content is encrypted. The DPI Engine used by HPE Aruba Networking APs, gateways, and switches (ENEA Qosmos) leverages protocol heuristics to recognize these behavioral patterns, helping to classify encrypted traffic.