Extended Independent Comparison of Popular Deep Packet Inspection (DPI) Tools for Traffic Classification TOMASZ BUJLOW, VALENTIN CARELA-ESPAÑOL, PERE BARLET-ROS Broadband Communications Research Group (CBA) Department of Computer Architecture (DAC) Universitat Politècnica de Catalunya (UPC) Extended Independent Comparison of Popular Deep Packet Inspection (DPI) Tools for Traffic Classification Tomasz Bujlow, Valentin Carela-Español, and Pere Barlet-Ros Broadband Communications Research Group (CBA) Department of Computer Architecture (DAC) Universitat Politècnica de Catalunya (UPC) ii Tomasz Bujlow, Valentin Carela-Español, and Pere Barlet-Ros. Extended Independent Comparison of Popular Deep Packet Inspection (DPI) Tools for Traffic Classification. TECHNICAL REPORT Version 1: January 17, 2014 Distribution: Universitat Politècnica de Catalunya (UPC) Department of Computer Architecture (DAC) Broadband Communications Research Group (CBA) Campus Nord. Mòdul D6, Jordi Girona 1-3 ES-08034 Barcelona Spain Phone: +34 934 017 001 Fax: +34 934 017 055
[email protected] Copyright c Universitat Politècnica de Catalunya 2014 All rights reserved. No part of the material protected by this copyright notice may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying, recording or by any information storage and retrieval system, without a written permission from the authors. DEN EUROPÆISKE UNION Den Europæiske Fond for Regionaludvikling Vi investerer i din fremtid iii Abstract Network traffic classification became an essential input for many network-related tasks. However, the con- tinuous evolution of the Internet applications and their techniques to avoid being detected (as dynamic port numbers, encryption, or protocol obfuscation) considerably complicated their classification. We start the re- port by introducing and shortly describing several well-known DPI tools, which later will be evaluated: PACE, OpenDPI, L7-filter, NDPI, Libprotoident, and NBAR.