* A look at deep packet inspection Our Special Focus author (tgreene@nww.com) this week takes a look at the world of deep packet inspection.First there were packet filters. Then stateful inspection firewalls; then intrusion detection.Basically deep packet inspection lets an application traffic management device peer into the content of a TCP or User Datagram Protocol (UDP) packet. The idea is to let the device filter, track or discard traffic based on content encapsulated in a packet’s header or payload, regardless of the protocol or application type.Greene writes that by analyzing packets not just in isolation, but by reassembling and analyzing packet streams that make up individual application sessions, these application-layer firewalls can spot odd behavior by traffic using a particular protocol that can signal a brand new attack. Deep packet inspection firewalls are the latest stage in the evolution of firewall technology, says Richard Steinnon, an analyst for Gartner Group credited with coining the term deep packet inspection. Steinnon says Check Point Fortinet and NetScreen do this as well as intrusion prevention systems (IPS) such as Tipping Points’, Intruvert’s and NetContinuum’s. Devices such as those made by Teros and Radware also fall under the same broad umbrella.Application firewalls can find malicious traffic that stateful inspection firewalls miss. For example, stateful firewalls don’t detect worms that send strings of malicious code within legitimate protocols because stateful firewalls just look at network-layer packet headers. Deep packet inspection, however, can find such attacks by looking for telltale signatures farther inside packets. For more on our Special Focus see: https://www.nwfusion.com/news/2004/0202specialfocus.html Related content how-to Getting started with scripting on Linux, Part 1 Once a script is prepared and tested, you can get a significant task completed simply by typing the script's name followed by any required arguments. By Sandra Henry-Stocker Dec 11, 2023 5 mins Linux feature Starkey swaps out MPLS for managed SD-WAN Hearing aid manufacturer achieves performance boost, increased reliability and cost savings after a shift from MPLS to managed SD-WAN services from Aryaka. By Neal Weinberg Dec 11, 2023 6 mins SASE SD-WAN Network Security news Nvidia races to fulfill AI demand with its first Vietnam semiconductor hub Vietnam has been a growing tech manufacturing destination for the past few years, and Nvidia said it is open to a new manufacturing partner in Vietnam. By Sam Reynolds Dec 11, 2023 3 mins CPUs and Processors Technology Industry how-to Doing tricks on the Linux command line Linux tricks can make even the more complicated Linux commands easier, more fun and more rewarding. By Sandra Henry-Stocker Dec 08, 2023 5 mins Linux Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe