Comparison of Deep Packet Inspection (DPI) Tools for Traffic Classification

Posted · Add Comment

From time to time we receive emails form people asking how nDPI compares with other similar toolkits. Licio Marchetti has shared this report Comparison of Deep Packet Inspection (DPI) Tools for Traffic Classification written by the Universitat Politècnica de Catalunya that says: “the best accuracy we obtained from NDPI (91 points), PACE (82 points), UPC MLA (79 points), and Libprotoident (78 points)”. So nDPI looks in good shape :-)

This said, last week we have improved quite bit the Bittorrent and Skype dissectors and we have create a small test tool that demonstrate that we can create an inline application that for instance blocks Skype traffic (i.e. we believe that nDPI now scores much better than in this report). We’re not focusing on the (overdue) ntopng release, but once done that, we will release a tool that can demonstrate all this in practice. Thanks to the whole nDPI user community for the comments and code patches.

If interested in nDPI, you can also view this webinar organized by AlienVaultHow to Improve Network Security with nDPI.

Updated report (01/2014): Extended Independent Comparison of Popular Deep Packet Inspection (DPI) Tools for Traffic Classification