nDPI

nDPI

Introducing the nDPI TCP Fingerprint: A Stable, Patent-Free Way to Fingerprint TCP Stacks

Every TCP connection starts with a SYN, and that first packet says a lot about the machine that sent it. The Linux, Windows, macOS and Android stacks each set different flags, choose different initial TTLs, advertise different receive windows, and, above all, lay out their TCP options in different orders. Passive TCP fingerprinting turns those differences into a compact signature. Today we are announcing the nDPI TCP Fingerprint (NTF), a modern, open, patent-free TCP fingerprint format that has been included in nDPI for a few years now. It is implemented …
Announce

Introducing JA5: A Stable, Collision-Resistant Successor to JA4

TLS client fingerprinting has become one of the workhorse techniques in network security, and JA4 (FoxIO) has been the de facto standard for identifying TLS clients from their ClientHello messages. But recent production experience at ntop surfaced two real limitations, and today we’re announcing JA5, an open, patent-free extension of JA4 that addresses both. Ephemeral Extensions Break Hash Stability JA4 builds its fingerprint from the full set of TLS extensions a client presents, hashed together with the cipher suite list. The trouble is that not every extension reflects something stable …
nDPI

Introducing nDPI 6.0: Licensing Update, Slow DoS Detection and Smarter Fingerprints

We are proud to announce the release of nDPI 6.0, the latest major update to our open-source Deep Packet Inspection (DPI) toolkit. This release brings an important licensing update, a brand-new detection logic for Slow DoS attacks, more flexible and reliable traffic fingerprints, and zero-overhead runtime observability via USDT tracepoints — on top of new protocols and dozens of improvements and fixes. Updated Licensing Terms With nDPI 6.0 we have updated the licensing terms of the project, introducing a distinction between for-profit and not-for-profit usage of some components. Full details …
nDPI

Announcing nDPI Dual License Change

A License Change for nDPI: Protecting the Project We Started in 2012 When we began nDPI back in 2012, the idea was simple: build an open source, high-performance Deep Packet Inspection engine that anyone could use as a foundation layer for network applications. No gatekeeping or strings attached, but just a solid piece of infrastructure that the community could build on, improve, and share back. In order to protect this idea, we have registered the nDPI trademark both in the US and EU to prevent people from using the word …
cento

Post-Quantum Cryptography (PQC) Analysis

Modern digital security relies on public-key encryption (like RSA and ECC) to protect global data. The future arrival of a Cryptographically Relevant Quantum Computer (CRQC) will completely break these mathematical foundations. To counter this, organizations must migrate to Post-Quantum Cryptography (PQC) — new, math-based algorithms deployed via standard software that quantum computers cannot exploit. The PQC migration requires to protect data “at rest” (i.e. static data stored on physical drives, databases, cloud storage, or backups) and “in transit” (i.e. data transmitted on computer networks, including HTTPs and VPNs). In the latter case quantum …
nDPI

Observing nDPI from the Inside: Introducing USDT Tracepoints

by Ivan Nardi One of the recurring challenges when embedding the nDPI library into a production application is answering a deceptively simple question: what is nDPI actually doing right now? You know packets are coming in, flows are being classified, and risks are being flagged — but at what rate? With what latency? Are some protocols taking longer to classify than usual? Is that CPU spike caused by a wave of TLS flows, a flood of DNS queries, or something else entirely? Your application or monitoring backend probably already exports …
Cybersecurity

Slow DoS Detection and Prevention

A slow DoS (Denial of Service) attack is a type of cyberattack designed to overwhelm a server or web application by exploiting protocol weaknesses—not through high-volume traffic, but by sending requests very slowly or keeping connections open as long as possible. This consumes server resources (like concurrent connection limits, memory, or threads) with minimal bandwidth usage by the attacker. Instead of flooding the target with huge amounts of data, the attacker sends legitimate-looking requests at an extremely slow pace, or sends partial requests and delays completing them.The server keeps these connections open, waiting for …
nDPI

Is JA4 Now Obsolete?

JA4 is a modern network fingerprinting standard used to identify and profile clients initiating encrypted TLS (Transport Layer Security) connections. JA4 it is the successor to the widely used but now deprecated JA3 standard. JA3 is considered obsolete because it cannot provide a stable identifier for modern browsers and is easily bypassed by attackers. Its reliance on the specific sequence of fields in the TLS ClientHello message makes it highly fragile in today’s networking environment. One (but not the only one) of the main limitations is JA3 is sensitivity to …
nDPI

nDPI 5.0: Enhanced Traffic Fingerprinting and FPC, Many new Protocols

We are proud to announce the release of nDPI 5.0, the latest major update to our open-source Deep Packet Inspection (DPI) toolkit. This release introduces a powerful new fingerprinting system, unlimited protocol support, and enhanced detection capabilities that go beyond traditional methods. Major Highlights A Unified nDPI Fingerprint With nDPI 5.0, we are introducing a new fingerprinting mechanism that combines multiple layers of flow metadata into a single, robust fingerprint. This unified fingerprint integrates: This new approach allows nDPI to identify and correlate encrypted or obfuscated traffic more accurately than ever before.You can read more about the …
Cybersecurity

When SNIs Cannot be Trusted

SNI (Server Name Indication) is an optional extension in TLS/QUIC that contains the symbolic host name we’re connecting to. For instance, during the TLS handshake, the SNI allows the server to identify the correct TLS certificate of a server hosting multiple websites. nDPI reports SNIs in order to make it possible to detect name-based services deployed on the same server IP address. Below you can see an example of how nDPI reports SNIs in encrypted traffic. Client applications use the SNI to verify that the website it is connecting to matches …
nDPI

Beyond JA3/JA4: Introducing nDPI Traffic Fingerprint

Traffic fingerprinting is a hot topic and we have discussed it several times both in this blog and at conferences. There are various fingerprints techniques and probably most of you know JA3/JA4. Let me do a short recap on the subject in nDPI we support several de-facto fingerprint such a JA4 and additional nDPI-native such as the OS (Operating System) fingerprint. In our research we have realized that in cybersecurity using a single fingerprint (e.g. JA4) leads to too many false positives making it a “nice to have” rather than …
nDPI

Introducing nDPI 4.14: Added QoE (Quality of Experience) and New Protocols, Several Fixes

We’re excited to announce the release of nDPI 4.14, a maintenance release that also includes some cool new protocol dissectors and fixes. As you know, maintaining a DPI library is no easy task, and this release is no exception. We’ve worked hard to enhance existing dissectors, making them more robust and efficient. We’ve also cleaned up some outdated code and improved flow risks. We’ll be sharing more details about the plans for the next nDPI release at PacketFest. This might be the last release of the 4.x series, so we’re …