Hacker News new | ask | show | jobs
by tptacek 6652 days ago
Network Algorithmics is an awesome book; it's been recommended here before.

But I don't think most of the DPI products use advanced packet classification algorithms. No product I've worked on has; it's pretty much, "that's port 80, so use the HTTP decode". There's classification done for binning and accounting, but it's pretty brute force.

Narus is a DPI vendor, but not of the type WaPo is talking about. They provide "lawful" (read, "unlawful") intercept for traffic that has already been classified and diverted.