Deep Packet Inspection Matthew Carson. What is Deep Packet Inspection? A form of packet filtering...

16
Deep Packet Inspection Matthew Carson

Transcript of Deep Packet Inspection Matthew Carson. What is Deep Packet Inspection? A form of packet filtering...

Page 1: Deep Packet Inspection Matthew Carson. What is Deep Packet Inspection? A form of packet filtering which examines the data portion of an internet packet.

Deep Packet InspectionMatthew Carson

Page 2: Deep Packet Inspection Matthew Carson. What is Deep Packet Inspection? A form of packet filtering which examines the data portion of an internet packet.

What is Deep Packet Inspection?

A form of packet filtering which examines the

data portion of an internet packet as it passes an

inspection point, which searches for protocol non-

compliance, viruses, spam, intrusions or other

specified criteria to determine whether the packet

may pass through the inspection point or if it

needs to be routed to a different destination.

Page 3: Deep Packet Inspection Matthew Carson. What is Deep Packet Inspection? A form of packet filtering which examines the data portion of an internet packet.

How is it used?

• Network Security

• Network Optimization

• Copyright enforcement

• Data mining

• Eavesdropping

• Censorship

Page 4: Deep Packet Inspection Matthew Carson. What is Deep Packet Inspection? A form of packet filtering which examines the data portion of an internet packet.

Why is it important?

Page 5: Deep Packet Inspection Matthew Carson. What is Deep Packet Inspection? A form of packet filtering which examines the data portion of an internet packet.

How much data??According to Intel

• In just 60 seconds, nearly 640 TB of IP data is transferred over the internet

• Amazon averages $83,000 in sales

• Google processes over 2 million search requests

• In one day, on average, nearly 900 Petabytes are sent over the internet

Page 6: Deep Packet Inspection Matthew Carson. What is Deep Packet Inspection? A form of packet filtering which examines the data portion of an internet packet.

My information is protected…

Right?

Page 7: Deep Packet Inspection Matthew Carson. What is Deep Packet Inspection? A form of packet filtering which examines the data portion of an internet packet.

Electronic Communications Privacy

Act of 1986(ECPA)

• Prevents unauthorized interception of electronic communications

• Imposes civil liability upon those who do

• Includes traffi c on the internet

Page 8: Deep Packet Inspection Matthew Carson. What is Deep Packet Inspection? A form of packet filtering which examines the data portion of an internet packet.

Embarq & NebuAd

In 2007 ISP Embarq authorized NebuAd to collect information about their customers

Collected Browsing data as customers passed through network “checkpoints”

Class Action Lawsuit fi led November 2008

Page 9: Deep Packet Inspection Matthew Carson. What is Deep Packet Inspection? A form of packet filtering which examines the data portion of an internet packet.

Legal vs Ethical

Page 10: Deep Packet Inspection Matthew Carson. What is Deep Packet Inspection? A form of packet filtering which examines the data portion of an internet packet.

Court Ruling

• Embarq was not in violation of ECPA

• Embarq had “access” to the information through the use of devices used during the course of normal business operations

• Embarq had no access to the data apart from its access as an ISP

Page 11: Deep Packet Inspection Matthew Carson. What is Deep Packet Inspection? A form of packet filtering which examines the data portion of an internet packet.

And NebuAd?

SUBSEQUENTLY DISSOLVED

AGREED TO A $2.4 MILLION DOLLAR SETTLEMENT

ASSERTS NO WRONG DOING

Page 12: Deep Packet Inspection Matthew Carson. What is Deep Packet Inspection? A form of packet filtering which examines the data portion of an internet packet.

Other Uses of DPI technology

Security• Dell utilizes a DPI technology known as

Reassembly-Free Deep Packet Inspection (RFDPI) to monitor for viruses, malware, Trojans, etc.

Internet Censorship• China uses DPI to monitor and control

the flow of information throughout the population

CALEA

Page 13: Deep Packet Inspection Matthew Carson. What is Deep Packet Inspection? A form of packet filtering which examines the data portion of an internet packet.

Communications Assistance for Law Enforcement Act

(CALEA)

• Requires Telecommunications providers to provide the ability for law enforcement to intercept communications in the pursuit of criminal activity

Page 14: Deep Packet Inspection Matthew Carson. What is Deep Packet Inspection? A form of packet filtering which examines the data portion of an internet packet.

Conclusion

• DPI is a powerful and necessary technology

• Mostly used for security purposes

• Can be misused, like all other technology

• Need for more detailed, up-to-date laws

Page 15: Deep Packet Inspection Matthew Carson. What is Deep Packet Inspection? A form of packet filtering which examines the data portion of an internet packet.

Referenceshttp://en.wikipedia.org/wiki/Communications_Assistance_for_Law_Enforcement_Act

https://www.sonicwall.com/us/en/products/Deep-Packet-Inspection.html

http://en.wikipedia.org/wiki/NebuAd

http://arstechnica.com/uncategorized/2008/07/06-opt-out-nebuad-hides-link-in-5000-word-privacy-policy

http://www.telecomlawmonitor.com/2013/01/articles/litigation/court-rules-for-isp-in-deep-packet-inspection-lawsuit