# Deep packet inspection

Source: https://ordergroup.co/glossary/deep-packet-inspection/
Last updated: 2026-10-10

> Deep packet inspection explained for teams that control device traffic - how DPI classifies flows, what encryption hides, and where to run it.

[IoT & Devices](https://ordergroup.co/glossary/iot/)
4 min read

# Deep packet inspection

Also known as: DPI, packet inspection

Definition

Deep packet inspection (DPI) is a method of network traffic analysis that reads packet contents, not only IP addresses and ports, to identify the protocol or application behind a flow, extract fields such as host names, and allow, block or log the traffic by policy.

Cite this entry

Text
"Deep packet inspection". Order Group, Software glossary, 10 October 2026. https://ordergroup.co/glossary/deep-packet-inspection/
HTML
`<a href="https://ordergroup.co/glossary/deep-packet-inspection/">Deep packet inspection</a> - Order Group`

Reviewed by [Maciej Sułek](https://ordergroup.co/authors/maciej-sulek/), Co-founder & CTO
Last reviewed 10 October 2026

## How deep packet inspection works

A classic firewall decides on the packet header: source and destination address, port and protocol. Deep packet inspection reads further. It reassembles the packets of a flow and looks at what they carry, so it can tell which application or protocol is behind the traffic regardless of the port it uses. ITU-T standardized the requirements for DPI in operator networks in Recommendation Y.2770 (2012). The same technique runs today in enterprise gateways, cloud proxies and on devices.

A DPI engine combines three methods. Protocol dissectors parse known protocols and pull out fields: the name in a DNS query, the Host header of plain HTTP, the server name in a TLS handshake. Signatures match byte patterns typical of an application. For traffic that cannot be read, statistical and behavioral features of the flow (packet sizes, timing, handshake parameters) suggest what it is. nDPI, an open LGPLv3 library maintained by ntop, is a common building block: its maintainers list more than 450 detected Layer-7 protocols, and it extracts metadata from encrypted communications for encrypted traffic analysis.

Encryption keeps shrinking what DPI can see without decrypting. In TLS 1.3 (RFC 8446) all handshake messages after the ServerHello are encrypted, including the server certificate, which TLS 1.2 sent in the clear. The server name indication in the ClientHello stayed visible, and many classifiers rely on it. Encrypted Client Hello (ECH), published as RFC 9849 in March 2026, encrypts the ClientHello under the server's public key and protects the server name and the ALPN list. DNS over HTTPS (DoH, RFC 8484) moves name lookups into ordinary HTTPS traffic, so DNS-based detection also loses its input. Without decryption, a network DPI box increasingly sees an IP address, flow behavior and little else.

On a device the situation is different, because the operating system knows which app opened each connection before any byte is encrypted. On stock Android an app can inspect traffic only through VpnService, which creates a virtual network interface and hands the app every outgoing packet. The platform limits this: the user must approve the first VPN connection, unless a device owner or profile owner configures an always-on VPN; only one VPN can run at a time; and a system notification stays visible while it runs. A custom Android build can place inspection inside the system instead.

## What deep packet inspection means for your software

In practice DPI is a policy engine with a classifier in front of it, and most of the work goes into the policy, its updates and its behavior when classification fails. Requirements for any system that inspects or filters device traffic:

- Decide where inspection runs: in the network, in a cloud proxy, in an app on the device or inside the operating system. Each place sees different data and fails differently (see the table).
- Policy is versioned data per organization and device group: blocked protocols, applications, domains, URL keywords and patterns. Devices sync it from the backend and report which version they apply.
- Define the behavior before classification completes and for traffic the engine cannot identify. Fail-open lets unknown traffic pass; fail-closed breaks apps when a new protocol appears. Choose per policy, and say so in the admin panel.
- A blocked connection fails fast with a clear error, so apps do not hang on timeouts and users can tell a blocked site from a broken network.
- The detection library is a dependency with its own update cycle. Protocols change, so signatures and dissectors ship with system updates, and the build targets the device CPU, often ARM.
- Plan for less visibility. TLS 1.3, Encrypted Client Hello and DNS over HTTPS remove fields that older rules depend on. Decrypting TLS on a device means installing your own root certificate, which is a security and legal decision of its own, and apps that pin certificates will break.
- Logs of inspected traffic are personal data when they tie a person to sites and apps. Under the GDPR, Regulation (EU) 2016/679, the system needs a defined purpose, a retention period and access control for those logs.
- Measure CPU, memory and battery on the target hardware with real traffic before rollout.

Writing the specification?

Add Deep packet inspection to your requirements checklist

Collect the terms your project touches and get their system requirements in one e-mail, ready for an RFP.

Where deep packet inspection can run
LocationWhat it seesLimitsTypical use

Network appliance or gatewayAll traffic on the site network, metadata of encrypted flowsBlind to devices off the network, loses SNI under ECH and DNS under DoHOffice and plant networks, operator networksCloud proxy or always-on VPNTraffic routed through the service, from any locationAdds latency, needs the device to keep the tunnel upRemote workforce, managed fleetsApp on the device (Android VpnService)Every packet of the device before it leaves, per appOne VPN at a time, user approval, visible notificationFiltering and monitoring apps on stock AndroidInside the operating systemConnections with app identity, before encryption of the payloadRequires your own OS build and its update channelHardened phones, terminals, dedicated devices

## Rules and standards

ITU-T Y.2770 (2012) sets out requirements for DPI in next-generation networks; it is a reference for operator equipment, not a legal duty. The protocols that limit DPI are IETF standards: TLS 1.3 in RFC 8446, Encrypted Client Hello in RFC 9849 and DNS over HTTPS in RFC 8484. In the EU, traffic records linked to a user fall under the GDPR, so inspection of employees' devices needs a legal basis, information for the people concerned and a retention rule. Check the employment and telecommunications rules of each country where the devices are used.

## From our projects

In the [Raw Control OS project](https://ordergroup.co/case-studies/raw-cyber-custom-android-os/), packet inspection ran inside the operating system. The first layer, built from 2020, was a link classifier: the system synced keywords, rules and addresses from the backend, rejected a connection when the address contained a keyword, matched a listed address or matched a regular expression, and returned the error EHOSTUNREACH so apps failed at once.

In April 2021 we compiled nDPI for ARM and integrated its API into the operating system. DNS detection followed in May and URL extraction in June. In August and September 2021 we added blocking of protocols and applications recognized by nDPI: an administrator selects them for a company or a group in the panel, the backend exposes the settings to the phones, and Android blocks the matching traffic.

From our projects

[RAW Cyber - Secure Custom Android Operating System
How Order Group and RAW Cyber built a secure mobile operating system: a custom Android-based OS hardened with CopperheadOS for secure communications.](https://ordergroup.co/case-studies/raw-cyber-custom-android-os/)

## Related terms

- [MDM](https://ordergroup.co/glossary/mdm/)

Mobile device management
Mobile device management (MDM) is software that lets an organization enroll, configure, monitor, lock and wipe phones, tablets and other devices from a central console, by sending policies to an agent or to the management interface of each device's operating system.
- [OTA update](https://ordergroup.co/glossary/ota-update/)

Over-the-air update
An OTA (over-the-air) update is a software or firmware update that a device downloads and installs over a network, with no cable or service visit. FOTA is the firmware case. The package must be signed, verified on the device and recoverable when the installation fails.

## Sources

1. [ITU-T Y.2770: Requirements for deep packet inspection in next generation networks](https://www.itu.int/rec/T-REC-Y.2770) - ITU-T
2. [nDPI: Open and Extensible LGPLv3 Deep Packet Inspection Library](https://www.ntop.org/products/deep-packet-inspection/ndpi/) - ntop
3. [RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3](https://www.rfc-editor.org/rfc/rfc8446.html) - IETF
4. [RFC 9849: TLS Encrypted Client Hello](https://www.rfc-editor.org/rfc/rfc9849.html) - IETF
5. [RFC 8484: DNS Queries over HTTPS (DoH)](https://www.rfc-editor.org/rfc/rfc8484.html) - IETF
6. [VpnService (Android API reference)](https://developer.android.com/reference/android/net/VpnService) - Android Developers
7. [Regulation (EU) 2016/679 (GDPR)](https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng) - EUR-Lex

Maciej Sułek reviewed this entry. Ask how it applies to your project.

[Ask an engineer](https://ordergroup.co/contact-us/)

## FAQ

![Maciej Sułek](https://ordergroup.co/media/images/T02DHCC1Z-U04AVB19V-45105f88ff4a-512.format-webp.webp)

Maciej Sułek

Co-founder & CTO

[Talk to an engineer](https://ordergroup.co/contact-us/)

### Can deep packet inspection see inside HTTPS?

Not without decrypting it. Without decryption it sees metadata: addresses, flow behavior and, until Encrypted Client Hello is used, the server name. Decryption requires a trusted root certificate on the device, and apps that pin certificates will stop working.

### Is DPI the same as a firewall?

No. A firewall filters on addresses, ports and protocols in the packet header. DPI identifies the application or protocol from the content and behavior of the flow, so it can block an app that uses the same port as allowed traffic.

### Should DPI run on the device or in the network?

On the device if devices leave your network or you need to know which app made a connection. In the network if you only control fixed sites and want one point of control. Many fleets use both.

### Can we use an open-source DPI library in a commercial product?

nDPI is licensed under LGPLv3, which allows use in proprietary software under conditions on distributing the library and letting users replace it. Have the license reviewed for your distribution model before you ship.

Building a system that depends on Deep packet inspection?

See how we build software for this domain, with case studies and the stack we use.

[See IoT & Device Software Development Services](https://ordergroup.co/iot-software-development/)

Requirements checklist

For each term we send the definition and what it requires from your software. Free, no sales call needed.
Your checklist is empty. Use the plus next to a term to add it.
