None
Accepted And Announced
Submission 31 May 2026 9:46:58am EDT f339152e24ca1df6ca9129b1d69eaa7d0ec24eeebc33783356f1bd1961aa545df339152e
Modern network visibility and security are heavily based on understanding the behavior of the application-layer. However, ubiquitous encryption and stealthy evasion protocols have severely degraded the effectiveness of legacy firewalls. This talk proposal introduces the latest advancements in nDPI, an open-source Deep Packet Inspection (DPI) toolkit. We explore how modern DPI transcends simple payload parsing by leveraging cryptographic fingerprints to identify malicious actors despite encryption.
Furthermore, we expose structural flaws in industry-standard fingerprinting methodologies like JA3 and JA4 when confronted with ephemeral TLS extensions. Finally, we present the practical integration of nDPI within the Linux kernel firewall architecture for real-time traffic optimization, alongside architectural blueprints utilizing PF_RING and SmartNIC flow managers to achieve deterministic 100 Gbps traffic monitoring and hardware-accelerated enforcement.
Luca Deri (ntop) <deri@ntop.org>
Alfredo Cardigliano (ntop) <cardigliano@ntop.org>