More

PC conflicts

None

Accepted And Announced

[PDF] Submission 31 May 2026 9:46:58am EDT · f339152e24ca1df6ca9129b1d69eaa7d0ec24eeebc33783356f1bd1961aa545df339152e

Abstract

Modern network visibility and security are heavily based on understanding the behavior of the application-layer. However, ubiquitous encryption and stealthy evasion protocols have severely degraded the effectiveness of legacy firewalls. This talk proposal introduces the latest advancements in nDPI, an open-source Deep Packet Inspection (DPI) toolkit. We explore how modern DPI transcends simple payload parsing by leveraging cryptographic fingerprints to identify malicious actors despite encryption.

Furthermore, we expose structural flaws in industry-standard fingerprinting methodologies like JA3 and JA4 when confronted with ephemeral TLS extensions. Finally, we present the practical integration of nDPI within the Linux kernel firewall architecture for real-time traffic optimization, alongside architectural blueprints utilizing PF_RING and SmartNIC flow managers to achieve deterministic 100 Gbps traffic monitoring and hardware-accelerated enforcement.

Authors (blind)

Luca Deri (ntop) <deri@ntop.org>

Alfredo Cardigliano (ntop) <cardigliano@ntop.org>

Submission Type
Talk
Submission Label
Nuts and Bolts
Estimated Length Of Time For Presentation (in minutes)
45
Attendance
Physically

To edit this submission, sign in using your email and password.