Fosstodon
NETDEV VIDEOS
Session
Line-Rate Cybersecurity: Modern DPI and Encrypted Traffic Fingerprinting at 100 Gbps
Speakers
Luca Deri
Alfredo Cardigliano
Label
Nuts and Bolts
Session Type
Talk
Description
Modern network visibility and security are heavily based on understanding the behavior of the application-layer. However, ubiquitous encryption and stealthy evasion protocols have severely degraded the effectiveness of legacy firewalls. This talk proposal introduces the latest advancements in nDPI, an open-source Deep Packet Inspection (DPI) toolkit. We explore how modern DPI transcends simple payload parsing by leveraging cryptographic fingerprints to identify malicious actors despite encryption.
Furthermore, we expose structural flaws in industry-standard fingerprinting methodologies like JA3 and JA4 when confronted with ephemeral TLS extensions. Finally, we present the practical integration of nDPI within the Linux kernel firewall architecture for real-time traffic optimization, alongside architectural blueprints utilizing PF_RING and SmartNIC flow managers to achieve deterministic 100 Gbps traffic monitoring and hardware-accelerated enforcement.
Recent News
Bronze Sponsor, Common Net
[Tue, 16, Jun. 2026]
Bronze Sponsor, secunet
[Fri, 12, Jun. 2026]
Bronze Sponsor, Red Hat
[Fri, 12, Jun. 2026]
Bronze Sponsor, Mpiric
[Tue, 09, Jun. 2026]
Bronze Sponsor, Viasat
[Mon, 08, Jun. 2026]
Important Dates
| Closing of CFS | June 1st |
| Notification by | June 10th |
| Conference dates | July 13th-16th |