FINDING · DEFENSE

Manually-generated FTE regexes achieve a 100% misclassification rate against all six tested DPI systems — appid, l7-filter, YAF, bro, nProbe, and the proprietary enterprise-grade DPI-X — for HTTP, SSH, and SMB target protocols. Each regex took less than 30 minutes to specify and debug against known classifiers.

From 2013-dyer-protocolProtocol Misidentification Made Easy with Format-Transforming Encryption · §4.2, Figure 4 · 2013 · Computer and Communications Security

Implications

Tags

censors
generic
techniques
dpiml-classifier
defenses
format-transformpluggable-transport

Extracted by claude-sonnet-4-6 — review before relying.