Deep Packet Inspection
What is Deep Packet Inspection?
A network analysis technique that examines the full content of data packets as they pass through a checkpoint to detect threats, filter content, or enforce policies.
Terms that appear alongside deep packet inspection
Each of these is named in at least one of the same controls as deep packet inspection. The number is how many controls name both.
- management system 2 shared controls
- spoofing 2 shared controls
- firewall 2 shared controls
- audit 2 shared controls
- gateway 2 shared controls
Frameworks that govern deep packet inspection
What the standards actually require on deep packet inspection
Requirements naming deep packet inspection across 4 standards, quoted from the control text.
Use deep packet inspection through AWS Network Firewall, Gateway Load Balancer with third-party appliances or service mesh to inspect and filter traffic for threats.
SEC05-BP03 · Implement inspection-based protection →Detect is the third of five functional elements per MSC-FAL.1/Circ.3/Rev.2. Activities include: (1) Anomaly Detection - behavioural baselines for OT systems (bridge equipment patterns + engine room SCADA + propulsion + cargo) + network anomaly detection (deep...
IMO-MSC-FAL-Detect-AnomalyDetection-OT-IT-Monitoring-Reporting-BridgeAlarms · IMO MSC-FAL Detect Function - Anomaly Detection + OT and IT System Monitoring + Bridge Alarms + Log Aggregation + Incident Reporting Channels + Crew Observation →Security Planes per X.805 Clause 7.4: A Security Plane represents a certain type of network activity protected by Security Dimensions and applied across all 3 Security Layers.
X805-Planes-Management-Control-EndUser-OAM-Signalling-Network-Element-Subscriber-Data · ITU-T X.805 Security Planes - Management Plane + Control Plane + End-User Plane + OAM Operations-Administration-Maintenance + Signalling + Routing + Network Element Activity + Subscriber Data Flows + Cross-Layer Application →Use deep packet inspection or protocol-aware filtering for industrial protocols (Modbus, DNP3, OPC, EtherNet/IP, PROFINET) to enforce allowed function codes and detect anomalies.
OT-NET-2 · Industrial Protocol Filtering and Inspection →Questions people ask about deep packet inspection
What is Deep Packet Inspection?
Why is Deep Packet Inspection important for compliance?
Which compliance frameworks address Deep Packet Inspection?
Where can I learn more about Deep Packet Inspection?
See how Deep Packet Inspection applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.