Deep Packet Inspection
Deep packet inspection examines packet contents beyond the header, useful for malware detection and data-leak prevention but also enabling tracking and government censorship. Effective encryption (HTTPS, encrypted email) blocks it.
How this supports CIPP/US study
Use this lesson to identify the legal source, actor, data and activity before applying a rule to a scenario. Continue with the CIPP/US study guide.
Only the header is needed to route a packet, but a node can examine the rest - deep packet inspection. Legitimate uses include scanning incoming packets for viruses and outgoing packets for data leaks. Abusive uses include tracking all of a user's online behavior to target ads, or government censorship such as China's 'Great Firewall.'
When communications are effectively encrypted, deep packet inspection can no longer see the contents. After the 2013 Snowden disclosures, major email providers shifted to encrypted email, and HTTPS adoption grew rapidly. Inspection now works mainly on unencrypted traffic or where encryption is broken (e.g. stolen keys).
Key terms - quick answers
What is “Deep packet inspection”?
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.