Packet contents
Deep Packet Inspection
Network equipment that examines packet contents beyond headers.
Read the definitionThe definition and detection notes below retain the published reference wording. They are not a current network test.
01 / Definition
What it means.
Deep Packet Inspection (DPI) technology examines the full content of network packets, not just routing headers. This enables sophisticated filtering based on protocols, content patterns, and application signatures.
DPI is the foundation of advanced censorship systems, enabling SNI filtering, protocol detection (blocking VPN protocols), and content-based filtering. It requires significant infrastructure investment but enables precise, evasion-resistant censorship.
02 / How We Detect This
What we look for.
We identify DPI through behavioral analysis: testing for protocol-specific blocking, examining how connections fail (RST timing, injected responses), and detecting signature-based blocking patterns. Inconsistent blocking that varies by packet content rather than destination indicates DPI presence.
03 / Examples
What it can look like.
VPN protocols blocked regardless of destination
Connections reset mid-stream based on content
Protocol obfuscation required to bypass blocks
Illustrative examples from the glossary, not incident reports or live observations.
Sources
Read the original.
Reference context & original shorthand
Published bypass label: Hard to bypass.
This is the original index’s editorial shorthand. Actual access depends on the network and technique; this label is not a guarantee. The glossary has no per-entry publication or review date.
Related links lead to definitions in the published glossary.
Complete definition →