Loading... Loading...
Grenze Logo
GRENZE International Journal of Engineering and Technology Vol. 12 (2026), Issue 2

Pattern-based Stateful DPI Intrusion Prevention Engine

Authors

Krishnapriya S, Daniel Madan Raja S

Abstract

It has become a huge challenge to ensure security in real time due to the rapid growth of encrypted and high-speed networks. Traditional intrusion detection systems often depend on offline analysis or signature databases, hence are less effective against live threats. This work proposes the design and implementation of a pattern-based stateful Deep Packet Inspection engine for real-time intrusion prevention. The developed system captures live network traffic, inspects packet headers and payloads, classifies traffic based on rule-based analysis, and blocks policy-violating domains using a dynamic blocklist. The proposed engine allows DNS and TLS traffic inspection and raises real-time alerts against malicious or unauthorized communication. The experimental results show that suspicious traffic can be detected and blocked efficiently with low processing overhead, making the solution suitable for use in an enterprise and smart infrastructure network.