Revisiting Layer 2 in Traditional DPI with Realist CFMO Thematic Synthesis

Layer 2 Header field usage in DPI

Authors

  • Shafana Muhammed Shareef Dept. of Information and Communication Technology, South Eastern University of Sri Lanka, Sri Lanka.-Department of Computer Science, International Islamic University Malaysia, Kuala Lumpur, Malaysia
  • Adamu Abubakar Department of Computer Science, International Islamic University Malaysia, Kuala Lumpur, Malaysia

DOI:

https://doi.org/10.31436/ijpcc.v12i2.711

Keywords:

Anomaly Detection, Data Link Layer, EtherType, Thematic Analysis, Packet Inspection

Abstract

Traditional Deep Packet Inspection (DPI) systems rarely emphasize data link layer fields for anomaly detection, despite their foundational role in Ethernet-based communications. To examine this gap, this thematic synthesis consolidates research from 2020 to 2025 on how traditional DPI pipelines utilize link-layer fields such specifically Destination MAC, Source MAC, EtherType/Length, and Frame Check Sequence (FCS) for security-relevant tasks. Using a Realist CFMO lens (Context-Feature-Mechanism-Outcome), eight major studies were analysed in which core link-layer fields like Destination MAC, Source MAC, EtherType/Length, and Frame Check Sequence (FCS) were considered resources which enabled distinct detection mechanisms. Environments included protocol-specific inspection, programmable environments, and spoofing scenarios as well as traffic mirroring settings, with usage patterns, benefits, and outcomes taken as outcome. Results show that field use in data-link layer remains limited but purposeful. It also reveals that the predominant services offered by destination and Source MAC addresses were distinction of served devices, authentication of the sender and session-based grouping of flows, which were supported by the early phases of anomaly detection. EtherType/Length facilitated protocol-level parsing and FCS contributed to integrity validation in one case. The corpus overall had VLAN Tag (802.1Q) was entirely absent, and this indicates a broader underutilization of Layer 2 features in mainstream DPI research. Mechanisms across the literature were largely deterministic and deployed in isolated scenarios, which enhances the secondary importance of data-link inspection compared to higher-layer analysis. The review identifies a major thematic gap and suggests a future research agenda focusing on multi-layer hybrid strategies, VLAN-aware segmentation, and the broader integration of link-layer parsing to optimise DPI-based anomaly detection pipelines.

References

M. Çelebi, A. Özbilen, and U. Yavano?lu, “A comprehensive survey on deep packet inspection for network security,” NOHU Journal of Engineering Sciences, vol. 12, no. 1, pp. 1–29, 2023.

F. A. Khan and A. A. Ibrahim, “Network traffic classification analysis on differentiated services code point using deep learning models for efficient deep packet inspection,” International Journal of Innovative Computing, vol. 14, no. 2, pp. 15–24, 2024, doi: 10.11113/ijic.v14n2.438.

Snort Project, “What are community rules?” Snort.org FAQ, 2025. [Online]. Available: https://www.snort.org

M. Çelebi and U. Yavano?lu, “Accelerating pattern matching using a novel multi-pattern-matching algorithm on GPU,” Applied Sciences, vol. 13, no. 14, Art. no. 8104, 2023, doi: 10.3390/app13148104.

I. Butun, Y. K. Tuncel, and K. Oztoprak, “Application layer packet processing using PISA switches,” Sensors, vol. 21, no. 23, Art. no. 8010, 2021, doi: 10.3390/s21238010.

S. Mubarak, M. H. Habaebi, M. R. Islam, F. D. Abdul Rahman, and M. Tahir, “Anomaly detection in ICS datasets with machine learning algorithms,” Computer Systems Science & Engineering, vol. 37, no. 1, pp. 33–46, 2021, doi: 10.32604/csse.2021.014384.

A. Agrawal, U. Chatterjee, and R. R. Maiti, “kTRACKER: Passively tracking KRACK using ML model,” in Proc. 12th ACM Conf. Data and Application Security and Privacy (CODASPY ’22), 2022, pp. 1–12, doi: 10.1145/3508398.3519360.

W. Song, M. Beshley, K. Przystupa, H. Beshley, O. Kochan, A. Pryslupskyi, D. Pieniak, and J. Su, “A software deep packet inspection system for network traffic analysis and anomaly detection,” Sensors, vol. 20, no. 6, Art. no. 1637, 2020, doi: 10.3390/s20061637.

R. Pawson, T. Greenhalgh, G. Harvey, and K. Walshe, “Realist review—A new method of systematic review designed for complex policy interventions,” Journal of Health Services Research & Policy, vol. 10, suppl. 1, pp. 21–34, 2005, doi: 10.1258/1355819054308530.

S. M. Dalkin, J. Greenhalgh, D. Jones, B. Cunningham, and M. Lhussier, “What’s in a mechanism? Development of a key concept in realist evaluation,” Implementation Science, vol. 10, Art. no. 49, 2015, doi: 10.1186/s13012-015-0237-x.

D. Denyer, D. Tranfield, and J. E. Van Aken, “Developing design propositions through research synthesis,” Organization Studies, vol. 29, no. 3, pp. 393–413, 2008, doi: 10.1177/0170840607088020.

J. Noyes, J. Popay, A. Pearson, K. Hannes, and A. Booth, “Qualitative research and Cochrane reviews,” in Cochrane Handbook for Systematic Reviews of Interventions, vol. 5.0.1, J. Higgins and S. Green, Eds. Wiley, 2008, pp. 1–18.

M. Ouzzani, H. Hammady, Z. Fedorowicz, and A. Elmagarmid, “Rayyan—A web and mobile app for systematic reviews,” Systematic Reviews, vol. 5, Art. no. 210, 2016, doi: 10.1186/s13643-016-0384-4.

A. F. Musfira, N. Ibrahim, and H. Harun, “A thematic review on digital storytelling (DST) in social media,” The Qualitative Report, vol. 27, no. 8, pp. 1590–1620, 2022, doi: 10.46743/2160-3715/2022.5383.

M. Zairul, “A thematic review on student-centred learning in the studio education,” Journal of Critical Reviews, vol. 7, no. 2, 2020, doi: 10.31838/jcr.07.02.95.

S. Mubarak, M. H. Habaebi, M. R. Islam, and S. Khan, “ICS cyber-attack detection with ensemble machine learning and DPI using cyber-kit datasets,” in Proc. IEEE Conf., 2021, pp. 1–6, ISBN: 978-1-7281-1065-3.

J. Nam, S. Lee, P. Porras, V. Yegneswaran, and S. Shin, “Secure inter-container communications using XDP/eBPF,” IEEE/ACM Transactions on Networking, vol. 31, no. 2, pp. 672–685, 2023, doi: 10.1109/TNET.2022.3206781.

S. R. Gulomov, T. R. Khudayberganov, T. T. Turdiyev, A. B. Xasanov, and R. R. Raximov, “Hybrid traffic filtering and anomaly detection model for next-generation networks,” in Proc. 2025 IEEE Ural-Siberian Conf. Biomedical Engineering, Radioelectronics and Information Technology (USBEREIT), 2025, doi: 10.1109/USBEREIT65494.2025.11054242.

X. Liu, Z. Liu, Y. Zhang, W. Zhang, D. Lv, and Q. Zhou, “TCN enhanced novel malicious traffic detection for IoT devices,” Connection Science, vol. 34, no. 1, pp. 1322–1341, 2022, doi: 10.1080/09540091.2022.2067124.

Z. Li, Q. Wei, R. Ma, Y. Geng, Y. Yang, and Z. Lv, “DpGuard: A lightweight attack detection method for an industrial bus network,” Electronics, vol. 12, no. 5, Art. no. 1121, 2023, doi: 10.3390/electronics12051121.

Downloads

Published

30-07-2026

How to Cite

Muhammed Shareef, S., & Abubakar , A. . (2026). Revisiting Layer 2 in Traditional DPI with Realist CFMO Thematic Synthesis: Layer 2 Header field usage in DPI. International Journal on Perceptive and Cognitive Computing, 12(2), 71–81. https://doi.org/10.31436/ijpcc.v12i2.711

Issue

Section

Articles

Most read articles by the same author(s)

1 2 > >>