NINOX: Seeing Clearly in the Dark
Introducing Netify's next-generation deep packet inspection engine. NINOX provides lightweight, high-performance protocol identification and rich traffic intelligence without the memory overhead of legacy DPI architectures.
Seeing Clearly in the Dark
The genus Ninox - the hawk-owls - hunts in conditions where most eyes give up. Low light isn't a handicap for an owl; it's the environment it evolved for. It doesn't need more light; it needs better optics.
There exists a parallel in modern day network traffic. It is overwhelmingly encrypted, increasingly tunneled, and moves off well-known ports whenever it suits an application. The visibility problem is no longer "capture more packets". It is what you can resolve from the few bytes that are still in the clear - a handshake, a header block, or a negotiation exchange - before the rest goes dark.
NINOX is Netify's next-generation Deep Packet Inspection (DPI) engine, built for exactly that.
Built from the Ground Up
Every NINOX dissector is a "clean-room" implementation written directly against published IETF standards (RFCs). We didn't port or adapt existing code; we wrote it from the specifications. Across our current set, we cite more than 110 RFCs-from foundational protocols like DNS and FTP to the modern transport stack including TLS 1.3, QUIC, and DTLS 1.3.
This deliberate choice ensures that every heuristic in NINOX is one we can explain, defend, and cite. When NINOX identifies an "obsolete cipher," that judgment is grounded in the standard itself, not just a pattern observed on a network.
High-Fidelity Metadata
Identification is just the beginning. NINOX extracts protocol metadata as a first-class output, providing deep insights into what is happening on your network:
- Encrypted Traffic (TLS / DTLS / QUIC): We recover server names (SNI), negotiate ALPNs, certificate common names, and JA4 client fingerprints. We even decrypt QUIC Initial packets to ensure you get the same handshake detail as standard TCP TLS flows.
- Infrastructure & Mail: Comprehensive session details from DHCPv4/v6, DNS, SSDP, and mail protocols (SMTP, POP3, IMAP).
- Remote Access & Web: Detailed request methods, URLs, hostnames, and user agents for HTTP, along with banner inspection for SSH.
| Category | Protocols Covered |
|---|---|
| Web & Security | HTTP, TLS, DTLS, QUIC |
| Name Resolution | DNS, mDNS, LLMNR, NetBIOS-NS |
| VPN & Tunneling | OpenVPN, WireGuard, IPsec/IKE |
| Mail & Transfer | SMTP, POP3, IMAP, SSH, Telnet, FTP |
| Infrastructure | DHCPv4, DHCPv6, SSDP, STUN, RTP |
Our team is continuously pushing the capabilities, with new protocols being developed and added to the NINOX engine on a monthly basis to ensure comprehensive coverage of the evolving network landscape.
Modern Engineering for Performance
NINOX is written in modern C++17, which allows us to achieve high performance and memory safety without the "weeds" of legacy code.
- Safety by Design: By leveraging C++17 features, we've made the engine inherently more robust against common memory-safety defects often found in packet parsers.
- Efficiency: We’ve moved away from legacy designs that allocate large, fixed blocks of memory for every flow. Instead, NINOX is demand-driven, using a tiny memory footprint for background chatter and reserving resources only for the flows that have something meaningful to see.
- TCP Reassembly: A built-in reassembler handles out-of-order packets and retransmissions, ensuring classification doesn't break just because of network segmentation.
Proprietary Benefits for OEMs
NINOX is proprietary Netify technology, which is a major strategic advantage for our partners. Open-source DPI libraries often carry complex license obligations (GPLv3) that can create legal hurdles for hardware manufacturers and ISPs.
By using NINOX, commercial vendors and OEMs have a frictionless, legally clear path to embed Netify directly into their hardware, firewalls, and firmware without inheriting third-party license conditions.
Internal Development & Evaluation Invitation
NINOX currently serves as our primary internal development branch, shipping as the default detection engine in Netify Agent v5.3.x and later. While Netify Agent v5.2.x remains our stable, long-term support release through 2030, we are looking toward the future.
We are actively seeking users and organizations to help us evaluate the NINOX engine. If you are interested in testing the next era of network visibility and providing feedback on our v5.3.x internal builds, we invite you to join our evaluation program.
Owls don't need more light. Neither should your network visibility. We are building NINOX to be the most efficient, legally sound, and high-resolution engine available.
Join us in evaluating Netify Agent v5.3.x and help shape the future of NINOX.
Learn More
To learn more about the Netify NINOX, please contact our team directly at hello@netify.ai.