Back to results
Bibliographic record · Consultation and access
Artículo

Application Identification with pfSense, Snort, and OpenAppID in Academic Lab Networks

Minh-Khanh Vu · Kennesaw State University · 2026

Open access available
Quick overview. Review the resource’s basic details, then access the content using the main button. This page shows only the information needed to identify, cite, and open the work.

Resource access

Open the content from the main option or choose another available source.

DOAJ DOAJ Articles
Entrar por DOAJ
Main access

Open access available

Recurso identificado como acceso abierto, sin confirmar automáticamente si es texto completo directo.
Open resource

Summary

Descripción general del contenido del recurso.

<p>This paper evaluates the practical capabilities and limitations of a widely used open-source network security stack—pfSense firewall, Snort Intrusion Detection System (IDS), and OpenAppID detectors—in academic cy- bersecurity laboratories and small-to-medium enterprise (SME)-like environments. In a controlled virtual testbed, we measure application-level and feature-level identifi- cation performance for major applications (Facebook, YouTube, Zoom) using the pfSense/Snort/OpenAppID configuration. The stack achieves 97% application-level identification accuracy for these applications in our lab dataset, drawing on a library of 3,374 OpenAppID detectors. However, our experiments reveal a substan- tial feature-level detection gap: specific functions such as Zoom file transfers and Facebook messaging can- not be reliably identified or blocked despite correct application-level classification. These findings clarify the architectural limitations of signature-based inspection on encrypted traffic and pfSense plug-in deployments and provide evidence-based guidance for cybersecurity educa- tors and SME administrators when selecting tools and setting realistic expectations. We argue that achieving fine-grained, feature-specific policy control will require hybrid approaches that combine traditional signatures with advanced machine-learning-based traffic classifica- tion rather than relying on signature-based methods alone.</p>

How to cite

Elegí el formato que necesitás y copiá la referencia al portapapeles.

APA 7

Vu, M. K. (2026). Application Identification with pfSense, Snort, and OpenAppID in Academic Lab Networks. https://doi.org/10.62915/2472-2707.1280

MLA

Vu, Minh-Khanh. "Application Identification with pfSense, Snort, and OpenAppID in Academic Lab Networks." 2026. https://doi.org/10.62915/2472-2707.1280.

Chicago

Vu, Minh-Khanh. 2026. "Application Identification with pfSense, Snort, and OpenAppID in Academic Lab Networks.". https://doi.org/10.62915/2472-2707.1280.

Harvard

Vu, M. K. 2026, Application Identification with pfSense, Snort, and OpenAppID in Academic Lab Networks, Kennesaw State University, available at: https://doi.org/10.62915/2472-2707.1280 [Accessed 6 Aug. 2026].

Share and print

Save the record, copy its permanent link, or print it as a PDF.

Export reference

You can export the record in common formats for use in a reference manager.

Resource details

Bibliographic information to help confirm that this is the correct material.

Title
Application Identification with pfSense, Snort, and OpenAppID in Academic Lab Networks
Author / contributors
Minh-Khanh Vu
Publisher
Kennesaw State University
Publication year
2026
ISSN
2472-2707
ISSN
2472-2707
Language
English

Subjects

Explore related resources through these subjects.

Copied