Revisiting OSI Layer4 inTraditional DPI: A Systematic Thematic Review ofTCP Header Fields for Anomaly Detection

Authors

  • Shafana Muhammed Shareef International Islamic University
  • Adamu Abubakar Ibrahim

Keywords:

Anomaly Detection, ATLAS.ti Checksum, Control Flags, Deep Packet Inspection, Network Security, Sequence Number, Transport-Layer Analysis, Thematic Synthesis

Abstract

TCP remains a common transport substrate in operational networks, yet traditional deep packet inspection (DPI) anomaly detection studies report TCP header usage in a narrow and unevenly documented way. Transport-layer header cues are often treated as deterministic signals for steering inspection, but the literature is fragmented in how fields are selected and operationalized across parsing, flow construction, feature extraction, and rule or policy gating. To consolidate evidence, this study conducts a thematic review of TCP header-field usage as reported within traditional DPI anomaly detection studies over a six-year window (2020–2025), using a code-to-document workflow in ATLAS.ti that codes each eligible study by field and functional role. Findings are structured using a Realist Context–Feature–Mechanism–Outcome (CFMO) lens grounded in CMO logic and the view that mechanisms are resources plus reasoning, treating TCP fields as resources (features) that enable DPI mechanisms, consistent with CIMO-style extensions. Publication activity is modest with a peak in 2021, a dip in 2023, a rebound in 2024, and a marked decline in 2025. Destination and source ports are the most consistently reported cues, supporting five-tuple context, service/protocol demultiplexing, and rule or policy selection, while control flags provide state semantics for handshake validation, teardown checks, and misuse screening. Sequence and acknowledgment numbers appear less often and support continuity and manipulation contexts, and data offset anchors header-length validation and payload alignment. Window size is used selectively as a recorded feature, TCP options are rare and mainly reflect MSS evidence in SYN packets, and checksum is sparsely reported and typically appears in niche contexts rather than as a primary detector; reserved bits, the urgent pointer, and header padding are absent as explicit themes. The review contributes a concise TCP field-to-function taxonomy aligned to CFMO, highlights reporting gaps that constrain reproducibility, and proposes an agenda centered on explicit extraction and validation pipelines, baselines for flag and handshake patterns, option-aware parsing and window-scale considerations, transparent checksum interpretation under capture

References

Downloads

Published

2026-08-20

How to Cite

Revisiting OSI Layer4 inTraditional DPI: A Systematic Thematic Review ofTCP Header Fields for Anomaly Detection. (2026). Indonesian Journal of Cyber-AI and Security Intelligence, 1(1), 18-32. https://journal.idnns.org/index.php/ijcasi/article/view/29