Back to articles
Technology Insight

Mastering Network Visibility: Deploying Deep Packet Inspection with Zeek and Malcolm on VPS

May 28, 2026

Introduction to Modern Network Surveillance

In an era where cyber threats are becoming increasingly sophisticated, traditional firewalls and signature-based intrusion detection systems are no longer sufficient. Organizations now require granular visibility into their network traffic to identify anomalies, lateral movement, and data exfiltration. This is where Deep Packet Inspection (DPI) and advanced network security monitoring (NSM) come into play.

By leveraging open-source powerhouses like Zeek and the Malcolm framework, security professionals can transform a standard Virtual Private Server (VPS) into a robust analytical engine. This post explores the technical intricacies of operating these systems to achieve comprehensive situational awareness.

Understanding the Core Components

What is Zeek?

Zeek (formerly Bro) is not just a packet sniffer; it is a powerful network analysis framework. Unlike traditional IDS that alerts on known patterns, Zeek converts raw traffic into compact, high-fidelity transaction logs. These logs describe every connection, DNS query, HTTP request, and SSL certificate encountered on the wire, providing a goldmine for forensic investigators.

What is Malcolm?

Malcolm is an auxiliary toolset designed to ingest, analyze, and visualize the data generated by Zeek. Developed by Idaho National Laboratory, it packages several components into a cohesive Docker-based environment:

  • Arkime: For full packet capture (FPC) and indexing.
  • Logstash: For data normalization and enrichment.
  • OpenSearch: For high-performance data storage and search.
  • Dashboards: For visual representation of network behavior.

Architectural Considerations for VPS Deployment

Deploying a DPI solution on a VPS requires careful resource planning. Because Zeek is CPU-intensive and Malcolm requires significant RAM for its search engine, your VPS should meet the following minimum specifications:

Component Requirement
CPU 4+ Cores (High frequency preferred)
Memory 16GB - 32GB RAM
Storage NVMe SSD (High IOPS for database operations)

Note: Since a VPS typically sits behind a virtual switch, you must ensure your provider supports promiscuous mode or TAP/SPAN port mirroring if you intend to monitor traffic external to the host itself.

Step-by-Step Operational Workflow

1. Environment Preparation

Before installation, update your Linux kernel and install Docker and Docker Compose. These are essential as Malcolm is container-native, ensuring that dependencies do not conflict with the host OS.

2. Deploying the Zeek Sensor

Zeek can be deployed as a standalone sensor or as part of the Malcolm cluster. When running on a VPS, it is often best to optimize Zeek using AF_PACKET to load-balance traffic across multiple CPU cores. This prevents packet drops during high-bandwidth spikes.

3. Configuring Malcolm Ingestion

Malcolm uses a specialized directory structure to monitor PCAP files. By setting up an automated upload pipeline (via SFTP or SCP), you can send traffic captures from various remote branch offices to your central VPS for analysis. Alternatively, real-time logging can be achieved by forwarding Zeek's .log files directly to the Malcolm Logstash instance.

Advanced Analysis Techniques

Once the system is operational, the real value lies in Protocol Analysis. Unlike simple flow data (NetFlow), Zeek and Malcolm allow you to peer into the payloads. This enables security teams to:

  1. Identify Shadow IT: Detect unauthorized applications using non-standard ports.
  2. Analyze Encrypted Traffic: Use Zeek's JA3 and JA3S fingerprinting to identify malicious clients and servers without needing to decrypt the traffic.
  3. File Extraction: Automatically extract suspicious files (executables, PDFs) from the network stream for sandbox analysis.

By utilizing the Intelligence Framework in Zeek, you can cross-reference network activity against known Threat Intel feeds in real-time, automatically flagging connections to Command and Control (C2) servers.

Optimization and Maintenance

Operating a DPI system is not a "set and forget" task. To maintain peak performance on a VPS:

  • Log Rotation: Implement strict retention policies in OpenSearch to prevent disk exhaustion.
  • Script Customization: Disable Zeek scripts for protocols you do not need to monitor to save CPU cycles.
  • Security Hardening: Since your analysis platform contains sensitive network data, ensure the Malcolm web interface is protected by a VPN or strong IP whitelisting.

Conclusion

The combination of Zeek and Malcolm on a VPS provides a professional-grade DPI solution that rivals expensive proprietary platforms. By mastering these tools, organizations can gain the deep visibility necessary to defend against modern adversaries. Whether you are performing proactive threat hunting or reactive incident response, this stack offers the flexibility and depth required for today's cybersecurity landscape.

Mastering Network Visibility: Deploying Deep Packet Inspection with Zeek and Malcolm on VPS | DPTCloud