You don't need to do deep packet inspection when you just MITM all the traffic.
Madness!
The protocol must be finalized before enterprise-grade products can use it, not the other way around.
socat tcp-listen:8080,reuseaddr,fork 'system:curl $(grep -m 1 GET | cut -d " " -f 2)'
with a little logging to put Nefarious Sites on your Permanent Record.