Heuristics for Detecting ESP-NULL Packets
RFC 5879

A thorough piece of work. Thanks.

I think the Abstract may be a little terse.

   to quickly decide whether given packet flow is interesting
   or not

This phrase doesn't make anything clear. I would prefer you say what you
are attempting to determine and why.

The heuristics seem too weak to recommend for UDP. The misclassification of UDP such as RTP as IPSEC seems like it will do more harm than good. DPI devices will misclassify then fail to apply the right policy. It will be extremely hard to debug in the network as it will only happen to some of the RTP stream.