Networking and High-Performance Systems

MobileScope - Mobile-Core Traffic and GTP Analytics

A C/DPDK mobile-core processing layer validated at approximately 500 Gbps, decapsulating GTP-U into raw IP for downstream PacketLens analysis while separately processing GTP-C control traffic.

ContextConfidential regional mobile-network operator
PeriodOne-year mobile-core analytics program
RelationshipSpecialized mobile-core packet-processing system
Team footprintThree engineers contributed over one year.
GTP-U and GTP-CDPDKMobile corePacket processingPacketLens integration

The system

The customer already operated the PacketLens/IP Analyzer platform for raw IP traffic. Mobile-core user traffic reached that analysis environment inside GTP, so OPTIME engineered MobileScope as a specialized high-performance preprocessing layer in front of PacketLens.

The user-plane path captures GTP-U traffic, parses and decapsulates the subscriber payload, and emits the underlying raw IP traffic for downstream analysis. PacketLens was the primary verified downstream system in this deployment, although the normalized output architecture does not inherently restrict the traffic to one consumer.

GTP-C follows a separate control-plane path for session and control analysis. A local C++/Qt engineering interface allows operators to inspect captured GTP session and control-plane information without implying that the tool modifies live subscriber sessions.

Engineering relationship

Across a one-year mobile-core engineering program, OPTIME designed and delivered the C/DPDK packet-processing path, GTP-U decapsulation, separate GTP-C analysis, raw-IP handoff, PacketLens integration, and local C++/Qt operational interface.

MobileScope is one specialized component in a modular traffic-processing architecture. It performs mobile-core/GTP normalization; PacketLens performs deeper raw-IP classification and selective analysis; ProtocolForge handles a broader set of encapsulations as an independent preprocessing service.

Engineering constraints

  • Capture and process very high-rate monitored mobile-core traffic with low packet-processing overhead.
  • Keep GTP-U user-plane decapsulation separate from GTP-C control/session analysis.
  • Recover raw subscriber IP traffic without exposing subscriber identities or private mobile-core topology.
  • Minimize packet loss and monitored-path latency under high traffic rates without making absolute zero-loss claims.
  • Feed the existing PacketLens platform through a clear modular boundary.
  • Provide local session/control-plane visibility without changing live subscriber sessions.
  • State approximately 500 Gbps only as tested and validated GTP-U throughput, not current customer traffic.

What OPTIME engineered

  • DPDK-based capture and packet distribution for the monitored mobile-core traffic stream.
  • A performance-critical C data path for parsing and GTP-U decapsulation.
  • Extraction of underlying subscriber payload as normalized raw IP traffic.
  • Handoff of decapsulated IP to the existing PacketLens/IP Analyzer platform.
  • A separate GTP-C parsing and session/control-information analysis path.
  • C++ session-analysis and administration components.
  • A Qt local engineering interface for captured GTP information and operations.
  • Linux deployment, high-rate validation, and production integration.

Architecture

  1. User plane - monitored GTP-U traffic

    Captured mobile-core user traffic enters the high-performance preprocessing layer without exposing customer topology.

  2. User plane - DPDK capture

    DPDK provides high-throughput packet I/O with reduced operating-system overhead.

  3. User plane - C packet-processing path

    Performance-critical parsing and buffer handling execute in the native data plane.

  4. User plane - GTP-U decapsulation

    Mobile-core encapsulation is removed to recover the underlying subscriber IP payload.

  5. User plane - raw IP output

    Normalized traffic is forwarded to PacketLens/IP Analyzer, the primary verified downstream consumer.

  6. Control plane - GTP-C capture and parsing

    Control traffic is processed independently from the high-volume user-plane path.

  7. Control plane - session information

    Parsed control data supports generalized session and operational analysis without claiming live-session modification.

  8. Control plane - C++ / Qt interface

    The local engineering UI presents captured GTP session and control-plane information to operators.

Key engineering decisions

Separate user-plane and control-plane processing

GTP-U decapsulation follows a high-rate raw-IP production path, while GTP-C is parsed independently for session and control analysis. Each workload can be engineered around its own traffic and information characteristics.

Use DPDK for the monitored data path

DPDK reduces packet-I/O and operating-system overhead, helping the C data plane limit processing latency and packet loss under high traffic rates without making universal line-rate or zero-loss claims.

Normalize before deep analysis

MobileScope removes GTP-U encapsulation and emits raw IP rather than duplicating PacketLens analysis. This preserves specialized component responsibilities and independent scaling.

Keep the operator UI outside the packet hot path

C++/Qt administration and session inspection remain separate from the performance-critical C/DPDK user-plane processing path.

Related engineering platform

Mobile-core traffic flows through MobileScope for GTP-U decapsulation before the resulting raw IP reaches PacketLens for classification and selective protocol analysis. GTP-C follows a separate local control/session-analysis path.

ProtocolForge provides a related generalized normalization layer for QinQ, MPLS, VNTag, GRE, and GTP encapsulations. The services remain independently deployable rather than forming one monolithic data-plane process.

Verified capability

The system was delivered and remains in production. Its GTP-U path was tested and validated against approximately 500 Gbps of traffic; that figure describes validation capacity, not the unknown current customer traffic level.

Verified result

MobileScope provides the production mobile-core preprocessing boundary that converts GTP-U traffic into raw IP for PacketLens while retaining a separate GTP-C analysis and local administration path.

Verified metrics

Validated GTP-U throughput

Approximately 500 Gbps

Tested GTP-U processing throughput; not a claim about current production traffic volume.

Technology & Engineering Role

C
Performance-critical packet capture, parsing, and GTP-U decapsulation.
DPDK
High-throughput packet I/O and reduced packet-processing overhead.
GTP-U
Mobile-core user-plane encapsulation and decapsulation.
GTP-C
Mobile-core control-plane and session analysis.
Raw IP
Decapsulated subscriber traffic forwarded for downstream analysis.
C++
Session-analysis and administration components.
Qt
Local engineering and administration interface.
Linux
High-performance packet-processing and production runtime.
PacketLens integration
Primary verified downstream deep IP traffic analysis.

Related engineering

CONTACT US

Tell us about your project, and let’s create something together

Austin, Texas

Distributed engineering teams across North America, Europe, the Caucasus, and Latin America.

[email protected]

We use the information you submit to respond to your inquiry and process it through the service providers required to operate this form.