Keep the data plane focused
PacketLens performs capture, classification, bounded protocol analysis, filtering, and routing while leaving specialist functions such as SSL processing and broader IDS analysis in dedicated customer systems.
Networking and High-Performance Systems
A production C/C++ and DPDK ISP traffic-intelligence platform that evolved from an initial 100 Gbps requirement to more than 1 Tbps, combining protocol analysis, packet filtering, and traffic steering into specialized downstream systems.
PacketLens captures raw IP traffic from ISP network infrastructure and applies high-throughput TCP/UDP processing, protocol classification, packet filtering, selective protocol analysis, and configurable traffic steering. The platform turns a large monitored traffic stream into purpose-specific analysis and output paths without claiming to replace every security or analytics appliance around it.
OPTIME-built analyzers process HTTP and mail protocols including SMTP, POP3, and IMAP, with attachment handling inside the mail-analysis workflow. The platform also evaluates selected Layer 3 and Layer 4 conditions such as SYN flood behavior. This bounded scope is not presented as a complete intrusion-detection system.
Other traffic is classified and directed to specialist customer infrastructure. SSL/TLS traffic can be sent to an existing SSL-processing appliance, selected security traffic can be routed to the customer’s IDS, and additional filtered streams can feed other analysis tools. PacketLens steers those flows; it does not claim to decrypt TLS or implement the customer’s IDS.
Across a five-year program, OPTIME engineered the C/C++ and DPDK data plane, TCP/UDP and application-protocol analysis, packet and protocol filtering, configurable routing, external-tool integrations, and the C++/Qt local administration environment.
PacketLens is the raw-IP analysis layer in a related modular architecture. MobileScope removes GTP-U encapsulation from mobile-core traffic before feeding PacketLens, while ProtocolForge normalizes QinQ, MPLS, VNTag, GRE, and GTP traffic as an independently deployable preprocessing service.
Monitored network traffic enters PacketLens as raw IP, including normalized output from upstream preprocessing systems.
High-throughput packet I/O moves traffic into the native processing environment with reduced operating-system overhead.
The data plane classifies TCP/UDP traffic and applies configured protocol and packet-level routing criteria.
Selected HTTP traffic enters the OPTIME-built application-protocol analyzer.
SMTP, POP3, and IMAP traffic enters the mail-analysis path, including attachment processing.
Built-in processing evaluates bounded conditions such as SYN flood behavior without claiming complete IDS coverage.
Encrypted traffic selected by policy is routed to the customer’s existing SSL-processing appliance; PacketLens does not claim decryption.
Selected traffic is steered to the customer’s IDS or other purpose-built analysis tools.
The local interface supports filter, routing, analysis, and operational workflows outside the packet hot path.
PacketLens performs capture, classification, bounded protocol analysis, filtering, and routing while leaving specialist functions such as SSL processing and broader IDS analysis in dedicated customer systems.
Protocol and packet-filter criteria direct each selected flow toward the appropriate internal analyzer or external tool without exposing the customer’s private rule syntax.
MobileScope and ProtocolForge recover raw IP before PacketLens analysis, allowing preprocessing and deep traffic analysis to scale and deploy independently.
The C++/Qt administration environment controls filters, routes, and analysis without placing interactive operations inside the DPDK hot path.
The platform began around an approximately 100 Gbps requirement and later evolved to process more than 1 Tbps of traffic. The public case does not infer current average throughput, server count, hardware specification, or deployment footprint.
The modular architecture let traffic normalization, PacketLens analysis, SSL processing, IDS analysis, and other specialist functions evolve as separate responsibilities rather than becoming one monolithic service.
PacketLens remains in production as a high-throughput IP traffic processing and steering platform. It combines OPTIME-built HTTP and mail analysis with selected L3/L4 processing and integrations to customer-owned SSL, IDS, and other specialist systems.
The platform evolved from an initial approximately 100 Gbps requirement into a production system capable of processing more than 1 Tbps while retaining modular boundaries around specialized downstream analysis.
The starting traffic-processing requirement for the platform.
The later production traffic-processing capability; not a claim about current average throughput.
CONTACT US
Austin, Texas
Distributed engineering teams across North America, Europe, the Caucasus, and Latin America.
[email protected]