Networking and High-Performance Systems

PacketLens - High-Throughput IP Traffic Intelligence Platform

A production C/C++ and DPDK ISP traffic-intelligence platform that evolved from an initial 100 Gbps requirement to more than 1 Tbps, combining protocol analysis, packet filtering, and traffic steering into specialized downstream systems.

ContextConfidential large-scale internet service provider
PeriodFive-year network-visibility program
RelationshipLong-running network visibility and traffic-processing platform
Team footprintApproximately 11 engineers contributed across the five-year program.
Packet processingProtocol analysisDPDKNetwork visibility

The system

PacketLens captures raw IP traffic from ISP network infrastructure and applies high-throughput TCP/UDP processing, protocol classification, packet filtering, selective protocol analysis, and configurable traffic steering. The platform turns a large monitored traffic stream into purpose-specific analysis and output paths without claiming to replace every security or analytics appliance around it.

OPTIME-built analyzers process HTTP and mail protocols including SMTP, POP3, and IMAP, with attachment handling inside the mail-analysis workflow. The platform also evaluates selected Layer 3 and Layer 4 conditions such as SYN flood behavior. This bounded scope is not presented as a complete intrusion-detection system.

Other traffic is classified and directed to specialist customer infrastructure. SSL/TLS traffic can be sent to an existing SSL-processing appliance, selected security traffic can be routed to the customer’s IDS, and additional filtered streams can feed other analysis tools. PacketLens steers those flows; it does not claim to decrypt TLS or implement the customer’s IDS.

Engineering relationship

Across a five-year program, OPTIME engineered the C/C++ and DPDK data plane, TCP/UDP and application-protocol analysis, packet and protocol filtering, configurable routing, external-tool integrations, and the C++/Qt local administration environment.

PacketLens is the raw-IP analysis layer in a related modular architecture. MobileScope removes GTP-U encapsulation from mobile-core traffic before feeding PacketLens, while ProtocolForge normalizes QinQ, MPLS, VNTag, GRE, and GTP traffic as an independently deployable preprocessing service.

Engineering constraints

  • Capture and classify sustained ISP traffic with low per-packet overhead.
  • Scale from an initial requirement of approximately 100 Gbps to a later production capability above 1 Tbps.
  • Perform selected HTTP, mail, transport, and Layer 3/Layer 4 analysis without turning the platform into a monolithic security product.
  • Route SSL/TLS and broader security workloads to the customer’s existing specialist systems rather than duplicating them.
  • Support protocol-based and packet-filter-based traffic routing without exposing private rule syntax.
  • Keep administration and operational analysis separate from the performance-critical packet path.
  • Integrate normalized traffic from MobileScope and ProtocolForge through clear modular boundaries.

What OPTIME engineered

  • A C/C++ high-performance packet-capture and processing data plane using DPDK.
  • Raw IP, TCP, and UDP classification and processing.
  • HTTP protocol analysis implemented by OPTIME.
  • SMTP, POP3, and IMAP analysis with email-attachment processing.
  • Selected Layer 3 and Layer 4 analysis, including SYN flood conditions.
  • Protocol-based routing and packet-filter-based traffic steering.
  • Routing of SSL/TLS traffic toward the customer’s existing SSL-processing appliance.
  • Integration that directs selected security traffic toward the customer’s IDS.
  • Output paths for other customer and third-party analysis tools.
  • A C++/Qt local administration and analysis interface.
  • Linux production integration and sustained performance evolution beyond 1 Tbps.

Architecture

  1. ISP raw IP traffic

    Monitored network traffic enters PacketLens as raw IP, including normalized output from upstream preprocessing systems.

  2. DPDK capture

    High-throughput packet I/O moves traffic into the native processing environment with reduced operating-system overhead.

  3. C/C++ classification and filtering

    The data plane classifies TCP/UDP traffic and applies configured protocol and packet-level routing criteria.

  4. HTTP analysis

    Selected HTTP traffic enters the OPTIME-built application-protocol analyzer.

  5. Mail analysis

    SMTP, POP3, and IMAP traffic enters the mail-analysis path, including attachment processing.

  6. Selected L3/L4 analysis

    Built-in processing evaluates bounded conditions such as SYN flood behavior without claiming complete IDS coverage.

  7. SSL/TLS output

    Encrypted traffic selected by policy is routed to the customer’s existing SSL-processing appliance; PacketLens does not claim decryption.

  8. IDS and specialist outputs

    Selected traffic is steered to the customer’s IDS or other purpose-built analysis tools.

  9. C++ / Qt administration

    The local interface supports filter, routing, analysis, and operational workflows outside the packet hot path.

Key engineering decisions

Keep the data plane focused

PacketLens performs capture, classification, bounded protocol analysis, filtering, and routing while leaving specialist functions such as SSL processing and broader IDS analysis in dedicated customer systems.

Use configurable routing as an integration boundary

Protocol and packet-filter criteria direct each selected flow toward the appropriate internal analyzer or external tool without exposing the customer’s private rule syntax.

Normalize encapsulated traffic upstream

MobileScope and ProtocolForge recover raw IP before PacketLens analysis, allowing preprocessing and deep traffic analysis to scale and deploy independently.

Separate operations from packet processing

The C++/Qt administration environment controls filters, routes, and analysis without placing interactive operations inside the DPDK hot path.

Performance evolution

The platform began around an approximately 100 Gbps requirement and later evolved to process more than 1 Tbps of traffic. The public case does not infer current average throughput, server count, hardware specification, or deployment footprint.

The modular architecture let traffic normalization, PacketLens analysis, SSL processing, IDS analysis, and other specialist functions evolve as separate responsibilities rather than becoming one monolithic service.

Verified capability

PacketLens remains in production as a high-throughput IP traffic processing and steering platform. It combines OPTIME-built HTTP and mail analysis with selected L3/L4 processing and integrations to customer-owned SSL, IDS, and other specialist systems.

Verified result

The platform evolved from an initial approximately 100 Gbps requirement into a production system capable of processing more than 1 Tbps while retaining modular boundaries around specialized downstream analysis.

Verified metrics

Initial requirement

Approximately 100 Gbps

The starting traffic-processing requirement for the platform.

Later platform capability

More than 1 Tbps

The later production traffic-processing capability; not a claim about current average throughput.

Technology & Engineering Role

C / C++
High-performance packet capture, protocol processing, analysis, and routing.
DPDK
High-throughput packet I/O for the native data plane.
TCP / UDP
Transport-layer traffic classification and processing.
HTTP
OPTIME-built application-protocol analysis.
SMTP / POP3 / IMAP
OPTIME-built mail traffic analysis.
Email attachment processing
Attachment handling inside the mail-analysis workflow.
Packet / protocol filtering
Traffic classification and configurable routing.
SYN flood analysis
Selected Layer 3 and Layer 4 threat-condition analysis.
SSL/TLS integration
Steering selected encrypted traffic toward existing SSL-processing infrastructure.
IDS integration
Routing selected traffic toward specialized customer security analysis.
Qt
Local administration and analysis interface.
Linux
High-performance packet-processing and production runtime.

Related engineering

CONTACT US

Tell us about your project, and let’s create something together

Austin, Texas

Distributed engineering teams across North America, Europe, the Caucasus, and Latin America.

[email protected]

We use the information you submit to respond to your inquiry and process it through the service providers required to operate this form.