cPacket NOC–SOC Convergence: Compliance
At Security Field Day 13, cPacket explored how Network Observability empowers SecOps teams to elevate their threat detection and response. In this session, they shifted the lens to NetOps, examining the growing convergence between NOC (Network Operations Center) and SOC (Security Operations Center) workflows. As performance and security become inseparable in hybrid and zero-trust environments, NetOps teams must adopt tools and practices that support both operational resilience and threat visibility. cPacket demonstrated how packet-based observability bridges this gap, enabling NetOps to detect lateral movement, validate policy compliance, and collaborate more effectively with security teams through shared context and real-time data. They emphasized that security is a top concern for all organizations, and the network provides crucial insights to surface issues like malware and vulnerabilities.
Ron Nevo explained how cPacket’s solution empowers NetOps to contribute significantly to the organization’s security posture. Their Deep Packet Inspection (DPI) engine extracts relevant information from every session, including DNS queries and HTTPS queries, even from encrypted traffic (e.g., domain names, TLS certificate validity). This raw data can be used to generate dashboards and reports that feed into security tools. A compelling demonstration involved using an LLM (Large Language Model) to prompt the system to generate a Grafana dashboard tailored to specific HIPAA regulations. This highlights the platform’s ability to create customized compliance reports without requiring deep knowledge of the underlying visualization tools, extending the reach of network observability for security and auditing purposes.
The discussion acknowledged that while AI can create sophisticated reports and highlight suspicious activities (e.g., identifying suspicious domain names by filtering out known benign traffic), human expertise remains crucial for validation and full compliance. The goal is not to replace human operators but to provide them with powerful tools that streamline data analysis, automate report generation, and surface critical insights. By integrating network insights directly into SOC tools and workflows, cPacket enables proactive detection of anomalies and alerts, strengthening the overall security posture and fostering better collaboration between network and security teams. The ultimate aim is to provide the right data to the right person or tool at the right time, enhancing the ability to respond to and prevent security incidents.
Presented by Ron Nevo, CTO, and Erik Rudin, Field CTO. Recorded live at Networking Field Day 38 in Silicon Valley on July 10, 2025. Watch the entire presentation at https://techfieldday.com/appearance/cpacket-presents-at-networking-field-day-38/ or visit https://techfieldday.com/event/nfd38/ or https://cPacket.com for more information.
Transcript
Okay. Another use case here. So, uh, thank you for joining.
Uh, my name's Eric ine. I'm Field CTO for cpac, and I'm joined with Ron Devoux, or as our CTO. And today we're gonna talk about NOx stock convergence and auditing.
This is a very interesting topic for a lot of our customers. Uh, you know, I think it's, it's pretty clear today that security is one of the biggest, uh, top of mind issues for any organization, anybody running customer data. Uh, healthcare, obviously there's compliance requirements, financial services.
Uh, there's a lot of different impacts if a customer gets hacked or if they're starting to have internal challenges related to malware or whatever use case it could be. Um, the network provides insights to help surface up those issues. And this is really important.
This is what we talked about in security field day, is this is a form of augmentation, right? Uh, packets serve multiple functions. They can feed our ecosystem, uh, with packet data streamed into an IDS or an NDR solution to surface up vulnerabilities.
Uh, it could be for sim for surfacing up, uh, correlated events. So packets serve that function, but we also get, uh, session based metrics that also indicate things. And then we're able to use the AI to also surface up security issues from the network data.
So Ron's gonna walk you through, uh, a couple examples of how this works, how the two, two products and the two teams really are starting to function together to improve the security posture for the organization. Thank you. Yeah.
So what we wanted to say here, and, and again, we'll not again, we're gonna, uh, do some of this, uh, quickly. Uh, the idea is we went to, to the security field day and tell the security people, Hey, you should talk to the networking people. They have a lot of information that you can actually leverage.
So we want to tell the networking people have a lot of information that you can leverage, go back to the security team and make the organ the security, uh, posture of the organization, uh, better, right? So part of that is about, uh, we work with many enterprises in the, in the space of, uh, uh, financial services and, and hospitals. And, and there is, there are very strict regulations there, right?
Whether, uh, EPA or FSI, and, and you can think about the information that we have here, and, and it wasn't intended to be read, but the idea is that if you take each one of these, uh, regulations, it can break it down to say, okay, here's the information that you can, uh, get from the network, uh, from your observability solution, right? So we will go for, uh, we, we'll show an example in a second. And the idea is again, like, can, can I take my information that is there and create either a dashboard or create, uh, some information or a report that is driven from the networking, uh, observ, the network observability solution that can be fed into the security tools.
So technically what we're gonna show a lot of that is, uh, our, we have our own DPI engine deep packet inspection. So we, uh, look on every single session we extract the DNS queries, we extract all the HTPS queries. Uh, these are, even when most of the networks run fully encrypted, there's huge amount of very relevant information that is still, uh, can be, can be, uh, viewed as still in plaint text, right?
Which domains you're accessing, making sure that your ld a, uh, servers actually use encryption, uh, the TLS certificates, uh, did they expire or not. So all of that is done inside our packet capture and analytics engine. So if I go for a demo Yeah, go ahead.
For this use case and the previous use case, do we need any additional infrastructure or infrastructure that you normally have in your design? Yeah. Takes care of it.
It's there. That's part of the offering. No additional servers or anything?
Yeah, it's all that. So actually this one is another interesting one. So what this one, uh, we did is, uh, we asked l the LLM engine to say, what are the relevant HIPAA uh, regulations to the information we have, and can you create a dashboard on Grafana that has that?
So this dashboard was completely created by Grafana ass MCP with our prompts. So this is kind of the, another part of the answer to your question, right? Because we may, I think the idea is the reason we do want to get the, um, chat all the way to the user in the foreseeable future.
They're gonna be use cases that we are not aware of. But if you give them enough tools, they don't need, you don't need to know anything about Grafana beyond telling it when it doesn't get it right, you didn't get it right. So it'll figure it out at the end, right?
So you can create on your own the report that you care about, right? So this is just one way to show the relevant information to, uh, hipaa. 1 or or below, uh, that the, um, uh, cipher suites are what, uh, is, is relevant.
All this information is coming in from, uh, is coming in from, from our tools or another one is all the, um, domains that people accessed over the last 24 hours. I have a question though. I mean, I mean I, I I I think that's cool, right?
So I think these things are all useful. I think back, so for HIPAA compliance or even PCI compliance, there is the concept of sort of topology segmentation. Yes.
All these elements, yeah, the, the, not the danger, but like the conveniences, it, it, it plus these kind of graphs kind of cool, right? And you, you feel good about it, but it actually didn't address the actual compliance, you know, you know what I'm saying? Like, let's say PC components, right?
Without the topology, without knowing what applications are running where, and you know, which are your p os, you know, what's, where's your data? That, that, that nice graph and image actually doesn't tell you your state of compliance, right? So how, how do you see, like, how do you see getting there?
How do you tell the LLM, um, in a way that says A PCI compliance, gonna look at the topology, you know, find the data sources, find it, you know, and, and all that after that, walk through it and then using C packet, figure out whether there are probes in the right places or not. 1, we need to verify this, then we need to verify that. And so out of all these things I validated that we can check these things with certainty, and that's in your dashboard, there are these 50 things that we can't check or I dunno how to check that you need to validate before you know that you're compliant.
How do you see us sort of getting to that stage? Yeah, I think to, to, so I'm the last one that will say that AI is ready to replace us. Yeah.
No, I, I, well, I agree. I think, you know, we all agree, we all know sort of where it is, right? And, and these are very, these are indications of the possibilities, which is I, I think why we're all excited, right?
Um, I think what I'm trying to understand is you guys think about this more than maybe I do, right? And so I'm just trying to understand, when you look at these things, how do you think about getting there, right? Right.
What's the path and what do you hope to happen, right? From capability standpoint to get you there? Right?
So the way that you, it's all about the workflow, right? The workflow start with someone that understand hipaa, right? I'm not necessarily understand hipaa, right?
And say someone does, yeah. Okay. That's how it translates.
Then you say, okay, what of all these sections you can actually help me with, right? And if for example, you say, I want to make sure that there is right segmentation, that's something that an observability solution can help you, right? Because we have, so there is a, we, when we deploy, we don't have context to what the mo a physical monitoring point is.
Mm-hmm. But the user does. Mm-hmm.
So all this metadata or what they call rag, right? Access is, is part of what you can give us. And then you say, instead of asking V and 11 to V and 12, you can ask, am I seeing any traffic between HR and finance?
So, so there is an enrichment phase that will have to go in and if you think about the circle that Eric showed, yeah, there is a deployment and yes, have someone, our customer or if you outsource it to someone will have to enrich it with the relevant data. Yeah. If I could just add some additional context to that.
There's a lot of products like, uh, most organizations run multiple tools, right? Um, you know, the, those tools rely on, uh, process, they run, they run on other types of rules that, uh, based on compliance, but they're all dependent on data, right? And so I think our philosophy is we need to be getting the data at the time that it's requested, it needs to be enriched with context.
Mm-hmm. And then we need to have, uh, surface it up to the right person at the right time, right? But we're not necessarily the top of the stack doing all the regulatory compliance checks, right?
But the data that we're providing will serve a lot of functions. Mm-hmm. Got it.
Okay. So we'll see how fast, I think we're running behind time. But the idea here is really where you want to go to is show me all the suspicious domains and the way that, that tool is already.
So if you remember what I showed you just before we left, is yeah, I can generate a report with all the domains, sorry, all the domains, right? But that's a lot of chuff, right? How to figure out the wheat.
So here the tool does know that, okay, it's gonna go through all the domains that we have, make sure that it removes everything that is C packet. Make sure that if we remove everything that is, uh, A CDN or any cloud provider, so it cleans up everything that is, uh, kind of, uh, and you know, it's gonna run for a little more than we have, but so I can just show you the results and it is gonna run, make check, check that the domain names are, uh, check if the domain name is, looks like a DGA. Let's say if the domain name came from Iran or somewhere else and it comes up with, okay, here's five that I think are suspicious, right?
So that's the idea, right? So it's, as you go through the same use case over and over, you can get into, okay, here's what the definition is. Part of that is universal, part of that will have to be in the context of the user.
And do you have, do you have the option to drill down into that stuff from your dashboard? Like Oh, the dashboard? Yeah.
So, so I see this pie chart, can I click on that and kind of drill into it and get more details? But then I also have the option to go to my chat and say, you know, I, I don't wanna click through this stuff. Just tell me what it is.
Totally. Yeah. Okay.
So Again, we, in the previous one, we showed the workflow. So yes. Uh, either our link, there were links there.
So when I click link, I can see all the details for that server. So we have both, right? So today what users are using out in the field is more of the dashboard access, right?
So we have to prepare the dashboard and think what we are showing is like, well, it can, it can evolve, right? With, with AI ncps, these things they can generate on their own and they can go back and forth and I technically go back and forth between them when I investigate something today. Okay?
And, and where I was kind of going with that is some, I mean, it's, it's great to have all of this information. It's a ton of very useful information. Sometimes it's a lot to look through though.
And you want to kind of just focus on a specific area and okay, that is the area I want to go. Let me, let me double click and let me look at this and know, okay, now that's what I wanted to see right there. Yes.
Okay. That's absolutely the problem. We're seeing that we have huge amount.
So there's huge amount of data, there's huge amount of information. Yeah. How do you figure out the handful of things that you can actually do something about, right?
It's fantastic to have all that data in the first place, but sometimes it's, you know, the whole less is more thing where it's like, okay, but I can't focus on all that data, which is obviously what the tool is, is helping with, so, right. Exactly. Yep.
Very good. Thank you. Totally.
Alright, great. Thank you for that demo. So just to summarize, um, I think what we've, what we're really kind of getting here is this consistency theme of making sure that you're getting the right data to the right person or to the right tool.
And a lot of, uh, organizations have SOC tools or SOC teams, they need those network insights and they already have processes and workflows that we can tap into. Um, they have other technologies that need those information at real time to order to secure the enterprise. The other thing is, is those reports are really imp essential.
And so what we're doing is we're getting more insights automatically through the prompts. And now we're, we're taking the, the native data that it has, if it's understanding of a compliance protocol and then surfacing that up to the user, integrating that from a real-time perspective. Obviously that gets to the sim, that gets to the sock, that's how they operate.
So those anomalies and the other types of alerts coming from CPAC to inform normal processes that happen, uh, on the backend.