cPacket Network Observability for Incident Validation and Compliance
cPacket enables continuous security validation and compliance auditing with deep packet inspection, TLS certificate verification, and external domain access analysis. Its AI-enhanced observability platform ensures regulatory readiness, detects misconfigurations, and identifies policy drift across hybrid cloud and enterprise networks—helping security teams maintain an up-to-date posture and pass audits with real-time, actionable insights. cPacket’s solution focuses on ensuring that security postures don’t deteriorate over time due to new threats, outdated rules, misconfigurations, or broken integrations, which can lead to compliance breakdowns, especially in regulated industries like financial services and healthcare. They achieve this through Deep Packet Inspection (DPI) in their C-Store, which breaks down protocols like HTTPS, DNS, and LDAP to extract relevant metadata and performance data. This DPI capability, distinct from simple string matching, allows cPacket to understand protocol details and extract information crucial for security.
One key application of this capability is ensuring server compliance. cPacket’s dashboard provides real-time visibility into factors like TLS certificate status, cipher suite usage (e.g., ensuring adherence to TLS 1.2/1.3 and detecting insecure cipher suites), and the presence of expired certificates. This detailed monitoring helps organizations proactively identify and address compliance issues before they lead to regulatory scrutiny. Another powerful feature is DNS monitoring, which uses AI-enhanced agents to identify “unknown domains” by comparing accessed domains against known CSPs, CDNs, and top legitimate sites. This helps detect potentially malicious domains generated by Domain Generation Algorithms (DGAs) that might indicate a compromise.
cPacket is also developing AI-driven agents that can query their observability data using natural language, making it easier for security experts to analyze complex network activity without needing to master query languages. These agents are designed with controls to prevent improper operations, ensuring data integrity and security. While still in the lab and not yet in production, this capability holds significant promise for intuitive data exploration. Furthermore, cPacket’s platform allows for the analysis of external PCAP files, enabling security teams to leverage cPacket’s robust analytics tools on data captured by other systems, though a direct UI upload option is not yet readily available. Overall, cPacket aims to augment security postures by providing pervasive, real-time network observability that informs validation, ensures compliance, and aids in rapid incident response.
Presented by Ron Nevo, CTO, and Andy Barnes, Senior Director, Technical Marketing. Recorded live at Security Field Day 13 in Santa Clara, CA on May 30, 2025. Watch the entire presentation at hhttps://techfieldday.com/appearance/cpacket-presents-at-security-field-day-13/ or visit https://techfieldday.com/event/xfd13/ or https://cPacket.com for more information.
Transcript
The last section we wanted to talk about is, okay, now we are able to, we built our infrastructure. We are able to detect whether we had, uh, we had, uh, thresholds or not, uh, other devices or other security tools. Were able to deck, we're able to enrich them.
How do we keep things, uh, uh, making sure that we are not going deteriorating? So the last section is gonna be about validate. Uh, it's about compliance auditing, making sure that we're still, uh, meet the, uh, requirements.
And I'm vo, I'm the CEO of cpac. And with me is Andy Barnes, who is our Senior Director of Technical Marketing. And it should be a relatively straightforward story.
Uh, um, why do we need validation? Because all the physics majors here, you know, if you don't actually invest in keeping your room in order, things will deteriorate, right? And in security, it means new threats that you didn't update.
Outdated rules, misconfiguration, broken integration. Uh, and that leads to, you know, compliance breakdown. Again, we deal a lot with financial services and, and healthcare.
One of the things that they like the list is be called to a regulator to explain why things are not as they should be, right? Um, and, and, and what we are able to do is using DPI, and, and I think I touched that. I didn't explain too much about it.
Uh, we do have our own deep packet inspection engine inside our C-store. That's different than the string match. The string match is a string match, right?
This is a hardware based, uh, nice IP that is very useful, it able to match packets at one second. When we say DPI, or at least DPI in this context, even though it stands for D packet inspection, what we mean, what we mean is the ability to break down the protocol and extract the relevant information for, for the understanding the protocol. So again, we've done that mostly for, um, network observability reasons, right?
We break down HTT PS transactions to understand the performance of each server. Uh, we break down DNS transactions to understand what domains people are accessing, what applications to avoid manual configuration. Uh, we break down LDAP because it's one of the biggest issues that network operation teams have.
So we do that and we prioritize, and we, you know, it's not that we have 75 different database ind uh, break, uh, co uh, decoders. Uh, we are very focused on the ones that really bring value to our customers. It so happens, uh, that some of that is relevant, uh, to security too, right?
So the way that it works, our cstore, uh, in addition to generating all the TCP metric metrics, it generates all the, um, metadata and performance data that is relevant to understand specific protocols. Again, htt, PS handshakes, DNS, ldap, um, we have other monitoring that are less relevant here for video and, and for VPNs and whatnot. Uh, but for now, I think I'm just gonna focus on the DNS and the TLS password.
Okay? So what do we do with that? So again, this is the ccle.
Uh, this is the device that Andy was showing you before. Uh, it's a little different page, but this is the main controller. And I'm just gonna show you a couple of, uh, dashboards that we're using today.
One of them is, uh, making sure that your servers are in compliance. So servers like HTPS servers in compliance mean you want certificates to be up to date and you want to make sure that every transaction, uh, stays with tls 1, 2, 1 3 doesn't, you know, you don't get the client that is able to take you down or you don't get the client that is able to pull you down with, uh, unsecured cipher suite, right? So you also, we have to one side monitor all the servers as a baseline and then making sure that each transaction is still protected, right?
So that's the information that we have, right? 2, do we have anything that is using SSL? We certainly, you know, in our network, we run a lot of replays.
So we see that and what type of, uh, certificates, uh, sorry, what type of certificates do we have? Anything that expired? And you can see that we do have that.
And, uh, do we have any transactions that, uh, went down and didn't stay in T LS? One, three, that's one. The second one I'm gonna use video.
And the reason I'm gonna use video is, uh, uh, one of the things that we invested, and I mentioned before, we, you know, everybody's talking about gent ai. So we do have now agents that are able to query both of our, the ai, um, solution we have, as well as the raw data that we have in Sinclair. Uh, one of the things that we have, uh, found out is that, uh, they are somewhat temperamental.
So you may get a somewhat simpler different answer if you ask the same question. So we started, so we decided to record it, but what you're seeing here is, um, is the DNS, uh, the DNS, um, monitoring and, and we're, what we're using for DNS monitoring is really, let me stop just one second. Uh, is, uh, monitor all the, uh, will I be able to go back?
Uh, it didn't stop. So what we're using this thing is not the same. We'll see in a second.
So we're using the DNS is to see all the domains that were accessed over the last 24 hours. So what, what we saw is that that's a lot of data, right? So what that, what we asked for is, okay, go back to the data that you have in ccl.
Tell me if you find any unknown domains. And we define unknown domains by either it's, it's not a known CSP, it's not a known CDN. Uh, we also access the Cisco umbrella, uh, CSV to the top 1 million sites and said, bring me out, bring me everything that is not there, right?
So it's not something that you know of and it's potentially, uh, the domain name was potentially generated by a DGA domain generator, domain generator, uh, algorithm, right? So it came back, he said, okay, here are the things that seems weird. I think we kind of look through it, say one of them, okay, I still understand.
But then you can come back and say, okay, tell me now for that specific domain that I'm not sure who went and got this data. Right? So this is really, um, kind of leaves you, I, I think the, the interesting thing that for me is really, uh, it's pretty powerful tool because it does go and get you some more data and it allows me to not predefine the thresholds, the workflows and all that, right?
Uh, if I get a security expert that has somewhat different way of thinking about problems, they can still work on top of, uh, LLM and still get all the data. Alright, so, sorry. Yeah, go ahead.
This Is Sarah Christensen. Just really quickly, I see SQL queries running. Yes.
Whenever I see AI and SQL queries, I ask what stops it from doing an insert or uh, a drop table. Uh, and you had mentioned it's temperamental, so I'm curious about what kinds of controls are in place, um, to protect against, um, model poisoning, prompt injection, improper data, sanitization, all of that. Yes.
Yeah, it's a great question. So actually what you're seeing is not exactly sql. We are running on top of influx db.
So what you're seeing is, uh, influx questions and the, what we did with the agent, we only allowed, uh, we sanitize the requests. We only allow show and select. So in influx, it's pretty easy to, to make sure that they don't do, uh, any right or drop operations.
Uh, but similarly for, uh, you, you don't really want to give the, uh, agent direct access to your, um, to your database for that, right? So you will, this is why we needed the agent, right? So the agent does, does, the agent performs two things.
One is some level of protection. Uh, the other thing that we found out is that, um, if you see the code, it's, it's, it's a great foreign, an English literature graduate because it has pages and pages of explanation to the model where the data should be and how to run the query. And, uh, I think this whole notion of prompt engineering is, is, is, is coming.
So these are the two reasons that you need to develop the agent, and you can for us right now, uh, versus just let it, you know, go to the database, uh, uncontrolled. So this Is not available yet, or It's not in production? No, this is running in our lab today.
Yeah. Yeah. So the code is there.
So we have, if you saw in the beginning, we do have the agents for all of them. We haven't released them. Uh, and actually some of the challenges of releasing them is many of our customers don't really want to have any access to an, so what I was demonstrating now is, uh, anthropic cloud, right?
Cloud. So You can't run this locally. I run it locally, but I have access to the model.
Okay. So the, the desktop was running locally, but it was using a model from the internet. Yeah.
So you don't have the ability to run the, The model locally? Yeah, we do, we haven't found that they're good enough to, they're not good enough yet. Okay.
Yeah. So the ones that are able to run locally are just not good enough. Uh, Ron, with the, with all the analytics and even the AI LLM stuff, um, is it possible to bring in a packet capture that your system didn't capture and let your system do the analytics on it?
So if I get a packet capture from some other system and I got this suite of great analytics tools, how do I get your tools to analyze that packet capture? Yeah, we do that all the time. So we, you, we replay through, I mean, a lot of the things that you're seeing here is by replaying pickup files that we have from users, customers we generated.
Uh, also the packet capture itself has the ability to replay. So if you did capture it on our, then we can replay it. But this is really, if you want to replay it in real time, a hundred gigabit per second or more.
But if you just want to analyze it, you can take any server and send it to us. Okay. Yeah.
We certainly do that all the time. So you guys, I mean, I'm not, I don't wanna replay it through the network, of course. I just want your Sure tool to, to break down all the packets and sessions and stuff.
So then I, you know, I think the huge value in the, in the LLM is interacting with, you know, um, yeah. Natural language to get to packets. Like I'm very fortunate enough, I memorized most of the display filters in Wireshark.
Yeah. But for people who didn't, they just want to ask questions. Yes.
Show me the packets that do this. Yes. Um, and I think it's great if you guys captured them, but you know, if you didn't capture them, but I have the captures.
Yes. Yeah. You just take, you take a server, TCP replay and connect it to one of our packet broker ports.
You don't have to run it on the network again. Okay. But you guys don't have like a file import or upload option.
That's kind of what I was getting at. Yeah. You know, in your UI or your web u you know, your web ui, I need to be able to like upload a PCAP for analysis.
We, we can, we didn't expose it as a feature today. Okay. Yeah, We can, all right.
We have what we call report. So we can capture packets, we can upload them. There is an API to do that.
It's not an easy UI access. Okay, thanks. Sure.
We got one slide left, so we are wrapping up now. So that is pretty much what we've got for you guys today. Um, again, the main point that we made throughout, hopefully successfully was that, uh, you know, network observability is not a replacement, but really can augment and strengthen your security posture.
And so we'd love to get validation from this. Again, this is our first time doing a security field day, so we just kind of threw it all out there. And, you know, by all means, we are very interested in learning from the community as well.
So, you know, please provide feedback, talk to your teams, and, um, validate the use cases that we presented. And if there's any specific problems that you have, we'd love to try and help that QR code. There is actually an email.
Um, this is dangerous to me and, uh, to the team, so feel free to, to reach out directly and we'd love to again, engage further after this. So.