cPacket Security Field Day Introduction
cPacket delivers zero-downtime observability for mission-critical networks across finance, healthcare, and government. Trusted with over 50% of global market data, our ASIC+FPGA-powered platform aligns with NIST CSF 2.0 to provide pervasive, scalable visibility across hybrid and cloud environments—enabling real-time packet analytics, rapid threat detection, and enhanced protection for SOC/NOC operations. Founded in 2007 as a semiconductor company specializing in hardware-offloaded string search, cPacket evolved to build a full platform for network observability, initially gaining traction with British Telecom for the London 2012 Olympics. Their core strengths lie in providing nanosecond timestamping, pervasive packet capture, and real-time network analytics across hybrid environments, including private and public clouds, and data centers. Their ideal customers are “zero downtime enterprises” in finance, healthcare, and government that demand packet precision, performance, and the newly added context provided by AI.
cPacket believes that robust network observability solutions can significantly augment and strengthen security postures without replacing existing security tools. Their approach is built on a pervasive, independent, and scalable architecture, allowing them to capture packets anywhere in a hybrid network, from 100 to 400 gigabits per second, and process trillions of packets daily. Crucially, their solutions operate independently of application logs, ensuring visibility even if applications are compromised. The cPacket architecture involves monitoring points (taps, spans, virtual taps) that feed into packet brokers equipped with FPGAs and ASICs on every port. These hardware components enable high-speed packet inspection and counting at the port level, allowing for capabilities like string matching on every packet at speeds up to 1.6 terabits per second.
The solution further includes sophisticated packet capture analytics, capable of writing 200 gigabits per second directly to disk while simultaneously indexing and analyzing packets for session length, duration, and latency. While cPacket does not decrypt data, they extract and analyze a vast amount of metadata from handshakes, DNS calls, ICMP, and other network traffic to gain visibility into network health and potential threats. This collected data and metrics are centralized in C-Clear, where they are enriched, analyzed with AI/machine learning algorithms, and presented through dashboards and workflows, including Grafana and custom APIs. cPacket also offers the ability to push metrics and packets to external object storage for long-term retention or more extensive AI analysis, and is investing in LLM-based interactions for agentic AI, demonstrating their commitment to an open API ecosystem that integrates with security companies, SIEMs, and IT service management platforms.
Presented by Mark Grodzinsky, CPMO, and Ron Nevo, CTO. Recorded live at Security Field Day 13 in Santa Clara, CA on May 30, 2025. Watch the entire presentation at hhttps://techfieldday.com/appearance/cpacket-presents-at-security-field-day-13/ or visit https://techfieldday.com/event/xfd13/ or https://cPacket.com for more information.
Transcript
My name is Mark Radzinski. I'm the Chief Product and marketing officer. And Ron Novo, who's gonna come up is the Chief Technology Officer at C packett.
So, uh, just without further ado, um, how many of you actually watched the Networking Field Day stuff that we did? Thank you, Tom. For the rest of you, who, if you haven't, if you use the quick QR code up in the top, I guess I'm just using that for context setting because I want to know how, how deeply I need to go.
So again, we've got two slides just to kind of remind people who we are and how we got here. And then we're gonna talk, uh, through security. Uh, again, this is the first time we've done security field day networking field day that we did last summer.
Again, we just went through, you know, a, a very deep dive in, in our full portfolio. So, who's c packett? We've been around since 2007.
Started off as a fabulous semiconductor company, uh, building chips to do hardware offload for GRE or string search in real time. This was kind of a problem at the time people said couldn't be done, so of course they went off and did it. Um, then there was a request for a lot of, uh, software and reference designs using these chips.
So they said, okay, we'll just build a platform. And that happened in 2011. British Telecom took notice and really kind of put us on the map because that was one of the first 10 gig networks that was deployed.
And so we were deployed at the London 2012 Olympic Olympics, again, for security purposes, right? So then Ron will come in and can give you all the context on that. Um, the, the, uh, financial services industry took, took notice of that, said, oh, you guys can do nanosecond, timestamping.
Wouldn't it be great if you know, we could do that because we're doing a lot of electronic trading and we need to know how this is all going. So, and then there was a request that came in, Hey, can you also capture those packets, the pcap, and can we, so that we can analyze them later? Um, so then that kind of, we grew into packet capture, network analytics, everything went, moved to the cloud, then everything moved back to the data center.
So we end up with a hybrid solution where, um, we can, no matter where your data's coming from, we can handle it. So our full portfolio is in the cloud, private cloud, public cloud, or in a data center. And now for the last few years, we've been spending a lot of time on, uh, working through the algorithms to, for our AI solutions, and that's gonna be available this year.
And so who are our customers? Our typical ICP, we were talking about this last night, our ideal customer profile. You know, people who are zero downtime enterprises, people who just can't have their networks go down because you know, there's bad things happen, whether it's a financial situation, whether it's a healthcare situation, it's a government agency.
So you can see some of the logos that we got. These are the people that really care about package precision and performance. That's kind of our three Ps.
And we've added the fourth p. Now, I wrote a blog on it recently, you could check that out on LinkedIn, um, about ai. And AI really is providing some of the context to, to your information there.
So again, if you look at the, the, the customers that we have here very much about, um, you know, financial institution exchanges, healthcare, healthcare adjacent, and government agencies. My last slide before we really get into the meat, um, you know, you've seen probably a lot of, in a lot of articles being written lately about sock knock convergence, right? This is more than just operational efficiency where the CIOs and the CSOs are now merging into CISOs and you have your IT people and your security people.
Um, you know, it's really, you can't do one without the other anymore. We've, we were talking last night, you can't, you can't secure what you can't see, right? So the security people need to be able to see everything that's happening in the network.
And frankly, the network, you could have the best performing network. It's useless if it's not secure, right? So these two things are absolutely come coming together.
And what we're here to talk to you about is, again, we are unapologetically networking people coming to a security field day. And the reason we are coming here is because we believe, and we're gonna spend the next 90 minutes showing you, and you can tell us how successful we were at the end, that the right network observability solution will augment and strengthen your security posture. We're not saying that we are replacing our security, you know, the security tools that you use every day, but we can make them better.
And so that's, you know, throughout the presentation, we're gonna go through, uh, different sections and we're gonna talk about how, you know, whether it's through detection or through response or validation and compliance, the right networking observability solution can make all of those more powerful. And with that context set, I will hand off to Ron navo, who will now take us through. First and foremost, I think what we've seen over the last years, 12 years and, and a smart show, we have been around for a long time.
I keep saying we're the best kept secret in the industry because we have all these big customers, but usually when I go into a room that I haven't been before, they don't know who CA CT is. Uh, having said that, you know, we have seen a lot of people using us for security purposes, right? Or basically some of the features we have to, uh, again, strengthen their security posture.
So what we'll do is we'll take you through, uh, kind of four sections. We'll actually follow the NIST framework, right? So protect how we detect, how can people use us for detection.
Uh, detection will actually break into two. So I'm a little cheating there because it's gonna be two sections, even though it's one orange quadrant. How do you, how we can do it, uh, with, when you know the threshold and how it can do it with using ai, then, uh, what can you do with our tools to when, you know, a breach happens?
And lastly, can, how do you keep your security posture, uh, up to date? Make sure that, uh, you know, you validate and, and, um, in compliance with whatever security, uh, uh, instructions you have. So the way we think about things and, and the reason that we think that the right network observability for, uh, can help you, uh, get your security posture better, is that by design.
Uh, when we were going after network observability, uh, we had to make it pervasive. When we made pervasive, we mean that we're able to get the packets anywhere. So we're able to run in a hybrid environment and we're able to, uh, run on-prem.
We are able to do it at a hundred gig, 200 gig, 400 gigabytes per second. We're able to look at trillions and trillions of packets per day. We're able to extract out of that millions and billions of sessions, and at the end make sense of them, right?
And we usually do that in order to understand if your network is healthy. The other advantage is because we are coming into this solution kind of from the tap and, and from pickup, we have a pickup. Uh, what is it?
Pickup? Don't, uh, it didn't happen. Uh, it's independent, right?
We're not counting on the logs and the information that is coming from the application. So if the application was compromised and somebody changed the log, we don't care. We still see the, uh, actual thing that happened.
Uh, and lastly, it's scalable, right? We are, it's part of being pervasive. It's, we are able to do things in very, very high speeds.
And, and we'll explain in the solution why, why that is the case, which allows you to, uh, at the end of the day, to get some things that are, uh, detect faster, uh, have less false positives when you detect something and being able to use the data if something happened to make sure that it doesn't happen again, right? So that's all kind of very high level. Uh, we are gonna use this kind of diagram to explain how we deploy and what we do things.
So really our focus is enterprise. You saw the ICPs governments, um, not so much telcos, right? So if you think about the enterprise and the network they have, it's, in today's world, very heterogeneous, right?
They certainly have data centers, A lot of places they have colocations, branches, campuses, and cloud, right? Nobody el everyone that we know of has both, right? So it's always hybrid.
It's always a combination of public cloud, private cloud, and data centers. And really, when you think about network of realty, it needs to be everywhere. So the way we do things is really about, uh, putting the monitoring points.
So these will be the blue ones everywhere that, uh, is, you know, every choke point that, um, network is going through. And we have a centralized view and control that allows us to see, even though things are gonna be very, very distributed, as I'll show you in a second, uh, still collect them place to collect them information into one place such that we can actually access it from one place and understand what's going on across the network. As we go to the solution, we start from the monitoring point, right?
So the monitoring point can be taps spans, uh, virtual taps, anywhere that we can get access to packets. And the first thing we do is, is a packet broker, but it's really kind of under call what the packet broker does in our case, because we are doing a lot of packet analytics at the port. So one thing that distinguishes our products on-prem from other products is that every single port in our packet broker carries an FPGA and ASIC that does a lot of processing, right?
So we are able to inspect and count every single packet and do a string match on every single packet, right? So that's a big difference in other architecture, and we'll spend a lot of time to explain how we utilize that, but it's really means that, one way to think about it, you know, one of the devices we have is, uh, 16 ports of a hundred gigabits per second in a two U rack or the two U box. 6 terabyte per second of packet processing, right?
Versus, you know, a hundred gigabit per second. In, in other cases. The second part of the solution is, uh, the packet capture.
And again, it's under calling it's packet capture analytics. Uh, the unique thing about the architecture we have is that, uh, it's a very hard thing to be able to capture packets and save up to disk, right? I think we talked about databases yesterday.
Uh, being able to achieve 200 gigabits per second right to disc is a big challenge. We're able to do that, but at the same time, we're able to index the packets and we are able to analyze the packets. And the idea behind that is if you cannot do it in real time in memory, you won't be able to catch up later.
All right, so our devices, you hear me probably using the name C-store at some point, really do all that up to speeds of 200 gigabits per second today, Is that only for latency purposes, or, or can you see inside the packets as well? We can see inside the packets. We, so both of these devices are able to see inside the packets, and we'll show exactly what, but the difference is that the first device counts packets.
So you can see how many sim packets did I have? How many CNA packets did I have? How many client hello packets that I have.
The second device also analyze TCP and application level. So it can m uh, session length, session duration, latency. Yeah, but you can't see the actual traffic, the protocols, because I, I know that everything is encrypted.
You, you can see inside that. So you can, No, so we don't un we, we don't unencrypt data. No.
Okay. But there is huge amount of metadata, and that's what we'll show that is, you know, in the hedged, in the handshake and in the DNS, uh, in the DNS calls and ICMP and so forth. This information, we do do, yeah.
Right? Yeah, yeah. We don't unencrypt data.
Okay, thank you. The next level is really the ccle is what called, uh, actually it does a few things. We capture everything in one box, the ability to collect all these metrics into one location, uh, have the workflows done there.
And so on the top right, what you're seeing is really the collection of the analytics, collection of the metrics and reaching of the metrics, running ai, machine learning algorithms on top of that. And on the right hand side, you're seeing the ability to interact with the user. So we have dashboards, we have workflows.
We're using Grafana on top of our interface. Some cases it's our own ai, our own API. And what we've been investing lately is really the ability to use LLM to interact with the data.
So what you call agent agent AI and all that, uh, from the ground up was designed with open APIs. Typically it's rest APIs, sometimes it's MCP APIs, uh, that allows us to work with our ecosystem. So our ecosystem includes security companies like NDR companies that need the packets.
Uh, they include Sims, Datadog, ServiceNow, and obviously the users, again, our customers many time have their own pretty sophisticated security teams. So they build a solution around that. Uh, I'll, I will mention here the external object storage.
Uh, it's not critical to what we're gonna explain, but we have the ability to push both the metrics and the packets into an external storage that either helps us to get a very, very long storage or being native in the cloud, or the ability to run the AI on much more information than what we can do inside a single device. So that will be the end of the introduction. Uh, I think the whole idea is really about, uh, just to say, you know, we have seen it in the real world.
Working people are using our features even though we have never sold ourselves, or never still don't come and say we're a security company. They basically take the features and integrate them. Uh, it was built to be pervasive and open, which helps us to deliver some security value.
And the whole idea is really about can you do things faster, more accurate, less false alarms, and be able to, uh, use the, uh, digital forensics that we can get from the packets to avoid future attacks.