Lawful Interception

Thanks to the internet, we all live in an interconnected global village. Therefore, it is all the more important to prevent data breaches and put a stop to malicious activity before it is too late. Because it is no longer possible to tell which data flow in the network from TCP/UDP port numbers, many security vendors have developed solutions using deep packet inspection (DPI), which provides a suitable means of detecting security threats. A problem that security vendors are currently facing nowadays is the deluge of data that high-speed networks bring. For this reason, it is necessary to deploy a solution that accelerates the DPI process.

traffic-strucutre.png

Aggregated network traffic structure for North and South America. Source: Global Internet Phenomena Report: North America and Latin America, Sandvine

Even the best DPI software is useless when the server it is running on does not have enough processing power to detect intrusion candidates because it wastes its performance on inspecting traffic that is uninteresting for DPI, such as YouTube and Netflix videos. In order to free up valuable CPU cycles, accelerate DPI and ensure real-time protection, it is necessary to offload preprocessing of the traffic to the hardware before it goes to the software.

Read whitepapers: 

Netcope Session Filter is a solution that is capable of filtering the traffic in hardware on a per-session basis (a YouTube video stream, an email session, a VoIP call), while a session is a sequence of packets with the same source and destination IP address, L4 protocol or TCP/UDP ports or, optionally, other fields. Thanks to this type of traffic preprocessing, real-time DPI is becoming a reality even in 100G networks.
 

Netcope Products Offer:

product-img_packet-capture1.png
  • Ready-to-use firmware with wire-speed hardware filters:

    • Stateless for traditional LI (L3 and L4 header fields)

    • Stateful for flow-based LI (L4 network flows)

  • Full 100Gbps RX throughput to SW

  • Support for multiple technologies on a single card (100/40GE + 10GE)

Explore more Netcope products

Netcope Session Filter (NSF)

Netcope Session Filter (NSF)

Learn more about Netcope's powerful session-oriented packet capture solution.

Netcope Development Kit (NDK)

Netcope Development Kit (NDK)

NDK enables rapid design, prototyping and evaluation of hardware-accelerated applications.

Netcope Success Stories

NSF-100G2-Picomass-Netcope

NSF-100G2-Picomass-Netcope Network Traffic Monitoring

Picomass uses Netcope Session Filter in the IPS200 DPI solution because NSF is capable of offloading traffic to hardware. This makes real-time DPI on 100G networks possible.

Flowmon Networks

Flowmon Networks Network Traffic Monitoring

Flowmon Networks aims to develop a new generation of NetFlow/IPFIX probes that can monitor and process traffic of 100GE high-speed networks. Because of that, Flowmon Networks needs to find a network card that would be able of handling 100 GE monitoring requirements.

U.S. trading firm deploys Tradecope

U.S. trading firm deploys Tradecope Electronic Stock Trading

For successful trading on electronic exchanges today, it is not enough to come up with the smartest strategy anymore. Learn more about how U.S trading firm deployed FPGA-based Tradecope solution to increase hit rate of the trading strategy.