See and control every application flowing through VPP.
PacketLens is an open-source DPI and call intelligence plugin suite for FD.io VPP. It classifies 300+ applications, enforces per-application policy and rate limits, exports IPFIX flow records and SIP CDRs, and applies a three-tier spam filter to flag suspicious calls for transcription and enforcement — all inside the data plane, at line rate, with zero hardware changes.

What PacketLens does
App classification
Identifies 300+ protocols — YouTube, Zoom, Netflix, SIP, RTP, DNS, TLS, QUIC, GTP-U, BitTorrent — using nDPI. SNI extraction, JA3 fingerprinting, risk scoring. Under 8 ns per cached flow.
SourcePer-app policy
Drop or permit traffic by application class. Rules installed at runtime via CLI or binary API — no restarts, no config files. set policy app BitTorrent action drop.
Per-app rate limiting
Token-bucket policer per application. Cap YouTube to 5 Mbps, DSCP-mark excess for downstream QoS — all in the forwarding path. set policer-ndpi app YouTube rate 5M.
IPFIX / NetFlow export
RFC 7011 flow records enriched with application name, category, TLS SNI, and JA3 fingerprint. Sends to any collector — ntopng, Elasticsearch, Splunk, or custom pipeline.
SourcePrometheus metrics
Per-application packet, byte, and flow counters scraped directly from VPP's stats segment. Grafana dashboard included — zero extra config.
SourceSpam & robocall detection — selective transcription
vpp-rtp-asr applies a three-tier filter to RTP audio: keyword spotting, audio heuristics (WPM, energy variance, silence ratio), and per-session score accumulation. Suspicious calls are flagged for transcription via Moonshine ASR — no external recorder, no SIP signaling dependency.
SourceAI-ready enforcement plane
Register any AI/ML scoring function as a callback. PacketLens calls your model once per new flow with the full L7 verdict — application, category, risk score, TLS SNI, JA3 — and applies your policy inline, classification to enforcement in under 1 ms. Pair with vpp-rtp-asr transcripts to run speech-based spam classifiers per call.
SourceSIP CDR export to Homer
Mirrors every SIP packet to Homer SIPCapture via HEP3 — the same protocol used by SBCs and SIP proxies. INVITE, 200 OK, BYE, and all SIP methods land in Homer's call search in real time. set cdr hep server 10.0.0.5 port 9060.
Inside the data plane, not next to it
Commercial DPI appliances sit next to your router on a mirror port. They cost $80K–$300K per chassis, require dedicated hardware, and add an extra hop to your management plane.
PacketLens runs inside VPP itself, as a feature arc node on ip4-unicast. Classification happens in nanoseconds, on the same CPU core as your forwarding path. No mirror port. No extra server. No per-Gbps license.
VPP is the forwarding engine behind 100G–800G production deployments at ISPs and carriers. PacketLens is built to preserve that scale rather than inherit it by assumption — on our bench it adds ~8 ns per cached packet on the fast path once a flow is classified.
Get in touch →$200K
+ ndpi-observe
Live application visibility in Grafana
The included Grafana dashboard shows real-time application traffic — throughput, flow rates, and engine metrics — scraped from VPP's stats segment via Prometheus.

Application classification in action
Watch nDPI classify live traffic in real time — YouTube, DNS, TLS, HTTP/2, and more appear in show ndpi applications as the engine identifies each flow. Per-application packet and byte counters tick up live alongside each verdict.

IPFIX export to any collector
PacketLens exports RFC 7011 IPFIX flow records enriched with nDPI metadata — application name, category, TLS SNI, and JA3 fingerprint. Any standard IPFIX/NetFlow collector can consume the stream.


ntopng dashboard

Per-host breakdown
Lab stack: VPP → IPFIX UDP/2055 → nProbe → ZMQ → ntopng.
SIP CDR export to Homer SIPCapture
vpp-cdr mirrors every SIP packet to Homer SIPCapture via HEP3 — the same protocol used by SBCs and SIP proxies. INVITE, 100 Trying, 180 Ringing, 200 OK, ACK, BYE — every SIP message in every call lands in Homer's call search in real time, enriched with timestamps and flow metadata.

Homer dashboard — 19 SIP messages from 5 concurrent calls captured via HEP3. Two commands: set cdr hep server 10.0.0.5 port 9060 + set interface cdr enable eth0.
Per-app enforcement — drop, permit at wire speed
vpp-policy enforces drop/permit rules inline on the ip4-unicast feature arc. Rules apply only to classified flows — unclassified packets are always permitted so nDPI can finish its verdict.

Two CLI commands to deploy: set interface policy eth0 enable + set policy app BitTorrent action drop.
Per-app rate limiting — drop or DSCP-mark at wire speed
vpp-policer-ndpi attaches a token-bucket policer to each application class. YouTube saturating a link? Cap it to 5 Mbps and DSCP-mark excess packets for downstream QoS — all inside VPP, no separate device.

One command: set policer-ndpi app YouTube rate 5M burst 40K dscp-mark 8.
SIP CDR export — every call captured in Homer
vpp-cdr mirrors SIP packets to Homer SIPCapture via HEP3 — the same protocol used by SBCs and SIP proxies. Every INVITE, 200 OK, BYE lands in Homer's call search in real time. nDPI identifies SIP flows; a port heuristic (5060/5061) handles the rest. The non-blocking UDP socket never stalls the forwarding path. Pair with vpp-rtp-asr to attach a spam score and selective transcript to each CDR entry — flagged calls get both the signaling record and the spoken content.

Two commands: set cdr hep server 10.0.0.5 port 9060 + set interface cdr enable eth0. Homer UI at http://homer:9080.
Three-tier spam filter — flag suspicious calls, transcribe what matters
vpp-rtp-asr intercepts RTP flows inside VPP and runs a three-tier spam detection pipeline entirely in the data-plane worker threads. No external recorder, no SIP signaling dependency — the plugin decodes G.711/G.722/G.729/Opus, resamples to 16 kHz, and scores each 2-second audio segment before deciding whether to emit a full transcript.
Tier 1 — keyword spotting: Moonshine ASR transcribes flagged audio segments and matches against a configurable keyword list ("press 1", "social security", "call now", …). Tier 2 — audio heuristics: silence ratio, energy variance, and words-per-minute consistency catch synthetic TTS voices without any transcript. Tier 3 — session scoring: per-session score accumulates across segments; confirmed spam sources are reported with their score and transcript for downstream enforcement.

Live demo: Piper TTS → ffmpeg RTP → VPP rtp-asr tap → Moonshine ASR → browser UI. Each row is one 2-second audio segment arriving as JSON-UDP.

show rtp-asr spam — thresholds and matched keywords · show rtp-asr sessions — per-SSRC spam score and decision (clean / SPAM? / SPAM!).
Composable plugin stack
Each plugin registers on the same VPP feature arc. Enable only what you need — the data plane cost is proportional to the plugins you activate.
All PacketLens plugins are open-source (Apache 2.0). Commercial support and custom integration available from PacketFlow.
Performance
| Metric | Value | Condition |
|---|---|---|
| Line rate | 100G–800G | VPP multi-worker, scales linearly |
| Overhead per packet (classifying) | ~150 ns | first 3–8 packets per flow |
| Overhead per packet (cached flow) | ~8 ns | bihash lookup only — invisible at any line rate |
| Flow table lookup | O(1) | per-worker, no locks |
| Max flows per worker | 1M | configurable |
| Classification convergence | 3–8 pkts | 95th pct, TCP/TLS |
| Protocols classified | 300+ | nDPI 4.2.0 |
Figures are measured on our own lab bench — a single x86 server driven by a hardware traffic generator — not collected from a production network. Line rate is VPP's established forwarding capability, which PacketLens is designed not to reduce; it is not a figure PacketLens has itself sustained at 800G.
Built on proven open-source foundations
FD.io VPP
Packet processing framework — 100+ Gbps forwarding, used by Cisco, Ericsson, Nokia, and scores of network vendors. Apache 2.0.
ntop nDPI
Deep packet inspection — 300+ protocols, used by ntopng, Suricata, Zeek, pfSense, and Arkime. LGPL-3.0.
Prometheus + Grafana
Industry-standard metrics and dashboards. Zero-code integration via VPP's stats segment shared memory. Apache 2.0.
Get in touch
Want to try PacketLens on a bench, or talk about building on it? We'll get back to you within 24 hours.