Resources

Threat intelligence, research, and everything you need to understand preemptive security.

All resources

Press Enter to search or Esc to close

Case Study

34,622 Connections per Second Under Real Adversarial Traffic

A measured production benchmark with the full security stack active, kept separate from the synthetic stress test.

Last reviewed: October 2026. This is a measured benchmark, not a customer testimonial. Both numbers below are labeled by test type, and neither is a vendor-rated ceiling.

At a glance

ItemDetail
SectorNot publicly documented
PlatformPacketViper v2631 on commodity hardware: Intel Xeon Silver 4215R, 8 cores and 16 threads, 62 GB RAM
Stack activeDeception, AMTD rotation, real-time geo-IP enrichment, 2,301 threat intelligence ipsets and the embedded analytics engine
Production measurementMarch 6, 2026
Stress testMarch 18, 2026

The challenge

Security platforms are usually quoted at a datasheet maximum, often measured on clean synthetic traffic with advanced features switched off. The question here was different: how many new connections per second does the platform sustain while it is under real adversarial traffic and every security function is running?

Approach

Two measurements were taken and are kept separate. The production measurement used real internet traffic with the full stack active. The stress test used a synthetic generator and is labeled as such.

Results

MeasurementResultConditions
Production load (March 6, 2026)34,622 new connections per second (CPS), with 46% of CPU still idleReal adversarial traffic: TCP scans, UDP probes and ICMP from 294 source IPs across 91 countries. Full security stack active throughout.
Synthetic stress test (March 18, 2026)501,496 CPS, with zero kernel packet drops at 500K CPSSynthetic SYN-flood on a 10 GbE link with fully randomized 5-tuples, so every packet is a new connection. Full security stack active. Three consecutive 10-second intervals above 498K CPS.

What the measurements do not show

The 501,496 CPS figure is a synthetic SYN-flood benchmark. It is not production traffic and not a rated capacity.
The 34,622 CPS figure is a measured production load, not a ceiling. Any higher capacity estimate is an extrapolation, not a measurement.
PacketViper does not replace a next-generation firewall for application-layer inspection or SSL/TLS decryption, so connection-rate figures are not like-for-like with platforms that perform those functions.
The tests were run by PacketViper and.

Takeaway

On commodity hardware, with deception and AMTD running, the platform handled 34,622 new connections per second of real adversarial traffic with 46% of CPU idle, and 501,496 CPS in a synthetic worst case. The full benchmark tables and methodology are on the Performance Benchmarks page.

Sources

  1. PacketViper, Performance Benchmarks (published page) Cites PacketViper Engineering Benchmark Reports, March 2026 (v1.0 and v2.1). Accessed 2026-10-09.
What is the difference between the 34,622 and 501,496 CPS figures?

34,622 CPS was measured under real adversarial internet traffic with the full stack active. 501,496 CPS was measured with a synthetic SYN-flood generator on a 10 GbE link, also with the full stack active.

Was the production traffic real?

Yes. The production measurement used real internet traffic from 294 source IPs across 91 countries, including TCP scans, UDP probes and ICMP.

Is 34,622 CPS the maximum the platform can handle?

No. It is a measured production load with 46 percent of CPU idle. It is not presented as a ceiling.

Does this replace a firewall?

No. PacketViper does not replace a next-generation firewall for application-layer inspection or SSL decryption. It adds AMTD, deception and inline contextual enforcement.

Measure it in your environment

Request a proof of concept and see the platform under your own traffic.