← All writing

Written October 2026, looking back at Career2 min read

Four months in Kanata

My first internship, at Nokia, writing C++ for a packet-inspection test harness, SIMD signature matching, and the CI that kept test networks honest.

From Nokia · Jan 2023 – Apr 2023

My first internship was at Nokia in Kanata, from January to April 2023, hybrid, on a team that works on network traffic at high throughput. It was four months, so this is a short post, but it was the first time my code ran somewhere that mattered.

The work

Most of my time went into C++ on a deep packet inspection (DPI) test harness. DPI looks inside network packets to work out what protocol or application they belong to. The harness generates and captures traffic so you can check that the classification is correct, at the speeds it has to run at.

A few pieces I worked on:

  • Zero-copy rings and per-core queues. At line rate, copying every packet is expensive and sharing one queue across cores turns into lock contention. Packets stay in one shared buffer and get passed by reference, and each core gets its own queue. That's where most of the "how do we not drop packets under a burst" problem lives.
  • SIMD signature matching. Classifying a packet means comparing its bytes against a set of known signatures. The straightforward version is a long chain of branches per signature. With AVX2, one instruction compares 32 bytes at once, filtering candidate signatures quickly before an exact check confirms a match. That's faster and, just as importantly, more predictable in latency than a branch per signature.
  • A plugin interface. New protocol signatures could be added without touching or rebuilding the capture path, which made the harness useful to more than one team.
  • CI for test environments. I helped automate spinning up the Docker and Kubernetes test networks through Jenkins, so testing didn't depend on someone setting up an environment by hand. I also wrote some Python automation against Jira's API for routing and updating tickets.
The harness pathPackets are passed by reference through per-core queues, and SIMD compares 32 bytes at a time against packed signatures.
Matching signatures: branches vs SIMDThe scalar version branches once per signature. The vectorized version compares 32 bytes per instruction and branches once at the end, so its latency barely depends on the input.

What I took from it

Trust the harness before the speedup. A faster matcher is only worth anything if you can show it's still correct and show the before and after on a setup that doesn't lie to you. That habit, measure first and write the baseline down, is the one I've carried into everything since.

Big-O isn't the whole story. In school I thought about complexity. On this team people thought about cache lines, branches, and memory traffic. None of that shows up in big-O, and all of it shows up in a profile.

Process has scars behind it. Reviews were thorough, and test stages existed because at some point someone had broken something important. I came in thinking the job was about being clever. I left thinking it's mostly about being careful in a way other people can verify.

After it came more school, and then IBM, where I learned how services, rather than packets, fail.