20060512TP-HOSPInd. 02Homeland Security ProgramTechnical Specification3
At the same time, the powerful probe is taking a number of information called “attributes” for all therecognized protocols, the software doing that is call CAPI-FM , like Flow Monitor. For each protocol, wewill have several attributes, for example:
–
SMTP: sender, receiver, subject, keyword, attachment type, … –
GTP (mobile tunneling) L2TP (fixed network tunneling) : IMSI, MSISDN, called ID, etc… –
WSP (wap): Agent, … –
HTTP: server, URI, agent, …. –
Radius: user, IP address, … –
Webmail: user, IP, subject, keyword,…
It is very important to realise that all those attributes will be given in real time for all traffic (real time meansseconds and not minutes!).Those attributes create a “CDR”, like Call Data Records which is going to be stored in the same data base asthe complete flow. The data base is hence separated in two smaller data base, one being the CDR data basewith all the attributes associated with every protocols and another database with the complete traffic.The filtering will be done based on those attributes, and then if necessary the complete data exchange will bereconstitute (in differed time obviously) like complete email including attached files, VoIP session, chat ,etc…
FIBER CHANNELup to 10kmISP SITE1Gbit/sInterfaceMain international trafic
OPTICAL TAPMAIN ROUTER CISCOSERIE 7500MAIN SWITCHCISCOCATALYST
« Sniffing » PROBE5 X 200MBit/smodules to process1Gbit/s and retrieveALL the traffic
WebNationalNetwork
Monitoring center Request of filtering andstored results of DISK ARRAY12ToDATA BASE server