<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CloudShield Blog &#187; Deep Packet Inspection</title>
	<atom:link href="http://blog.cloudshield.com/index.php/tag/deep-packet-inspection/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.cloudshield.com</link>
	<description></description>
	<lastBuildDate>Fri, 03 Apr 2009 21:39:31 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Technology specifics that are in motion&#8230;</title>
		<link>http://blog.cloudshield.com/2009/01/08/technology-specifics-that-are-in-motion/</link>
		<comments>http://blog.cloudshield.com/2009/01/08/technology-specifics-that-are-in-motion/#comments</comments>
		<pubDate>Thu, 08 Jan 2009 17:17:41 +0000</pubDate>
		<dc:creator>Peder</dc:creator>
				<category><![CDATA[Main]]></category>
		<category><![CDATA[CloudShield]]></category>
		<category><![CDATA[Deep Packet Inspection]]></category>
		<category><![CDATA[DPI]]></category>
		<category><![CDATA[Gigabit Ethernet]]></category>
		<category><![CDATA[Lawful Intercept]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://blog.cloudshield.com/?p=35</guid>
		<description><![CDATA[Earlier this week the changes being seen from the impact of new regulations was mentioned.  What has been interesting to watch is the technology specifics that are in motion.  Technology for the support of Lawful Interception was often a circuit &#8230; <a href="http://blog.cloudshield.com/2009/01/08/technology-specifics-that-are-in-motion/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p style="margin: 0in 0in 0pt;">Earlier this week the changes being seen from the impact of new regulations was mentioned.  What has been interesting to watch is the technology specifics that are in motion.  Technology for the support of Lawful Interception was often a circuit based such that clipping onto a phone line or Internet connection drove technology scaled to the performance of the one user.  As users moved to many devices and were mobile with thier communications, technology moved upstream interfacing to phone systems and network equipment that based upon awareness of the registered user selected appropriate information.  Today, relationships on the Internet are vast and dynamic and identity of a user is often not tied to a device or circuit.  As such systems must possess many new advanced analysis, inspection and capture capabilities in order to comply with the regulations.  Three notable technology requirements that really seem to clarify what I see in 2009 are: 10 Gigabit Ethernet, Full Content Capture and Protocol Specific User Identification.</p>
<p style="margin: 0in 0in 0pt;"> </p>
<p style="margin: 0in 0in 0pt;">Taking a look at 10 Gigabit Ethernet first, it seems off-hand as not new for 2009 but in this field I suggest that the meaning behind it really is.  For years we have seen 10GbE as coming, we have built systems that supported 10GbE and all marketed that we were first.  What is interesting is there really seems to be a migration from 10GbE is in the future or our network links are 10GbE but they really aren&#8217;t fully utilized to 10GbE means 10GbE.  What I mean by that is customer expectations and more importantly true need really deals with 10GbE means processing a fully utilized pipe and often bi-directionally for 20Gbps of unique data to inspect.  This has become a dramatic change in processing performance as DPI systems are essentially processing the data and moving from even uni-directional GigE or OC-48 systems to full duplex 10GbE is anywhere from an 8x to 20x processing increase from earlier generation systems in the DPI segment.  With large metro deployments in telcos, multiple 10GbE links are the norm not the exception.  This is where 2009 seems like a year of separating out the technology.</p>
<p style="margin: 0in 0in 0pt;"> </p>
<p style="margin: 0in 0in 0pt;">Full Content Capture is another area that directives and regulations appear to be driving change.  In the past, if content was seen of interest in a packet the desire was to capture it.  That evolved to if you see a session, or more specifically flow, that is of interest, capture the rest of it from here on out.  Now, the requests are that if you see information that identifies a flow of interest, make sure that the flow from the &#8220;start&#8221; of the conversation is captured.  In a sense, this is asking for systems to go back in time and record data.  As this is intersected with the 10GbE requirements this has led to large scale buffering systems to allow for arbitrary window sizes of time to be gathered such that it may be found of interest in the future.  This has led to very different architecture of solutions from the past and appears to be a new trend as we enter into 2009.</p>
<p style="margin: 0in 0in 0pt;"> </p>
<p style="margin: 0in 0in 0pt;">Protocol Specific User Identification is something that is old, but really speaks to the Internet age and the growth of protocols.  At its lowest level what I mean is looking at the content of an exchange with a web site and identifying the target based upon the credentials being passed.  As each and every web protocol or site establishes its own mechanism this leads to different methods for each.  Simply trying to do this for emails, within a specific region, can rapidly lead to dozens of variations. </p>
<p style="margin: 0in 0in 0pt;"> </p>
<p style="margin: 0in 0in 0pt;">The interesting thing from a technology point of view is how vastly and fast the requirements throughout the world are changing in response to new regulations.  While the western world appears slower than other areas to pass such regulations the technology development continues to move along at a fast clip to keep up with global needs.  What will be interesting is how quickly these advanced capabilities spread across the landscape of customers and how the solutions will stand the test of time.</p>
<p style="margin: 0in 0in 0pt;"> </p>
<p style="margin: 0in 0in 0pt;"> </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.cloudshield.com/2009/01/08/technology-specifics-that-are-in-motion/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Regulations are changing worldwide&#8230;</title>
		<link>http://blog.cloudshield.com/2009/01/06/regulations-are-changing-worldwide/</link>
		<comments>http://blog.cloudshield.com/2009/01/06/regulations-are-changing-worldwide/#comments</comments>
		<pubDate>Tue, 06 Jan 2009 21:53:09 +0000</pubDate>
		<dc:creator>Peder</dc:creator>
				<category><![CDATA[Main]]></category>
		<category><![CDATA[Deep Packet Inspection]]></category>
		<category><![CDATA[DPI]]></category>
		<category><![CDATA[EU]]></category>
		<category><![CDATA[European Union]]></category>
		<category><![CDATA[ISS Telestrategies]]></category>
		<category><![CDATA[Lawful Intercept]]></category>

		<guid isPermaLink="false">http://blog.cloudshield.com/?p=17</guid>
		<description><![CDATA[A few weeks ago I had the opportunity to present at the ISS Telestrategies conference on Deep Packet Inspection and Lawful Intercept Technology (http://www.issworldtraining.com/ISS_WASH/).  It was interesting to see how much and how fast this industry is changing.  Regulations are &#8230; <a href="http://blog.cloudshield.com/2009/01/06/regulations-are-changing-worldwide/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p style="margin: 0in 0in 10pt;">A few weeks ago I had the opportunity to present at the ISS Telestrategies conference on Deep Packet Inspection and Lawful Intercept Technology (<a href="http://www.issworldtraining.com/ISS_WASH/" target="_blank">http://www.issworldtraining.com/ISS_WASH/</a>).  It was interesting to see how much and how fast this industry is changing.  Regulations are changing worldwide that are driving the demands for new technologies and vendors are rapidly moving towards building those capabilities.  Furthermore, an industry that was heavily positioned for edge technologies sitting on a targeted link are migrating to aggregation points requiring not only performance but changes in the capability sets to appropriately deliver selected data.  As such this has led to segmentation in the deep packet inspection (DPI) market between those delivering what is being called deep packet capture (DPC) versus a broader DPI (<a href="http://en.wikipedia.org/wiki/Packet_capture" target="_blank">http://en.wikipedia.org/wiki/Packet_capture</a>). Each of these macro changes are worth a dialog in themselves, however, touching on the impact as a whole raises new questions.</p>
<p style="margin: 0in 0in 10pt;"> </p>
<p style="margin: 0in 0in 10pt;">As the world has begun to change or update regulations, such as those seen in the European Union with regards to data retention for the support of law enforcement <a href="http://www.ispai.ie/DR%20as%20published%20OJ%2013-04-06.pdf">DIRECTIVE 2006/24/EC OF THE EUROPEAN PARLIAMENT</a>, these are driving significant new changes to the telecom landscape.  The extent of these regulations drives growth of interception technology at pace with the network growth itself.  The expense of these systems as well as the complexity of protection of the privacy of the data gathered is changing the technology requirements unlike what has been seen before.  The big questions this leads to is how fast can compliance be achieved and will this change the landscape of the class of companies that can support this scale of deployments?  Also, what impact will this have on the architecture of the telecom provider&#8217;s networks as data collection is not a small issue but core to even how the network could be architected to support such directives?  Will this lead to specific variants of technology, such as the thesis of some of the DPC specific vendors for technology designed exclusively for these directives or will the costs of such a large scale deployment require common infrastructure with the telco gear to drive down CAPEX and OPEX of supporting the directive?</p>
<p style="margin: 0in 0in 10pt;">In many ways, more questions than answers but clearly lots of change.</p>
<p style="margin: 0in 0in 10pt;">Read More: <a href="http://blog.cloudshield.com/wp-content/uploads/2009/01/cloudshield-iss-telestrategies-dec-09-445pm.pdf" target="_blank">International Mandates : Changing the Way Law Enforcement Operates</a></p>
<p style="margin: 0in 0in 10pt;"> </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.cloudshield.com/2009/01/06/regulations-are-changing-worldwide/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

