The project was implemented by VAS Experts together with a local system integration partner. VAS Experts developed the software part of the system and provided expert support, while the partner deployed the ready-to-use solution on the customer’s side.
Project objectives
The operator had previously used Sandvine for working with user traffic data. After support for the solution ended and there was no way to extend its functionality, the operator needed its own UDR generation system that could work with the existing network infrastructure and automatically prepare records for internal systems.
Automated UDR generation
The main task was to automatically collect user session data from HTTP and HTTPS traffic and generate separate UDR files every 15 minutes. The resulting files had to be transferred to the operator’s internal infrastructure. To obtain subscriber data, the system also needed to process RADIUS Accounting from the PGW.
Up to 300 Gbps of traffic and 3 million subscribers
The system had to process mobile traffic from two sites, with a combined volume of up to 300 Gbps and 3,000,000 subscribers. This required support for 100G Ethernet interfaces and distributing processing across multiple DPI nodes. At the same time, the operator needed to be able to increase processing capacity as traffic grew without redesigning the entire system.
Continuous operation
In addition to the functional requirements, particular attention was paid to reliability and data retention. The architecture had to remain operational if individual components failed, while the generated UDRs had to be stored for 90 days.
Solution
The project included a license supporting bidirectional traffic processing and IPFIX statistics export.
From a basic configuration to a high-performance DPI platform, choose the required license level and expand it as the network grows.
Learn more about Stingray licensing options
The hardware part of the solution was built on the ITPOD server platform and included two DPI nodes and two QoE servers. Four 100G interfaces were used on each DPI node to connect the traffic.
The solution was deployed on standard x86 servers.
Figure 1 — Network interaction between the sites
From mirrored traffic to session data
Mirrored traffic from two data centers was sent to the DPI platform, where bidirectional L2–L7 flows were reconstructed and aggregated into unified session records. To associate network activity with a specific subscriber without changing the operator’s existing AAA infrastructure, RADIUS Accounting integration was implemented. The DPI generates a session identifier based on the IP address, while the AAA system provides the corresponding subscriber account. The platform matches this data and maintains the association between the network session and the subscriber even when the IP address changes.
Enriching user session data
The resulting mapping is used to enrich network activity data.
Subscriber information is added to aggregated fullflow and clickstream data, which contain parameters of user sessions and network events.
This creates a unified context in which technical session data is linked to a specific subscriber. As a result, the already aggregated data can be used to generate UDRs without the need to re-analyze individual network packets.
Figure 2 — UDR generation based on AAA, FullFlow, and Clickstream data
Why separate structures and filtering were needed
The next step was to generate the UDRs themselves from the enriched fullflow and clickstream data.
Since UDRs require only part of the collected information, the architecture includes a normalization and filtering layer. Separate UDR generation structures were created based on fullflow and clickstream data, along with rules for selecting the required fields. This made it possible to limit the final record to the parameters required by the operator and exclude unnecessary data during preparation.
As a result, the system became manageable in terms of UDR content and scalable as requirements change.
UDR generation and system scaling
The generated and filtered data is aggregated into text-based UDR files at 15-minute intervals, with HTTP and HTTPS processed separately. The files are then automatically transferred to the operator’s infrastructure.
Two active DPI nodes are used to ensure reliability, while a set of spare parts and equipment is available for rapid recovery.
The solution can be scaled in stages: first, the performance of the existing infrastructure can be increased, and once its capacity is exhausted, additional DPI nodes can be added.
Results
As a result of the deployment, the operator received a User Detail Record generation system that fully met its performance and integration requirements.
The solution provides:
- analysis of up to 300 Gbps of mobile HTTP and HTTPS traffic;
- automatic generation of separate UDRs for HTTP and HTTPS every 15 minutes;
- mapping of user sessions to RADIUS Accounting data;
- support for 100G Ethernet interfaces;
- a fault-tolerant architecture with redundancy for key components;
- further scalability without changing the overall system architecture.
The system successfully passed User Acceptance Testing (UAT), was put into production, and transferred to technical support.
Customer feedback
It was important for us to replace the previous solution with our own UDR generation system capable of handling large volumes of mobile traffic. We would also like to highlight our cooperation with the VAS Experts team and the local partner. The specialists took our requirements into account, helped us complete UAT, and put the system into production.
As a result, we received a clear and manageable tool for working with UDRs that allows us to further develop the system without being tied to the previous solution.