The project was implemented by VAS Experts together with a local integration partner. VAS Experts developed the software component of the system and provided expert support, while the partner deployed the finished solution on the customer’s side.
Project objectives
Previously, the operator used a Sandvine solution to work with user traffic data. After support for that solution ended and it was no longer possible to extend its functionality, the operator needed its own UDR generation system that could work with the existing network infrastructure and automatically prepare records for internal systems.
Automatic UDR generation
The main task was to automatically collect data on user sessions from HTTP and HTTPS traffic every 15 minutes and generate separate UDR files. The finished files had to be delivered to the operator’s internal infrastructure. Obtaining subscriber data also required processing RADIUS Accounting from the PGW.
Load of up to 300 Gbps and 3M subscribers
At the same time, the system had to process mobile traffic from two sites, with a combined volume reaching 300 Gbps and 3,000,000 subscribers. This required support for 100G Ethernet interfaces and distribution of processing across several DPI nodes. The operator also needed to be able to scale up performance as traffic grew without rebuilding the whole system.
Operation without downtime
In addition to the functional requirements, particular attention was paid to reliability and data integrity. The architecture had to remain operational in the event of individual component failures, and the generated UDRs had to be stored for 90 days.
Solution
The project used a license supporting bidirectional traffic processing and statistics transmission via IPFIX.
From a basic configuration to a high-performance DPI platform — choose the license tier you need and expand it as your network grows.
Learn more about Stingray licensing options
The hardware part of the solution is built on the ITPOD server platform and includes two DPI nodes and two QoE servers. Four 100G interfaces per DPI are used to connect traffic.
The solution was deployed on standard x86 servers.
Figure 1 — Diagram of network interaction between sites
From mirrored traffic to session data
Mirrored traffic from the two data centers was fed into the DPI platform, where bidirectional L2–L7 flow reconstruction and aggregation into unified session records took place. To link network activity to a specific subscriber without modifying the operator’s existing AAA infrastructure, integration with RADIUS Accounting was implemented. DPI generates a session identifier based on the IP address, and the AAA system provides the corresponding subscriber account. The platform matches this data and preserves the correspondence between the network session and the subscriber even if the IP address changes.
Enriching user session data
The resulting correspondence is used to enrich network activity data.
Subscriber information is added to the aggregated fullflow and clickstream representations, which contain the parameters of user sessions and network events.
This creates a unified context in which technical session data is linked to a specific subscriber. This makes it possible to use the already aggregated information when subsequently generating UDR, without the need to re-analyze individual network packets.
Figure 2 — Diagram of UDR generation based on AAA, FullFlow, and Clickstream data
Why separate structures and filtering were needed
The next stage was generating the UDRs themselves from the enriched fullflow and clickstream data.
Since UDR requires only part of the collected information, the architecture includes a normalization and filtering layer. Based on fullflow and clickstream, separate structures for UDR generation were defined, along with field selection rules. This made it possible to limit the final record to only the parameters required by the operator and exclude redundant data at the preparation stage.
As a result, the system became manageable in terms of UDR composition and scalable as requirements change.
UDR generation and system scaling
The generated and filtered data is aggregated into text UDR files at 15-minute intervals, with HTTP and HTTPS processed separately. The files are then automatically transferred to the operator’s infrastructure.
To ensure reliability, two DPI worker nodes are used, and a set of spare parts and equipment is kept on hand for rapid recovery.
The solution can be scaled in stages: first by increasing the performance of the existing infrastructure, and then, once its capacity is exhausted, by adding new DPI nodes.
Result
As a result of the implementation, the operator obtained a User Detail Records generation system that fully meets the performance and integration requirements.
The solution provides:
- analysis of up to 300 Gbps of mobile HTTP and HTTPS traffic;
- automatic generation of separate UDRs for HTTP and HTTPS every 15 minutes;
- matching of user sessions with RADIUS Accounting data;
- support for 100G Ethernet interfaces;
- a fault-tolerant architecture with redundancy of key components;
- the ability to scale further without changing the overall system architecture.
The system successfully passed user acceptance testing (UAT), was put into commercial operation, and handed over for technical support.
Customer testimonial
It was important for us to replace our previous solution with our own UDR generation system capable of working with large volumes of mobile traffic. We would especially like to highlight our collaboration with the VAS Experts team and the local partner. The specialists took our requirements into account, helped us get through UAT, and brought the system into commercial operation.
As a result, we got a clear and manageable tool for working with UDR that lets us keep developing the system further without being tied to the previous solution.