head

Where Intelligence Becomes Insightful

DATABASE LAYER

While DPI delivers real-time visibility, true power lies in retaining, indexing, and analyzing this intelligence over time. The Database Layer enables just that. It stores metadata, session records, and enriched intelligence generated by the DPI and Mediation Layers, creating a historical backbone for everything from threat hunting to lawful evidence retrieval.

Database Layer Functionality

With structured, enriched data models, fast querying, and flexible retention policies, it ensures critical insights are always accessible, secure, and ready for real-time or historical analysis.

High-Volume Data Storage

• Designed to handle billions of records per day, with support for petabyte-scale deployments.
• Optimized for telecom and security use cases - not just general-purpose logging.

Structured & Enriched Data Models

• Data stores:
    ◦ Flow/session metadata (5-tuple, app, timestamp, duration).
    ◦ DPI attributes (protocols, services, SSL fingerprints).
    ◦ User identifiers (IMSI, MSISDN, IP address, device).
    ◦ Geo-location, ASN, and time-based context.

• Supports custom tagging and labeling for advanced filtering.

Fast Querying & Retrieval

• Index-optimized for fast searches by:
◦ User or device ID.
◦ Application or protocol.
◦ Time range.
◦ Source/destination IP or country.

• Ideal for both real-time lookups and historical investigations.

Retention Policies & Lifecycle Management

• Data can be stored for days, months, or years, depending on:
◦ Legal requirements.
◦ Tiered storage policies (hot/warm/cold data).

• Supports automatic archiving, compression, and encryption.

Technology Stack (Abstracted for Commercial Use)

• Uses a combination of time-series, relational, and optionally big data storage technologies:
◦ SQL (PostgreSQL, MySQL).
◦ Time-series DBs (InfluxDB, TimescaleDB).
◦ Optional • NoSQL or distributed systems (Elasticsearch, Cassandra, ClickHouse).

• Storage engines are modular and scalable, adaptable to:
◦ Single-node or distributed deployments.
◦ On-premises or cloud-based environments.
◦ Real-time dashboards and batch exports.

background

Long-Term Visibility Starts with Smart Storage

Compliance & Security Built-In

• Role-based access control (RBAC) for data retrieval.

• Full audit trails of who accessed what, and when.

• Data encryption at rest & in transit.

• Optional integration with SIEMs or eDiscovery platforms for forensic workflows.

Use Cases by Stakeholder

Telcos

• Historical QoS tracking for SLA management. • Usage trend analysis for customer behavior & marketing. • Root-cause analysis of network events.

Value Proposition

High-speed data access

• Supports time-sensitive investigations.

Flexible retention & compliance

• Meets regulatory and operational needs.

Centralized intelligence hub

• Correlates data across access types, regions, and timelines.

Scalable architecture

• Grows with your national or multi-network deployments.

Connected to the Ecosystem

The Database Layer is fully integrated with:

• Analytics Dashboards (for trend visualization & reporting).

• Mediation Layer (feeds structured, policy-tagged data).

• Control Plane (for retrospective policy validation).

• External APIs (for reporting, exports, or third-party integrations).

The Database Layer ensures that everything is searchable and nothing is lost - from the first packet to the last policy trigger. Whether investigating an incident, fulfilling a warrant, or optimizing network usage over months, this is where deep network intelligence becomes durable, discoverable, and impactful.

Learn More