Improving Analytical Tools – The Future of Interrogating Data London, October 26 2010
OrbisIP Technology Services
Consultancy
Technology scouting and evaluation
Product Distribution
Technology Readiness Level enhancements
Secure Software Development
Horizon‐scanning & Technology watching
Open innovation services
Security Technology Clusters
Digital Forensics Biometrics Video Analytics Data Mining & Visualisation
Cryptography Network Security Internet Security Secure Software
Security Management & Architecture Data & Database Security Hardware, Embedded & Device Security Homeland Security Over 150 items of novel security technology exist in the OrbisIP Technology Tracker, available online
The OrbisIP Model
Sources of IP
Consumers of IP
IP Requirements IP Requirements Tech. Transfer IP Licensing Payment / Royalties Revenue Share University Research Labs National Research Labs SMEs Security Companies Primes Governments Advisory Board Technology Advisers OperationsSITC conference challenge
".... During the investigations into the London bombings in 2005, 90,000 hard drives and video tapes from CCTV systems were seized, together with 100 computers, 500,000 pages of photocopying, 4000 exhibits, 70 telephones and 10,000 statements” “… a responsibility to capture, consolidate and interrogate massive volumes of structured and unstructured data. How do you make sense out of all the data coming in and then use it to make a difference?” " ... technologies which can assist users in making informed, strategic decisions."The challenges of large scale data analysis
Data tracking, capture, management and
isolation
Retrieval and analysis of large data sets
Analytical impartiality
Data interrogation
Decision support
Actionable intelligence
Reportage and distribution
Helping to address the challenges
Intercept Modernisation Programme ‐ IP data
capture and interrogation –
Network Traffic
Surveillance System
High speed data retrieval and management –
Clusterpoint XML data base
Decision Support and tracking technology –
SheBa
Structured and Unstructured Data Analysis ‐
Leximancer
Intercept Modernisation Programme
“Every email, phone call and website visit is to be recorded and stored after the Coalition Government revived controversial Big Brother snooping plans.” The Telegraph 20 Oct 2010 "We will introduce a programme to preserve the ability of the security, intelligence and law enforcement agencies to obtain communication data and to intercept communications within the appropriate legal framework … Communications data provides evidence in court to secure convictions of those engaged in activities that cause serious harm. It has played a role in every major Security Service counter‐terrorism operation and in 95 per cent of all serious organised crime investigations.” UK Government Strategic Defence and Security Review October 2010Intercept Modernisation Programme
Technical challenges:
Mass capture and storage of data by ISPs
Gathering intelligence from data sets
Interrogate to level of all packets generated at IP
address
Produce auditable interactions with the data set
that conform to existing legislation and can be
submitted in court to support prosecution
Intercept Modernisation Programme
Technical challenges:
Mass capture and storage of data by ISPs
Gathering intelligence from data sets
Interrogate to level of all packets generated at IP
address
Produce auditable interactions with the data set
that conform to existing legislation and can be
submitted in court to support prosecution
NTSS collects data on ALL user network activities
Entirely searchable & scalable NTSS databaseNTSS
1. All TCP & UDP traffic IP packets
between customer and Internet get forwarded to NTSS
2. IP packets are reengineered back to application level information
units (web pages viewed, e-mails sent, documents transferred).
3. All reengineered and analysed information is fully indexed and stored
in Clusterpoint Server database.
4. Easy to use WEB interface provides
necessary tools, to:
• get a quick situation overviews, • search through the collected data, • receive alerts on user defined criteria, • follow up on network user activities, • preview the reconstructed information.
Decoder Internet Traffic
High speed data retrieval and management
The issues: Size of data base and scalability Retrieval or interrogation time The solution – Clusterpoint DBMS – TRL 9 create a fully scalable and fast response time XML based tagged database easily and lineary scalable ‐ no additional development required to scale the storage and necessary processing power can improve data retrieval times in such unstructured data storages 100‐fold and more with response times of sub 5 seconds in multi‐terabyte databasesSECURITY APPLICATION SERVICES Existing databases AUTHORIZED USERS Entirely searchable & scalable NTSS database SECURITY AUDITING AND MONITORING DATA
CLUSTERPOINT NTS ( MULTI-SERVER CLUSTER ) XML Clusterpoint API