|

The figure above gives a high level view of the Clouseau®
architecture. Individual modules are explained below. Multiple cores in
Clouseau®’s SoC hardware perform analyses in parallel
for high throughput
- Capture: Captures each packet from the network bridge, making it
available to Clouseau™ for inspection. Other modules in Clouseau™ then have opportunity
to pass/reject packet, and/or take other course of action.
- First Look: Classifies packets for inspection appropriate to their
characteristics. (Each classification has own unique set of fingerprint analysis rules
and DNA markers.) Packets of no interest immediately released.
- Release: After wire-speed inspection, Clouseau™ releases “Pass”
packets back onto the network to continue on to destination.
- Fingerprinting: Looks for DNA markers in message content of each
packer (Layer 7 of TCP). It is important to note, through continuous, thorough global
analysis, SafeMedia compiles and maintains fingerprints and DNA markers of all available
and existing P2P clients and protocols used. Clouseau™ does not need to "read"
packet, only look for DNA markers in certain identifiable positions. Depending on strength
of fingerprint and DNA marker, there are 3 levels of identification. In most cases,
Clouseau™ finds clear fingerprint with DNA markers in a single packet. In those
few cases where fingerprint alone not strong enough to rule out error, Clouseau™
combines DNA marker evidence from multiple packets, using stored history of evidence.
- Machine State: Records machine state of recent DNA markers that
refers to a current session or past misconduct. This allows Clouseau™ to check for
DNA signatures spanning more than one packet or occurrence without reconstructing multi-packet
message streams.
- Action: Takes measures appropriate to specific fingerprint matched in
identification. In most cases, confirmed ID will cause packet to be dropped. Matched
fingerprints and DNA markers also recorded here to be used on other packets of same connection,
or on later attempts to establish new connections.
- Fail Safe and Self-Defense: Takes appropriate actions to maintain
service and restore normal appliance functions in event of hardware/software failure.
Clouseau™ is designed with numerous features to assure fault tolerant and fail safe
behavior.
- Security: Provides secure connection between Clouseau™ and support
for updates; connections and any details of Clouseau's™ work, are strongly protected.
- Update and Remote Management: Updates lists of rules used to detect
fingerprints and DNA markers of P2P traffic and other illegal downloads. Receive secure
and confidential updates via connection through Security module.
- Logging: Records and reports status of system and, for user, aggregated
numbers of packets passed, dropped, and detected. Logged counts can be turned into
reports of the behavior of unit and user's network. No information is collected about
ID of individual packets, users' host addresses, or packet content.
|