BeauCoup: Answering Many Network Traffic Queries, One Memory Update at a Time

BeauCoup: Answering Many Network Traffic Queries, One Memory Update at a Time
复制标题

DOI:
10.1145/3387514.3405865
复制
发表时间:
2020-07
期刊:
Proceedings of the Annual conference of the ACM Special Interest Group on Data Communication on the applications, technologies, architectures, and protocols for computer communication
影响因子:
--
通讯作者:
Xiaoqi Chen;Shir Landau Feibish;M. Braverman;J. Rexford
Xiaoqi Chen;Shir Landau Feibish;M. Braverman;J. Rexford
中科院分区:
其他
文献类型:
--
作者:
Xiaoqi Chen;Shir Landau Feibish;M. Braverman;J. Rexford

文献摘要

被引文献

相似文献

网络管理员经常监控网络流量,防止拥塞和攻击。他们需要同时对流量进行大量的测量,以检测不同类型的异常,如重击者或超级传播者。现有技术通常侧重于单个统计数据(例如,流量)或流量属性(例如,目的地IP)。然而,由于每个数据包允许的内存访问数量有限,在现代网络设备的受限内存体系结构中执行大量异构测量会带来重大挑战。我们提出了BeauCoup,一个基于优惠券收集器问题的系统,它支持同时进行多个不同的计数查询,同时每个数据包只进行少量恒定数量的内存访问。我们在PISA商品可编程交换机上实现了BeauCoup,在使用其他数据平面硬件资源的适度部分的同时满足严格的内存大小和访问限制。评估表明,BeauCoup实现了与其他基于草图或基于采样的解决方案相同的精度,使用的内存访问减少了4倍。
Network administrators constantly monitor network traffic for congestion and attacks. They need to perform a large number of measurements on the traffic simultaneously, to detect different types of anomalies such as heavy hitters or super-spreaders. Existing techniques often focus on a single statistic (e.g., traffic volume) or traffic attribute (e.g., destination IP). However, performing numerous heterogeneous measurements within the constrained memory architecture of modern network devices poses significant challenges, due to the limited number of memory accesses allowed per packet. We propose BeauCoup, a system based on the coupon collector problem, that supports multiple distinct counting queries simultaneously while making only a small constant number of memory accesses per packet. We implement BeauCoup on PISA commodity programmable switches, satisfying the strict memory size and access constraints while using a moderate portion of other data-plane hardware resources. Evaluations show BeauCoup achieves the same accuracy as other sketch-based or sampling-based solutions using 4x fewer memory access.