Robust Distributed Monitoring of Traffic Flows

Robust Distributed Monitoring of Traffic Flows
复制标题

DOI:
10.1109/icnp.2019.8888046
复制
发表时间:
2019-10
期刊:
2019 IEEE 27th International Conference on Network Protocols (ICNP)
影响因子:
--
通讯作者:
Vitalii Demianiuk;Sergey Gorinsky;S. Nikolenko;Kirill Kogan
Vitalii Demianiuk;Sergey Gorinsky;S. Nikolenko;Kirill Kogan
中科院分区:
其他
文献类型:
--
作者:
Vitalii Demianiuk;Sergey Gorinsky;S. Nikolenko;Kirill Kogan

文献摘要

被引文献

相似文献

可扩展的流量监控面临着流量持续增长、设备异构性和负载不均匀性带来的挑战。我们探索了一种方法,通过将监视任务执行的一部分从过载的网络元素转移到具有空闲资源的另一个元素来解决这些挑战。将任务的整个执行移动到轻负载元素上可能是不可行的,因为对多个元素的执行是任务固有的,或者至少需要特定重载元素的部分参与(例如,为了计费目的,在入口元素上进行流大小计算)。有状态流量监控任务的分布式执行必须对数据包重新排序或丢失(即网络噪声)具有鲁棒性。本文设计了鲁棒流量监控,其目标是在不受网络噪声影响的情况下准确地确定每个流量的流量度量。我们遵循开环范式,不添加任何控制数据包,通过向被监视流的数据包添加少量(按2或4的顺序)控制位来在带内通信流状态,并保持低延迟。考虑了流量大小的计算任务,解析导出了保证所设计算法正确运行的条件,并在实际的流量轨迹上对算法进行了评价。这些算法成功地分配了监控任务负载,而不会增加大量的计算或存储开销。
Scalable monitoring of traffic flows faces challenges posed by unrelenting traffic growth, device heterogeneity, and load unevenness. We explore an approach that tackles these challenges by shifting a portion of the monitoring-task execution from an overloaded network element to another element that has spare resources. Moving the entire execution of the task to a lightly loaded element might be infeasible because execution on multiple elements is inherent in the task or requires at least partial participation by the particular overloaded element (e.g., flow-size computation at the ingress element for billing purposes). Distributed execution of a stateful traffic-monitoring task has to be robust against packet reordering or loss, i.e., network noise. This paper designs robust traffic monitoring where the goal is to determine a flow metric for each flow exactly in spite of network noise. We follow the open-loop paradigm that does not add any control packets, communicates flow state in-band by appending few (on the order of 2 or 4) control bits to packets of the monitored flows, and keeps latency low. We consider the task of flow-size computation, analytically derive conditions assuring correct operation of the designed algorithms, and evaluate the algorithms on realistic traffic traces. The algorithms successfully distribute the monitoring-task load without imposing significant computation or storage overhead.