...
首页> 外文期刊>Computer communication review >Building a better NetFlow
【24h】

Building a better NetFlow

机译:构建更好的NetFlow

获取原文
获取原文并翻译 | 示例

摘要

Network operators need to determine the composition of the traffic mix on links when looking for dominant applications, users, or estimating traffic matrices. Cisco's NetFlow has evolved into a solution that satisfies this need by reporting flow records that summarize a sample of the traffic traversing the link. But sampled NetFlow has shortcomings that hinder the collection and analysis of traffic data. First, during flooding attacks router memory and network bandwidth consumed by flow records can increase beyond what is available, second, selecting the right static sampling rate is difficult because no single rate gives the right tradeoff of memory use versus accuracy for all traffic mixes; third, the heuristics routers use to decide when a flow is reported are a poor match to most applications that work with time bins; finally, it is impossible to estimate without bias the number of active flows for aggregates with non-TCP traffic.In this paper we propose Adaptive NetFlow, deployable through an update to router software, which addresses many shortcomings of NetFlow by dynamically adapting the sampling rate to achieve robustness without sacrificing accuracy. To enable counting of non-TCP flows, we propose an optional Flow Counting Extension that requires augmenting existing hardware at routers. Both our proposed solutions readily provide descriptions of the traffic of progressively smaller sizes. Transmitting these at progressively higher levels of reliability allows graceful degradation of the accuracy of traffic reports in response to network congestion on the reporting path.
机译:当寻找主要的应用程序,用户或估计流量矩阵时,网络运营商需要确定链路上流量混合的组成。思科的NetFlow已经发展成为一种解决方案,它可以通过报告流记录来总结这种遍历链接的流量示例,从而满足这一需求。但是采样的NetFlow的缺点会阻碍流量数据的收集和分析。首先,在洪灾攻击中,路由器记录和流记录所消耗的网络带宽可能会超出可用范围,其次,选择正确的静态采样率非常困难,因为没有一个单一的率能够在所有流量混合中正确权衡内存使用与准确性。第三,启发式路由器用来确定何时报告流量与大多数使用时间仓的应用程序的匹配度不高。最后,不可能不带偏差地估计具有非TCP流量的聚合的活动流数。本文提出了可通过对路由器软件进行更新而部署的自适应NetFlow,它通过动态调整采样率来解决NetFlow的许多缺点在不牺牲精度的情况下实现鲁棒性。为了启用非TCP流计数,我们提出了可选的流计数扩展,该扩展需要扩展路由器上的现有硬件。我们提出的两种解决方案都可以轻松描述流量逐渐减小的情况。响应于报告路径上的网络拥塞,以逐渐提高的可靠性级别传输这些信息将使流量报告的准确性适度降低。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号