Skip to main content
Erschienen in: Journal of Network and Systems Management 3/2017

03.02.2017

A Modular Traffic Sampling Architecture: Bringing Versatility and Efficiency to Massive Traffic Analysis

verfasst von: João Marco C. Silva, Paulo Carvalho, Solange Rito Lima

Erschienen in: Journal of Network and Systems Management | Ausgabe 3/2017

Einloggen

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

The massive traffic volumes and heterogeneity of services in today’s networks urge for flexible, yet simple measurement solutions to assist network management tasks, without impairing network performance. To turn treatable tasks requiring traffic analysis, sampling the traffic has become mandatory, triggering substantial research in the area. Despite that, there is still a lack of an encompassing solution able to support the flexible deployment of sampling techniques in production networks, adequate to diverse traffic scenarios and measurement activities. In this context, this article proposes a modular traffic sampling architecture able to foster the flexible design and deployment of efficient measurement strategies. The architecture is composed of three layers—management plane, control plane and data plane—covering key components to achieve versatile and lightweight measurements in diverse traffic scenarios and measurement activities. Each component of the architecture is described considering the different strategies, technologies and protocols that compose the several stages of a measurement process. Following the proposed architecture, a sampling framework prototype has been developed, providing a fair environment to assess and compare sampling techniques under distinct measurement scenarios, evaluating their performance in balancing computational burden and accuracy. The results have demonstrated the relevance and applicability of the proposed architecture, revealing that a modular and configurable approach to sampling is a step forward for improving sampling scope and efficiency.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Fußnoten
1
The framework is available for download at http://​1drv.​ms/​1IggkCa as a Raspbian image ready to be deployed.
 
2
Note that the evaluation of flow classification methodologies and tools is beyond the scope of this work, which resorts to a port-based classification technique for distinguishing flows.
 
Literatur
2.
Zurück zum Zitat Silva, J.M.C., Carvalho, P., Rito Lima, S.: Analysing traffic flows through sampling: a comparative study. In: 20th IEEE Symposium on Computers and Communication (ISCC), Cyprus (2015) Silva, J.M.C., Carvalho, P., Rito Lima, S.: Analysing traffic flows through sampling: a comparative study. In: 20th IEEE Symposium on Computers and Communication (ISCC), Cyprus (2015)
3.
Zurück zum Zitat Jadwab, J., Phall, P., Pinna, B.: Traffic estimation for the largest sources on a network using packet sampling with limited storage. Technical report, Hewllet-Packard Laboratories, Bristol (1992) Jadwab, J., Phall, P., Pinna, B.: Traffic estimation for the largest sources on a network using packet sampling with limited storage. Technical report, Hewllet-Packard Laboratories, Bristol (1992)
4.
Zurück zum Zitat Claffy, K.C., Polyzos, G.C., Braun, H.W.: Application of sampling methodologies to network traffic characterization, SIGCOMM. Comput. Commun. Rev. 23(4), 194–203 (1993). doi:10.1145/167954.166256 CrossRef Claffy, K.C., Polyzos, G.C., Braun, H.W.: Application of sampling methodologies to network traffic characterization, SIGCOMM. Comput. Commun. Rev. 23(4), 194–203 (1993). doi:10.​1145/​167954.​166256 CrossRef
7.
Zurück zum Zitat Tammaro, D., Valenti, S., Rossi, D., Pescapé, A.: Exploiting packet-sampling measurements for traffic characterization and classification. Int. J. Netw. Manag. 22(6), 451–476 (2012). doi:10.1002/nem.1802 CrossRef Tammaro, D., Valenti, S., Rossi, D., Pescapé, A.: Exploiting packet-sampling measurements for traffic characterization and classification. Int. J. Netw. Manag. 22(6), 451–476 (2012). doi:10.​1002/​nem.​1802 CrossRef
13.
Zurück zum Zitat Singh, R., Kumar, H., Singla, R.K.: Analyzing statistical effect of sampling on network traffic dataset. In: Satapathy, S.C., Avadhani, P.S., Udgata, S.K., Lakshminarayana, S. (eds.). ICT and Critical Infrastructure: Proceedings of the 48th Annual Convention of Computer Society of India. Springer International Publishing, pp. 401–408. http://link.springer.com/chapter/10.1007/978-3-319-03107-1_43 (2014) Singh, R., Kumar, H., Singla, R.K.: Analyzing statistical effect of sampling on network traffic dataset. In: Satapathy, S.C., Avadhani, P.S., Udgata, S.K., Lakshminarayana, S. (eds.). ICT and Critical Infrastructure: Proceedings of the 48th Annual Convention of Computer Society of India. Springer International Publishing, pp. 401–408. http://​link.​springer.​com/​chapter/​10.​1007/​978-3-319-03107-1_​43 (2014)
17.
Zurück zum Zitat Kandula, S., Mahajan, R.: Sampling biases in network path measurements and what to do about it. In: Proceedings of the 9th ACM SIGCOMM Conference on Internet Measurement Conference IMC ’09 (ACM, New York, NY, USA) , pp. 156–169. doi:10.1145/1644893.1644912 (2009) Kandula, S., Mahajan, R.: Sampling biases in network path measurements and what to do about it. In: Proceedings of the 9th ACM SIGCOMM Conference on Internet Measurement Conference IMC ’09 (ACM, New York, NY, USA) , pp. 156–169. doi:10.​1145/​1644893.​1644912 (2009)
20.
Zurück zum Zitat Zhang, J., Luo, X., Perdisci, R., Gu, G., Lee, W., Feamster, N.: Boosting the scalability of botnet detection using adaptive traffic sampling. In: Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security, Ser. (ACM, New York, NY, USA), ASIACCS ’11, pp. 124–134. doi:10.1145/1966913.1966930 (2011) Zhang, J., Luo, X., Perdisci, R., Gu, G., Lee, W., Feamster, N.: Boosting the scalability of botnet detection using adaptive traffic sampling. In: Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security, Ser. (ACM, New York, NY, USA), ASIACCS ’11, pp. 124–134. doi:10.​1145/​1966913.​1966930 (2011)
22.
Zurück zum Zitat Brauckhoff, D., Tellenbach, B., Wagner, A., May, M., Lakhina, A.: Impact of packet sampling on anomaly detection metrics. In: Proceedings of the 6th ACM SIGCOMM Conference on Internet Measurement, Ser. (ACM, New York, NY, USA) IMC ’06, pp. 159–164. doi:10.1145/1177080.1177101 (2006) Brauckhoff, D., Tellenbach, B., Wagner, A., May, M., Lakhina, A.: Impact of packet sampling on anomaly detection metrics. In: Proceedings of the 6th ACM SIGCOMM Conference on Internet Measurement, Ser. (ACM, New York, NY, USA) IMC ’06, pp. 159–164. doi:10.​1145/​1177080.​1177101 (2006)
25.
Zurück zum Zitat Jae-Hyun, J., Cheol-Woong, A., Dongjoon, L., Sung-Ho, K.: DDoS attack detection using flow entropy and packet sampling on huge networks. In: ICN 2014 : The Thirteenth International Conference on Networks (IARIA), pp. 183–190 (2014) Jae-Hyun, J., Cheol-Woong, A., Dongjoon, L., Sung-Ho, K.: DDoS attack detection using flow entropy and packet sampling on huge networks. In: ICN 2014 : The Thirteenth International Conference on Networks (IARIA), pp. 183–190 (2014)
26.
Zurück zum Zitat Zseby, T.: Deployment of sampling methods for SLA validation with non-intrusive measurements. In: Proceedings of Passive and Active Measurements Conference (Fort Collins) (2002) Zseby, T.: Deployment of sampling methods for SLA validation with non-intrusive measurements. In: Proceedings of Passive and Active Measurements Conference (Fort Collins) (2002)
27.
Zurück zum Zitat Zseby, T.: Comparison of sampling methods for non-intrusive SLA validation. In: Proceedings of the Second Workshop on End-to-End Monitoring Techniques and Services (E2EMon) (2004) Zseby, T.: Comparison of sampling methods for non-intrusive SLA validation. In: Proceedings of the Second Workshop on End-to-End Monitoring Techniques and Services (E2EMon) (2004)
29.
Zurück zum Zitat Sommers, J., Barford, P., Duffield, N., Ron, A.: Improving accuracy in end-to-end packet loss measurement. In: Proceedings of the 2005 conference on Applications, Technologies, Architectures, and Protocols for Computer Communications—SIGCOMM ’05, (ACM Press, New York, New York, USA), vol. 35, p. 157 (2005). http://dl.acm.org/citation.cfm?id=1080091.1080111 Sommers, J., Barford, P., Duffield, N., Ron, A.: Improving accuracy in end-to-end packet loss measurement. In: Proceedings of the 2005 conference on Applications, Technologies, Architectures, and Protocols for Computer Communications—SIGCOMM ’05, (ACM Press, New York, New York, USA), vol. 35, p. 157 (2005). http://​dl.​acm.​org/​citation.​cfm?​id=​1080091.​1080111
30.
Zurück zum Zitat Dogman, A., Saatchi, R., Al-Khayatt, S.: An adaptive statistical sampling technique for computer network traffic. In: 7th International Symposium on Communication Systems Networks and Digital Signal Processing (CSNDSP, 2010), pp. 479–483 (2010) Dogman, A., Saatchi, R., Al-Khayatt, S.: An adaptive statistical sampling technique for computer network traffic. In: 7th International Symposium on Communication Systems Networks and Digital Signal Processing (CSNDSP, 2010), pp. 479–483 (2010)
34.
Zurück zum Zitat Zseby, T., Hirsch, T., Claise, B.: Packet sampling for flow accounting: challenges and limitations. In: Claypool, M., Uhlig, S. (eds.) Passive and Active Network Measurement, Ser. Lecture Notes in Computer Science, vol. 4979, (Springer Berlin / Heidelberg), pp. 61–71 (2008). doi:10.1007/978-3-540-79232-1_7 Zseby, T., Hirsch, T., Claise, B.: Packet sampling for flow accounting: challenges and limitations. In: Claypool, M., Uhlig, S. (eds.) Passive and Active Network Measurement, Ser. Lecture Notes in Computer Science, vol. 4979, (Springer Berlin / Heidelberg), pp. 61–71 (2008). doi:10.​1007/​978-3-540-79232-1_​7
38.
48.
Zurück zum Zitat Uslar, M., Specht, M., Rohjans, S., Trefke, J., González, J.M.: The Common Information Model CIM: IEC 61968/61970 and 62325—A Practical Introduction to the CIM, vol. 66. Springer, New York (2012) Uslar, M., Specht, M., Rohjans, S., Trefke, J., González, J.M.: The Common Information Model CIM: IEC 61968/61970 and 62325—A Practical Introduction to the CIM, vol. 66. Springer, New York (2012)
52.
Zurück zum Zitat Orebaugh, A., Ramirez, G., Beale, J.: Wireshark and Ethereal Network Protocol Analyzer Toolkit. Syngress, Rockland (2006) Orebaugh, A., Ramirez, G., Beale, J.: Wireshark and Ethereal Network Protocol Analyzer Toolkit. Syngress, Rockland (2006)
53.
Zurück zum Zitat Jacobson, V., McCanne, S.: Lawrence Berkeley Laboratory, Berkeley, CA (2009) Jacobson, V., McCanne, S.: Lawrence Berkeley Laboratory, Berkeley, CA (2009)
58.
59.
Zurück zum Zitat Silverman, B.W.: Density Estimation for Statistics and Data Analysis, vol. 26. CRC Press, Boca Raton (1986)CrossRefMATH Silverman, B.W.: Density Estimation for Statistics and Data Analysis, vol. 26. CRC Press, Boca Raton (1986)CrossRefMATH
Metadaten
Titel
A Modular Traffic Sampling Architecture: Bringing Versatility and Efficiency to Massive Traffic Analysis
verfasst von
João Marco C. Silva
Paulo Carvalho
Solange Rito Lima
Publikationsdatum
03.02.2017
Verlag
Springer US
Erschienen in
Journal of Network and Systems Management / Ausgabe 3/2017
Print ISSN: 1064-7570
Elektronische ISSN: 1573-7705
DOI
https://doi.org/10.1007/s10922-017-9404-5

Weitere Artikel der Ausgabe 3/2017

Journal of Network and Systems Management 3/2017 Zur Ausgabe