Seek and Push: Detecting Large Traffic Aggregates in the Dataplane

05/15/2018
by   Jan Kučera, et al.
0

High level goals such as bandwidth provisioning, accounting and network anomaly detection can be easily met if high-volume traffic clusters are detected in real time. This paper presents Elastic Trie, an alternative to approaches leveraging controller-dataplane architectures. Our solution is a novel push-based network monitoring approach that allows detection, within the dataplane, of high-volume traffic clusters. Notifications from the switch to the controller can be sent only as required, avoiding the transmission or processing of unnecessary data. Furthermore, the dataplane can iteratively refine the responsible IP prefixes allowing a controller to receive a flexible granularity information. We report and discuss an evaluation of our P4-based prototype, showing our solution to be able to detect (with 95 precision), hierarchical heavy hitters and superspreaders using less than 8KB or 80KB of active memory respectively. Finally, Elastic Trie can identify changes in the network traffic patterns, symptomatic of Denial-of-Service attack events.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
01/05/2018

A Novel Hybrid Method for Network Anomaly Detection Based on Traffic Prediction and Change Point Detection

In recent years, computer networks have become more and more advanced in...
research
03/22/2016

Implementation of a FPGA-Based Feature Detection and Networking System for Real-time Traffic Monitoring

With the growing demand of real-time traffic monitoring nowadays, softwa...
research
11/12/2019

Detecting Network Disruptions At Colocation Facilities

Colocation facilities and Internet eXchange Points (IXPs) provide neutra...
research
01/26/2018

Simulation for L3 Volumetric Attack Detection

The detection of a volumetric attack involves collecting statistics on t...
research
02/03/2023

Machine Learning-based Early Attack Detection Using Open RAN Intelligent Controller

We design and demonstrate a method for early detection of Denial-of-Serv...
research
09/28/2020

Traffic model of LTE using maximum flow algorithm with binary search technique

Inrecent time a rapid increase in the number of smart devices and user a...
research
09/01/2018

Evaluation of the performance challenges in automatic traffic report generation with huge data volumes

In this paper we analyze the performance issues involved in the generati...

Please sign up or login with your details

Forgot password? Click here to reset