基于可编程数据平面交换机的使用数据包计数和数据包大小特征的重流量(Heavy Hitter)流检测
Programmable Data Plane Switch based Heavy Hitter Flow Detection using Packet-Count and Packet-Size features
浏览论文内容
中文总结 AI 辅助
本文针对可编程数据平面交换机中重流量检测因哈希冲突导致的漏检问题,提出结合中期数据包计数与大小特征的方法,在P4和Tofino上实现,利用真实流量验证可显著降低假阴性。
中文摘要 AI 辅助
在承载大量流的数据网络中,重流量(Heavy Hitters,HHs)或大象流(Elephant flows)是指在给定时间窗口内超过预定阈值(例如数据包数量或字节数)的流。此类HH流需要被区别处理,以最小化其对其他较小流的影响。研究表明,在可编程数据平面交换机中实现HH检测技术更为有效。近期工作显示,数据包间间隔可用于识别重流量。此类方案使用有限大小的哈希表存储流状态信息并用于检测。然而,当发生哈希冲突时,表中有效的HH流可能被非HH流替换,导致HH流检测遗漏。为解决此问题,本文引入了流的中期数据包计数(Packet Count,PC)特征。为限制哈希表中数据包计数字段的大小,计数仅在哈希冲突发生前进行,以减少需存储的数值范围及所需位数。此外,另一流的的中期特征——数据包大小(Packet Size,PS)也被独立纳入。所提方案已用P4语言实现,并在Intel Tofino硬件上测试。性能评估使用基于CAIDA和MAWI的真实流量轨迹进行。结果表明,在多种场景下,通过有效且高效地利用数据包计数数据,我们可以显著减少HH的假阴性(False Negatives)。
英文摘要
In data networks carrying large numbers of flows, Heavy Hitters (HHs) or Elephant flows are the flows exceeding pre-determined thresholds (e.g. number of packets or bytes) in a given time window. Such HH flows need to be handled differently in order to minimize their impact on other smaller flows. HH detection techniques have been shown to be more effective when implemented in programmable data plane switches. In recent work, it was shown that the inter-packet gap can be used to identify heavy hitters. Such schemes use a limited-size hash table for storing flow state information and using this for the detection. However, when hash collisions occur, it is possible that a valid HH flow in the table can be replaced by a non-HH flow resulting in missing detection of HH flows. To address this problem, this paper incorporates a flow's medium-term Packet Count (PC) feature. In order to limit the packet count field size in the hash table, counting is done only till hash collision occurs so as to reduce the range of values to be stored and thus, the required number of bits. Also, another flow's medium-term feature, Packet Size (PS) is incorporated independently. The proposed scheme has been implemented in the P4 language and tested on Intel Tofino hardware. Performance evaluation has been performed using CAIDA and MAWI-based real-life traffic traces. The results show that in several scenarios cases, we can significantly reduce the False Negatives for HHs by using the packet count data effectively and efficiently.
发表机构
- Indian Institute of Technology Madras(印度马德拉斯理工学院)
- Ciena Corporation(赛恩纳公司)
机构由 AI 辅助整理,请以论文原文为准。