Flow-level loss detection with Δ-sketches

4Citations
Citations of this article
6Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Packet drops caused by congestion are a fundamental problem in network operation. Yet, it is difficult to detect where drops are happening, let alone which flows are most affected. Detecting the small-timescale drops caused by short bursts of traffic is even more challenging, and traditional monitoring techniques can easily miss them. To uncover packet drops as they occur inside a switch, the analysis must be real-time, fine-grained, and efficient. However, modern switches have distributed packet-processing pipelines that see either the arriving or departing traffic, but not the packet drops. Additionally, they do not have enough memory to store per-flow state. Our MIDST system addresses these challenges through a distributed compact data structure with lightweight coordination between ingress and egress pipelines. MIDST identifies the flows experiencing loss, as well as the bursty flows responsible, across different burst durations. Our evaluation with real-world traces and TCP connections shows that MIDST uses little memory (e.g., 320KB) while providing high accuracy (95% to 98%) under varying loss rates and burst durations. We evaluate a low-rate DDoS attack and demonstrate the potential use of our measurement results for attack detection and mitigation.

Cite

CITATION STYLE

APA

Feibish, S. L., Liu, Z., Ivkin, N., Chen, X., Braverman, V., & Rexford, J. (2022). Flow-level loss detection with Δ-sketches. In SOSR 2022 - Proceedings of the 2022 Symposium on SDN Research (pp. 25–32). Association for Computing Machinery, Inc. https://doi.org/10.1145/3563647.3563653

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free