DocumentCode
1826480
Title
Fast, memory-efficient traffic estimation by coincidence counting
Author
Hao, Fang ; Kodialam, Murali ; Lakshman, T.V. ; Zhang, Hui
Author_Institution
Bell Labs., Lucent Technol., Holmdel, NJ, USA
Volume
3
fYear
2005
fDate
13-17 March 2005
Firstpage
2080
Abstract
We consider the problem of fast, estimation of flow rates in backbone network links with possibly millions of flows. Accurate flow rate estimation is necessary for network traffic management, network planning, measuring compliance to service level agreements, and network security. Ideally, a rate estimation scheme should have short estimation times with provable bounds on estimation error, be low in memory usage, and be easily implementable in hardware for operation at high speeds. We develop such a scheme, and achieve up to two orders of magnitude speed-up in estimation time over the previously proposed two-runs-based RATE scheme [Kodialam, M et al., 2004]. The speedups are achieved without a significant increase in memory usage, by using coincidences instead of runs. Counting coincidences has a higher processing overhead than detecting two-runs, but this higher overhead is not significant for a hardware implementation. We show that the proposed scheme is faster and more accurate than other recently proposed schemes such as ACCEL-RATE [Hao, F et al., 2004] and smart sampling [Duffield, N et al., 2004]. The faster estimation time of the new scheme has many benefits including quicker detection of incipient denial of service attacks. We prove bounds on the scheme´s accuracy, memory needs, and also show that it performs well by simulations that use both synthetic and real traffic traces.
Keywords
IP networks; telecommunication links; telecommunication network routing; telecommunication traffic; IP networks; coincidence counting; flow rates estimation; hardware implementation; memory-efficient traffic estimation; network links; network planning; network traffic management; service attacks; smart sampling; Bones; Computer crime; Counting circuits; Event detection; IP networks; Monitoring; Sampling methods; Spine; Statistics; Telecommunication traffic;
fLanguage
English
Publisher
ieee
Conference_Titel
INFOCOM 2005. 24th Annual Joint Conference of the IEEE Computer and Communications Societies. Proceedings IEEE
ISSN
0743-166X
Print_ISBN
0-7803-8968-9
Type
conf
DOI
10.1109/INFCOM.2005.1498484
Filename
1498484
Link To Document