Network Flow Classification Using Volume and Duration Metrics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network traffic classification methods are inefficient and resource-intensive, particularly in scaling to large data networks, as they rely on complete traffic flow records and are insufficient for distinguishing elephant and mice flows based solely on data volume, leading to increased computational complexity and storage requirements.
Innovation Solution
The method classifies flows into two classes by calculating a flow metric from both data volume and duration, using packet-level and flow-level sampling, and applying representative unbiased estimators to derive analytics, enabling fast and scalable classification of elephant and mice flows, which reduces data storage and computational complexity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If complete traffic flow records are used for classification, then measurement precision is improved, but device complexity and storage requirements increase
Solution Approach 1:
The patent extracts only the essential flow metrics (data volume and duration) from complete traffic flow records, eliminating the need to store and process entire flow records. By taking out only the necessary components for classification, the system achieves accurate flow distinction while dramatically reducing storage and processing complexity.
Solution Approach 2:
The patent segments the flow classification task into two independent components: data volume measurement and duration measurement. Each component can be processed separately using sampling techniques, allowing the system to achieve classification accuracy without handling complete flow records as a single complex unit.
2Productivity
If real time monitoring is implemented, then productivity is improved, but device complexity and computational cost increase
Solution Approach 1:
The patent applies partial action by using sampling techniques to monitor only a representative subset of traffic flows rather than all flows in real time. This allows the system to achieve real-time monitoring capability for classification purposes while reducing computational cost and complexity by focusing on partial data representation.
Solution Approach 2:
The patent creates copies of flow characteristics through sampling, where sampled flow records represent the broader traffic pattern. By working with these representative copies rather than complete flow records, the system achieves real-time analysis capability with reduced computational complexity.
3Ease of operation
If data volume alone is used for flow classification, then ease of operation is improved, but measurement precision deteriorates
Solution Approach 1:
The patent merges two classification dimensions: data volume and duration. By combining these two metrics into a unified flow metric calculation, the system achieves more precise flow distinction (identifying elephant vs. mice flows) while maintaining operational simplicity through a straightforward classification algorithm that processes both parameters together.
Data Source
AI summary
A processing system may obtain a first sampled flow record for a first flow in a network, comprising information regarding selected packets of the first flow, derive, from the first sampled flow record, a data volume and a duration of the first flow, and determine a first flow metric for the first flow that is calculated from the data volume and the duration, where the first flow metric is one of a plurality of flow metrics for a plurality of flows, and where the plurality of flow metrics is determined from the plurality of sampled flow records associated with the plurality of flows. The processing system may then classify the first flow into one of at least two classes, based upon the first flow metric and at least a first flow metric threshold.


