Flow Record Size Reduction via Template Switching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current flow information export protocols result in large flow records and numerous export packets, leading to network congestion, processor, memory, and resource inefficiencies, with collector servers often dropping or failing to receive these packets.
Innovation Solution
Implement a method where an exporter device generates and exports flow records using two different templates: an initial template with full fields and a subsequent template with fewer fields, reducing repetitive information, thereby conserving resources and minimizing packet size.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If flow records are exported using a template with full fields, then complete flow information is captured, but the size of flow records and export packets increases leading to network congestion and resource inefficiencies
Solution Approach 1:
The flow record export process is segmented into two phases: an initial export using a first template with complete fields, and subsequent exports using a second template with reduced fields. This segmentation allows the system to capture full flow information initially while minimizing repetitive data transmission in later records, thereby reducing overall packet size and network congestion without losing essential flow information.
Solution Approach 2:
The patent changes the parameters of the flow record template by switching between two different templates. The first template includes a first quantity of fields for complete flow information, while the second template includes a second quantity of fields that is less than the first, excluding certain repetitive fields. This parameter change optimizes the balance between information completeness and packet size reduction.
2Measurement precision
If flow records are exported frequently to maintain accurate flow information, then flow data accuracy is improved, but processor and network resources are consumed more heavily
Solution Approach 1:
The patent applies dynamics by making the flow record template adaptive rather than static. The system dynamically selects between the first template (with more fields) and the second template (with fewer fields) based on whether it is an initial or subsequent export. This dynamic approach maintains flow data accuracy when needed while reducing resource consumption during routine updates, as subsequent exports with the second template require less processing and network bandwidth.
3Reliability
If all fields are included in every flow record, then comprehensive flow monitoring is achieved, but collector servers drop or fail to receive packets due to overload
Solution Approach 1:
The patent applies partial action by including only the necessary fields in subsequent flow records. The second template includes a reduced quantity of fields that excludes certain repetitive information, providing just enough data for continued flow monitoring without overwhelming the collector server. This partial inclusion strategy maintains reliable flow monitoring while improving packet reception efficiency by reducing the burden on collector servers.
Data Source
AI summary
A device may receive a packet associated with a flow and may assign a flow identifier to the flow. The device may generate a first flow record based on a first template. The first flow record may include the flow identifier and a first quantity of fields determined based on the first template. The device may export the first flow record. The device may generate a second flow record, including the flow identifier, based on a second template and after exporting the first flow record. The second flow record may include a second quantity of fields, determined based on the second template, that is less than the first quantity of fields. The device may export the second flow record.


