IP Traffic Flow Generation Using Time Bucket Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing flow generation methods for IP traffic on high-speed Internet lines are non-real-time, leading to delayed analysis and inefficiencies due to the generation of flows spanning multiple analysis periods, which complicates traffic analysis and server performance, especially when trying to include detailed packet information.
Innovation Solution
A method that generates flows using all IP packets within a predetermined time bucket, allowing for precise analysis by transferring flows to a flow analysis system only when the time bucket changes, utilizing a flow measurement system with a time bucket timeout mechanism and micro-coding on a Micro Engine for network processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If flows are generated using traditional timeout mechanisms (FIN, INACTIVE, ACTIVE), then flows can be generated continuously, but the analysis period must be longer than 1 hour due to delayed flow transfer
Solution Approach 1:
The patent segments the continuous flow generation process into discrete time buckets of fixed duration. Each time bucket independently generates and transfers flows, creating natural synchronization points that enable shorter analysis periods without requiring complex cross-bucket flow management.
Solution Approach 2:
The patent implements periodic flow generation and transfer at fixed time intervals (time buckets). This periodic action creates regular synchronization points, allowing the analysis system to process flows in manageable cycles rather than continuously, reducing the required analysis period to match the bucket duration.
2Reliability
If flows span multiple analysis periods, then continuous traffic can be tracked, but traffic analysis becomes complicated and server performance deteriorates
Solution Approach 1:
The patent segments flows into time-bucket-specific units, ensuring each flow is contained within a single analysis period. This segmentation prevents flows from spanning multiple periods, simplifying the analysis process and improving server performance while maintaining complete traffic analysis capability within each bucket.
Solution Approach 2:
The patent creates complete flow copies at the end of each time bucket and transfers them to the analysis system. This copying approach ensures all necessary flow information is captured and transferred together, enabling complete traffic analysis within the bucket period without requiring continuous tracking across periods.
3Loss of information
If detailed packet information is included in flows, then comprehensive traffic analysis is enabled, but the amount of information becomes too much for high-speed lines
Solution Approach 1:
The patent extracts only the essential flow-level information needed for analysis (aggregated statistics, timing data, and key flow identifiers) while leaving detailed packet-level data on the high-speed line. This extraction approach provides sufficient information for traffic analysis without overwhelming the line capacity.
Solution Approach 2:
The patent transfers complete flow information within each time bucket (excessive action for the bucket duration) rather than attempting to transfer all historical flow data continuously. This partial action approach ensures comprehensive analysis capability for each period while maintaining manageable transfer volumes.
Data Source
AI summary
A method of generating IP traffic flow based on a time bucket divides, in order to generate flows using all IP packets arriving in a preset time bucket, a previous time bucket flow table (PTBFT) and a current time bucket flow table (CTBFT) with reference to a current time when the flows are generated using IP packets collected from a high-speed line in a flow generating unit. Accordingly, the method allows real-time analysis of flows.


