Logical Network Traffic Analysis via Flow Sampling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network virtualization systems face challenges in efficiently monitoring and analyzing logical network traffic due to the distributed nature of logical network entities across multiple transport nodes, which complicates centralized monitoring and data collection.
Innovation Solution
Implementing a method for logical network traffic analysis by defining a logical network probe and associating it with observation points, distributing sample-action flow entries to managed forwarding elements, which sample packets based on matching criteria and user-definable sampling percentages, and forwarding the sampled data to data collectors for analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network virtualization is implemented to decouple logical networks from physical hardware, then flexibility and management efficiency are improved, but monitoring and analysis of logical network traffic becomes more complex
Solution Approach 1:
The patent introduces flow collectors as intermediary components that aggregate flow statistics from multiple managed forwarding elements. These collectors receive, consolidate, and analyze flow data centrally, serving as a mediator between the distributed logical network entities and the monitoring system, thereby simplifying the complexity of monitoring virtualized networks.
Solution Approach 2:
The system implements feedback mechanisms where flow statistics are continuously collected from managed forwarding elements, aggregated by flow collectors, and used to provide insights about logical network traffic patterns. This feedback loop enables centralized monitoring and analysis of distributed network entities without increasing operational complexity.
2Loss of information
If flow statistics are collected from all logical network entities, then monitoring visibility is improved, but system performance and resource usage deteriorate
Solution Approach 1:
The patent extracts only the necessary flow statistics data from logical network entities rather than collecting all possible data. Flow collectors selectively gather relevant flow statistics information needed for monitoring and analysis, reducing the data volume and processing requirements while maintaining adequate monitoring visibility.
Solution Approach 2:
The system implements partial action by collecting flow statistics at strategic points (managed forwarding elements) rather than from every single logical network entity. This selective collection approach provides sufficient monitoring coverage while minimizing the performance overhead and resource consumption associated with comprehensive data gathering.
3Ease of operation
If centralized control is implemented for logical network management, then management efficiency is improved, but the complexity of data aggregation and processing increases
Solution Approach 1:
The patent segments the monitoring architecture into distinct functional components: managed forwarding elements that generate flow statistics, flow collectors that aggregate data, and analysis systems that process information. This segmentation distributes the data aggregation workload across multiple specialized components rather than concentrating all processing in a single centralized point, reducing the complexity burden on any single element.
Solution Approach 2:
Flow collectors serve as intermediary components that handle the complex task of data aggregation between managed forwarding elements and the central management system. These intermediaries perform the heavy lifting of consolidating flow statistics from multiple sources, simplifying the overall data aggregation process and making centralized management more efficient.
Data Source
AI summary
Some embodiments of the invention provide a method for gathering data for logical network traffic analysis by sampling flows of packets forwarded through a logical network. Some embodiments are implemented by a set of network virtualization controllers that, on a shared physical infrastructure, can implement two or more sets of logical forwarding elements that define two or more logical networks. In some embodiments, the method (1) defines an identifier for a logical network probe, (2) associates this identifier with one or more logical observation points in the logical network, and (3) distributes logical probe configuration data, including sample-action flow entry data, to one or more managed forwarding elements that implement the logical processing pipeline at the logical observation points associated with the logical network probe identifier. In some embodiments, the sample-action flow entry data specify the packet flows that the forwarding elements should sample and the percentage of packets within these flows that the forwarding elements should sample.


