Network Traffic Analysis Using Sampled IP Flow Records
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network traffic analysis methods face challenges in accurately estimating traffic trends due to sampling mechanisms that fail to capture all IP flows and vary in packet and byte values, leading to incorrect analysis and increased costs when scaling with high network traffic volumes.
Innovation Solution
A method for analyzing network traffic using sampled flow records involves randomly selecting IP flow records and analyzing corresponding records to estimate network traffic trends, reducing the need for additional hardware and costs by processing only sampled data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If sampling mechanisms are used to reduce processing load, then hardware costs are reduced, but measurement precision deteriorates due to failure to capture all IP flows and variation in packet and byte values
Solution Approach 1:
The patent applies partial action by processing only a representative subset of flow records rather than all records. By selecting and processing a carefully chosen sample of flow records that represent the overall traffic patterns, the system achieves adequate measurement precision while significantly reducing processing load and hardware requirements.
Solution Approach 2:
The patent changes the parameter of sampling strategy from simple random sampling to intelligent sampling based on flow record characteristics. By analyzing and selecting flow records based on specific parameters such as traffic patterns, time periods, and flow types, the system maintains measurement precision while reducing the volume of data that needs to be processed.
2Measurement precision
If all flow records are processed to ensure accurate analysis, then measurement precision is improved, but productivity deteriorates due to increased processing time and resource requirements
Solution Approach 1:
The patent extracts and processes only the essential and representative flow records needed for accurate traffic analysis. By filtering out redundant or less significant records and focusing processing resources on key samples, the system maintains analysis accuracy while improving processing throughput and reducing resource consumption.
Solution Approach 2:
The system processes a partial set of flow records that are sufficient for accurate analysis rather than attempting to process all records. This selective processing approach maintains measurement precision while significantly improving productivity by reducing the total processing workload.
3Measurement precision
If sampling rate is increased to improve traffic estimation, then measurement precision is improved, but device complexity increases due to need for additional hardware
Solution Approach 1:
The patent changes the approach from increasing hardware capacity to optimizing sampling parameters. By adjusting sampling rates, selection criteria, and processing algorithms, the system achieves improved traffic estimation accuracy without requiring additional hardware, thereby avoiding increased device complexity.
Data Source
AI summary
Provided is a method of analyzing network traffic in a computer network. An Internet Protocol (IP) flow record of an IP flow in a computer network is selected. The selected IP flow record and additional IP flow records corresponding to the IP flow of the selected IP flow record are analyzed to obtain information related to the network traffic in the computer network.


