Port Mirroring for High-Speed Network Flow Sampling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network monitoring techniques, such as counter-based and sampling-based methods, face limitations in granularity, latency, and sample volume when analyzing network flows, particularly in high-speed switched networks, due to constraints on port mirroring and sampling rates.
Innovation Solution
Implementing port mirroring in network forwarding devices to dynamically sample data packets at saturation limits, allowing for high-volume, low-latency data traffic analysis by mirroring data packets to designated ports without involving the control plane processor, thereby overcoming traditional sampling rate limitations and achieving true random sampling.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If traditional sampling methods (sFlow) are used to monitor high-speed switched networks, then the control plane processor can process samples, but the sampling rate is limited to approximately 300 samples per second due to CPU processing constraints
Solution Approach 1:
The patent extracts the sampling function from the control plane processor and implements it at the data plane through hardware-based port mirroring. This allows sampling to occur independently of CPU processing constraints, achieving rates exceeding 300 samples per second by utilizing the switch's hardware forwarding capabilities rather than relying on software processing.
Solution Approach 2:
The patent introduces port mirroring as an intermediary mechanism between the network traffic and the sampling collector. Instead of the control plane processor directly processing samples, the port mirroring hardware creates copies of packets and directs them to the collector, enabling high-speed sampling without CPU involvement in the sampling decision-making process.
2Quantity of substance
If port mirroring is used to copy data packets to designated ports, then high-volume sampling can be achieved, but the control plane processor must be involved in configuring the mirroring
Solution Approach 1:
The patent implements preliminary configuration of port mirroring rules during the setup phase, where the control plane processor programs the switch hardware with mirroring instructions. Once configured, the hardware autonomously performs the sampling without requiring continuous control plane involvement, allowing high-volume sampling while minimizing ongoing configuration complexity.
3Measurement precision
If sampling is performed at line rate on high-speed switches, then comprehensive network flow information can be obtained, but the sampling rate must be set very low (e.g., 1 in 400,000 packets) to maintain manageable sample volumes
Solution Approach 1:
The patent enables dynamic adjustment of sampling rates based on real-time network conditions and requirements. By configuring the port mirroring to sample at saturation limits rather than fixed low rates, the system can adaptively control sample volume while maintaining comprehensive flow information, allowing the sampling rate to be optimized for each specific monitoring scenario rather than using a conservative fixed rate.
Data Source
AI summary
Mechanisms are provided for analyzing data traffic through a network. The mechanisms sample data packets of a data flow through a normal port of a network forwarding device of the network. The sampling is performed at least by configuring the network forwarding device to implement port mirroring of the normal port to a designated mirror port of the network forwarding device. The mechanisms forward sampled data packets, copied to the mirror port by virtue of the port mirroring, to a collector computing device. The mechanisms process, by the collector computing device, the sampled data packets to analyze the data flow through the normal port of the network forwarding device. The mechanisms perform, by the collector computing device, an operation based on results of the analysis.


