Prefix-Based Fat Flows for Cloud Data Center Flow Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems in cloud data centers face challenges in efficiently managing large numbers of flows due to resource limitations, particularly under conditions like DDOS attacks, where microflows do not scale effectively and lead to performance bottlenecks.
Innovation Solution
The formation of prefix-based fat flows, where multiple microflows are aggregated using criteria such as IP addresses and port numbers, allowing for the configuration of fat flows that ignore specific IP or port details, enabling efficient load balancing and reducing the entropy that disrupts flow management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If microflows are used to manage individual flows, then flow management precision is improved, but system scalability deteriorates under DDOS attack conditions
Solution Approach 1:
The patent merges multiple microflows into macroflows by aggregating flows that share common characteristics (such as destination IP address, source IP address, or port numbers). This consolidation reduces the number of individual flow entries the system must manage, thereby improving scalability during DDOS attacks while maintaining the ability to distinguish between different traffic patterns through the aggregated flow representation.
Solution Approach 2:
The patent changes the parameters used for flow identification from granular microflow parameters (individual source-destination-port tuples) to coarser macroflow parameters (aggregated IP prefixes and port ranges). This parameter transformation enables the system to handle large volumes of flows efficiently while preserving sufficient differentiation to manage traffic strategically during attack conditions.
2Measurement precision
If multiple microflows are managed individually, then flow differentiation accuracy is improved, but resource consumption increases
Solution Approach 1:
The patent combines multiple individual flow entries into aggregated macroflow entries, reducing the total number of flow table entries required. This merging operation directly decreases memory consumption and processing overhead while maintaining flow differentiation accuracy through the use of meaningful aggregation keys (IP addresses, ports) that preserve traffic identification capabilities.
Solution Approach 2:
The patent creates a universal flow management mechanism that can handle both normal traffic and attack traffic through a unified macroflow aggregation approach. This multi-functional system simultaneously provides flow differentiation for legitimate traffic and resource efficiency for attack mitigation, eliminating the need for separate handling mechanisms.
3Quantity of substance
If fat flows are formed by aggregating multiple flows, then resource constraints are reduced, but flow management complexity increases
Solution Approach 1:
The patent simplifies flow management complexity by transforming the management interface from individual microflow parameters to aggregated macroflow parameters. This parameter abstraction reduces the cognitive and computational complexity of managing flows during attacks, as administrators and systems work with higher-level aggregates rather than granular details, while still maintaining sufficient precision for effective traffic management.
Data Source
AI summary
A network device includes one or more processors configured to use a fat flow rule that specifies at least one of a mask to be applied to source Internet protocol (IP) addresses or to destination IP addresses, or that source ports or destination ports are to be ignored. The one or more processors may further be configured to receive packets having different source or destination IP addresses and/or different source or destination ports, and nevertheless assign the packets to the same fat flow according to the fat flow rule, e.g., by masking the source or destination IP addresses and/or ignoring the source or destination ports of the packets. In this manner, the network device may aggregate two or more different flows into a single fat flow.


