Traffic Flow Segmentation for Real-Time Monitoring Under SRAM Limits
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional traffic monitoring devices face challenges in monitoring all network flows in real time due to limited SRAM capacity and insufficient sampling methods, leading to gaps in traffic data during non-sampling periods.
Innovation Solution
A traffic monitoring device that identifies flows into registered and unregistered groups, calculates occurrence probabilities, and estimates unregistered flow traffic amounts by multiplying total values with these probabilities, utilizing low-speed, large-capacity memory for real-time monitoring.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If SRAM is used for high-speed memory access in real-time processing, then processing speed is improved, but memory capacity is limited
Solution Approach 1:
The invention divides flows into two segments: registered flows stored in high-speed SRAM for real-time monitoring, and unregistered flows stored in low-speed large-capacity memory for sampling-based monitoring. This segmentation allows the system to handle both speed-critical and capacity-critical requirements simultaneously.
Solution Approach 2:
Instead of attempting to monitor all flows with the same high-speed method, the invention applies partial action by using sampling-based monitoring for unregistered flows. This approach monitors a subset of traffic patterns statistically, providing sufficient monitoring capability without requiring full real-time processing capacity for all flows.
2Quantity of substance
If sampling rate is reduced to manage large number of rules in low-speed memory, then memory capacity requirement is reduced, but traffic information completeness deteriorates
Solution Approach 1:
The invention applies sampling-based monitoring specifically to unregistered flows, accepting partial information loss for this subset while maintaining complete information for registered flows. This partial action approach allows the system to manage large numbers of flow rules in low-speed memory without compromising overall monitoring effectiveness.
Solution Approach 2:
By segmenting flows into registered and unregistered categories, the invention applies different monitoring strategies to each segment. Registered flows receive complete real-time monitoring, while unregistered flows use sampling-based monitoring, thereby reducing overall information loss while managing memory capacity constraints.
3Measurement precision
If all flows are monitored in real-time using hardware implementation, then monitoring accuracy is improved, but device complexity increases
Solution Approach 1:
The invention segments the monitoring system into two pathways: a hardware-based real-time monitoring pathway for registered flows, and a software-based sampling analysis pathway for unregistered flows. This segmentation reduces device complexity by avoiding the need for hardware implementation of all monitoring functions while maintaining accuracy for critical flows.
Solution Approach 2:
The invention replaces hardware-based real-time processing with software-based sampling analysis for unregistered flows. This substitution reduces device complexity and hardware resource requirements while maintaining sufficient monitoring accuracy through statistical analysis of sampled traffic data.
Data Source
AI summary
A traffic monitoring device includes an identification unit that identifies a flow of a packet received from a monitoring target network into a flow of a first flow group and a second flow group other than the first flow group on the basis of a rule table in which a predetermined rule is registered, a traffic aggregation unit that aggregates a traffic amount of the first flow group for each flow, an occurrence probability calculation unit that calculates an occurrence probability of each flow on the basis of a result of sampling at least some of the flow of the packet received, and a traffic estimation unit that estimates a traffic amount of each flow of the second flow group by multiplying the occurrence probability of each flow by the total value of the traffic amount of the second flow group.


