SketchFlow: Per-Flow Systematic Sampling Using Sketch Saturation Event
Rhongho Jang, DaeHong Min, Seongkwang Moon, David Mohaisen, DaeHun Nyang
Abstract
Sampling is a powerful tool to reduce the processing overhead in various systems. NetFlow uses a local table for counting records per flow, and sFlow sends out the collected packet headers periodically to a collecting server over the network. Any measurement system falls into either one of these two models. To reduce the overhead, as in sFlow, simple random sampling (SRS) has been widely used in practice because of its simplicity. However, SRS provides non-uniform sampling rates for different fine-grained flows (defined by 5-tuple), because it samples packets over an aggregated data flow (defined by switch port or VLAN). Consequently, some flows are sampled more than the designated sampling rate (resulting in over-estimation), and others are sampled fewer (resulting in under-estimation). Starting with a simple idea that "independent per-flow packet sampling provides the most accurate estimation of each flow", we introduce a new concept of per-flow systematic sampling, aiming to provide the same sampling rate across all flows. In addition, we provide a concrete sampling method called SketchFlow, which approximates the idea of the per-flow systematic sampling using a sketch saturation event. We demonstrate SketchFlow's performance in terms of accuracy, sampling rate, and overhead using real-world datasets, including a backbone network trace, I/O trace, and Twitter dataset. Experimental results show that SketchFlow outperforms SRS (i.e., sFlow) and the non-linear sampling method while requiring a small CPU overhead to measure high-speed traffic in real-time.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 461ac7e5-6258-4bf7-89ec-90f4ea7189f1Cited by top-tier papers5
- Self-Adaptive Sampling for Network Traffic MeasurementYang Du, He Huang, Yu-e Sun, Shigang Chen et al.INFOCOM 2021 · 49 citations
- A Scalable and Dynamic ACL System for In-Network DefenseChanghun Jung, Sian Kim, Rhongho Jang, David Mohaisen et al.CCS 2022 · 17 citations
- FlowShark: Sampling for High Flow Visibility in SDNsSogand SadrHaghighi, Mahdi Dolati, Majid Ghaderi, Ahmad KhonsariINFOCOM 2022 · 9 citations
- A Robust Counting Sketch for Data Plane Intrusion DetectionSian Kim, Changhun Jung, RhongHo Jang, David Mohaisen et al.NDSS 2023
- Defeating Slow-and-Low Threats via Diffusion Model-based Generative InferenceSeyed Mohammad Mehdi Mirnajafizadeh, Prashant Khanduri, DaeHun Nyang, Rhongho JangNSDI 2026
Related papers
- Universal Online Sketch for Tracking Heavy Hitters and Estimating Moments of Data StreamsQingjun Xiao, Zhiying Tang, Shigang ChenINFOCOM 2020 · 30 citations
- Online Spread Estimation with Non-duplicate SamplingYu-e Sun, He Huang, Chaoyi Ma, Shigang Chen et al.INFOCOM 2020 · 40 citations
- Single Update Sketch with Variable Counter StructureDimitrios Melissourgos, Haibo Wang, Shigang Chen, Chaoyi Ma et al.VLDB 2023 · 16 citations
- Towards Guaranteed Accuracy for Flow Spread Measurement with -Nonduplicate SamplingHaibo Wang, Chaoyi Ma, Dimitrios Melissourgos, Guoju Gao et al.INFOCOM 2025
- BurstDetector: Real-Time and Accurate Across-Period Burst Detection in High-Speed NetworksZhongyi Cheng, Guoju Gao, He Huang, Yu-e Sun et al.INFOCOM 2024 · 8 citations
