One Sketch to Rule Them All
Johns Hopkins University · Carnegie Mellon University
Abstract
Network management requires accurate estimates of metrics for traffic engineering (e.g., heavy hitters), anomaly detection (e.g., entropy of source addresses), and security (e.g., DDoS detection). Obtaining accurate estimates given router CPU and memory constraints is a challenging problem. Existing approaches fall in one of two undesirable extremes: (1) low fidelity general-purpose approaches such as sampling, or (2) high fidelity but complex algorithms customized to specific application-level metrics. Ideally, a solution should be both general (i.e., supports many applications) and provide accuracy comparable to custom algorithms. This paper presents UnivMon, a framework for flow monitoring which leverages…
Citation impact
- FWCI
- 34.26
- Percentile
- 100%
- References
- 49
Authors
5Topics & keywords
- Computer science
- Generality
- Anomaly detection
- Sketch
- Data mining
- Network monitoring
- Fidelity
- Entropy (arrow of time)