arrow
Return

Efficient Lightweight Coordinated Sampling for Dynamic Flows: Theory and Implementation

delete2026-01-01
delete0
PRE
AI
M
M.J. Chen
T
Thomas La Porta
T
Trent Jaeger
S
Srikanth V. Krishnamurthy
DOI:10.1109/TON.2025.3644238delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
As cyber-attacks on networks become stealthier, monitoring techniques relying on low-rate packet sampling may prove insufficient to detect attacks. While various methods, such as truncating packets, flow-based sampling, and adaptive sampling rates, have been proposed to enhance detection rates and ease capability limitations, it remains challenging to perform sufficient sampling at line speed and high rates at a single sampling point due to limited CPU or bandwidth capacity and fluctuating network traffic. To address these challenges, we propose <sc xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">CoordSamp</small>, a system that distributes the sampling workload across multiple sampling points and coordinates their actions to avoid duplicate sampling of the same packet. This design enables scalable, resource-aware monitoring—particularly suited for dynamic, agentless cloud-based environments—relying solely on network-level deployment that can be dynamically assigned and adjusted by the provider. We develop a coordinated sampling algorithm on multiple P4-programmable switches and show that the algorithm ensures coordination among multiple sampling points for each flow, preventing duplicate samples, with negligible network overhead and real-time configurability. At its core, <sc xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">CoordSamp</small> separates <italic xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">offline placement</i>—the budgeted selection of sampling points—from <italic xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">online allocation</i>—the capacity-aware assignment of sampling tasks—allowing practical deployment in hybrid networks that combine programmable and legacy switches. We formulate sampling point placement as budgeted maximum multi-coverage problems, solving them optimally in pseudo-polynomial time. Our system far outperforms those based on greedy placement along many key dimensions.
Keywords:
P4-programmable switch
coordinated sampling
budgeted maximum multi-coverage
balanced matrix

Journal

I
IEEE Transactions on Networking
IF:
0
Papers:
543
Citations:
0

Organization

U
university of california riverside
Scholars:
1.1W
Papers: 8.3K
Citations: 16
P
pennsylvania state university
Scholars:
3.1K
Papers: 1.8K
Citations: 0
K
kansas state university
Scholars:
1.1K
Papers: 440
Citations: 0
researcher View more organizations