arrow
Return

PISketch: Finding Persistent and Infrequent Flows

delete2023-12-01
delete3
delete
OA
AI
Z
Zhuochen Fan
Z
Zhoujing Hu
Y
Yuhan Wu
J
Jiarui Guo
S
Sha Wang
W
Wenrui Liu
T
Tong Yang *
Y
Yaofeng Tu
S
Steve Uhlig
DOI:10.1109/TNET.2023.3272287delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Finding persistent and low-active activity periods is very helpful in practice, for example to detect intrusion activities. Most of the literature focuses on finding persistent flows or frequent flows. No previous work is able to find persistent and infrequent flows. In this paper, we propose a novel sketch data structure, PISketch, to find persistent and infrequent flows in real time. The key idea of is to define a weight and its Reward and Penalty System for each flow to combine and balance the information of both persistency and infrequency, and to keep high-weighted flows in a limited space through a strategy. We implement PISketch on P4, FPGA, and CPU platforms, and compare the performance of PISketch with two strawman solutions (On-Off + CM sketch, and PIE + CM sketch), in terms of finding persistent and infrequent flows. Our experimental results demonstrate the advantage of PISketch, by comparing it to two strawman solutions: 1) The F1 Score of is around 22.1% and 57.6% higher than two strawman solutions, respectively; 2) The Average Relative Error (ARE) of is around 820.9 (up to 1188.8) and 126.2 (up to 265.6) times lower than two strawman solutions, respectively; 3) The insertion throughput of is around 1.23 and 16.5 times higher than two strawman solutions, respectively. Moreover, we implement two concrete cases of PISketch through end-to-end experiments. All of our codes are available at GitHub.
Keywords:
Random access memory
Field programmable gate arrays
Frequency estimation
Filtering algorithms
Fans
Data structures
Codes
Data streams
persistent flows
infrequent flows
advanced persistent threats
sketch
weight
P4
FPGA

Journal

I
IEEE-ACM Transactions on Networking
IF:
3.6
Papers:
4.4K
Citations:
9.5K

Organization

Q
Queen Mary University London
Scholars:
2.0W
Papers: 1.5W
Citations: 327
U
university of london
Scholars:
21.5W
Papers: 19.7W
Citations: 305
P
peking university
Scholars:
11.7W
Papers: 8.7W
Citations: 146
N
national university of defense technology - china
Scholars:
1.8W
Papers: 1.4W
Citations: 9
researcher View more organizations