skip to main content
article

Observations on Cisco sampled NetFlow

Published: 01 December 2005 Publication History

Abstract

Traffic monitoring is an important first step for network management and traffic engineering. With high-speed Internet backbone links, efficient and effective packet sampling is not only desirable, but also increasingly becoming a necessity. The Sampled NetFlow [10] is Cisco router's traffic measurement functionality with static packet sampling for high speed links. Since the utility of sampling depends on the accuracy and economy of measurement, it is important to understand sampling error and measurement overhead. In this paper, we first discuss fundamental limitations of sampling techniques used in the Sampled NetFlow. We assess the accuracy of the Sampled NetFlow by comparing its output with complete packet traces [8] from an operational router. We also show the overheads involved in the Sampled NetFlow. We find that Sampled NetFlow performs correctly without incurring dramatic overhead during our experiments. However, a care should be taken in its use, since the overhead is linearly proportional to the number of flow records.

References

[1]
Cisco Express Forwarding. http://www.cisco.com.
[2]
D. Berry and B. Lindgren. Statistics theory and Methods. Duxbury Press, ITP, 2nd edition, 1996.
[3]
David Bolen and licensed to CAIDA (The Cooperative Association for Internet Data Analysis). ARTS. http://www.caida.org/tools/utilities/arts.
[4]
B.-Y. Choi, J. Park, and Z.-L. Zhang. Adaptive Packet Sampling for Total Load Estimation. In IEEE International Conference on Communications (ICC'03), Anchorage, Alaska, May 2003.
[5]
B.-Y. Choi, J. Park, and Z.-L. Zhang. Adaptive Packet Sampling for Accurate and Scalable Flow Measurement. In to appear in the Proceedings of IEEE Global Internet Symposium (Globecom'04), Dallas, TX, Nov/Dec 2004.
[6]
DAG. DAGMON SONET network interface. http://www.endace.com.
[7]
IPFIX. Internet Engineering Task Force, IP Flow Information Export Working Group. http://www.ietf.org/html.charters/ipfix-charter.html.
[8]
Sprint ATL IPMon project. http://ipmon.sprint.com.
[9]
PSAMP. Internet Engineering Task Force Packet Sampling Working Group. https://ops.ietf.org/lists/psamp.
[10]
Cisco Sampled NetFlow. http://www.cisco.com.
[11]
T. R. Scheaffer, W. Mendenhall, and R. Ott. Elementary Survey Sampling. Duxbury Press, 5th edition, 1995.
[12]
R. Sommer and A. Feldmann. NetFlow: Information Loss or Win. In ACM SIGCOMM Internet Measurement Workshop, Marseille, France, November 2002.
[13]
T. Yamane. Elementary Sampling Theory. Prentice-Hall, Inc., 1967.

Cited By

View all
  • (2024)CloudSentry: Two-Stage Heavy Hitter Detection for Cloud-Scale Gateway Overload ProtectionIEEE Transactions on Parallel and Distributed Systems10.1109/TPDS.2023.330185235:4(616-633)Online publication date: 1-Apr-2024
  • (2022)A GNN-based Approach for Detecting Network Anomalies from Small Traffic Samples2022 IEEE International Conference on Big Data (Big Data)10.1109/BigData55660.2022.10021074(6838-6840)Online publication date: 17-Dec-2022
  • (2021)CloudPin: A Root Cause Localization Framework of Shared Bandwidth Package Traffic Anomalies in Public Cloud Networks2021 IEEE 32nd International Symposium on Software Reliability Engineering (ISSRE)10.1109/ISSRE52982.2021.00046(367-377)Online publication date: Oct-2021
  • Show More Cited By

Recommendations

Comments

Information & Contributors

Information

Published In

cover image ACM SIGMETRICS Performance Evaluation Review
ACM SIGMETRICS Performance Evaluation Review  Volume 33, Issue 3
Special issue on the First ACM SIGMETRICS Workshop on Large Scale Network Inference (LSNI 2005)
December 2005
61 pages
ISSN:0163-5999
DOI:10.1145/1111572
Issue’s Table of Contents

Publisher

Association for Computing Machinery

New York, NY, United States

Publication History

Published: 01 December 2005
Published in SIGMETRICS Volume 33, Issue 3

Check for updates

Qualifiers

  • Article

Contributors

Other Metrics

Bibliometrics & Citations

Bibliometrics

Article Metrics

  • Downloads (Last 12 months)14
  • Downloads (Last 6 weeks)0
Reflects downloads up to 20 Feb 2025

Other Metrics

Citations

Cited By

View all
  • (2024)CloudSentry: Two-Stage Heavy Hitter Detection for Cloud-Scale Gateway Overload ProtectionIEEE Transactions on Parallel and Distributed Systems10.1109/TPDS.2023.330185235:4(616-633)Online publication date: 1-Apr-2024
  • (2022)A GNN-based Approach for Detecting Network Anomalies from Small Traffic Samples2022 IEEE International Conference on Big Data (Big Data)10.1109/BigData55660.2022.10021074(6838-6840)Online publication date: 17-Dec-2022
  • (2021)CloudPin: A Root Cause Localization Framework of Shared Bandwidth Package Traffic Anomalies in Public Cloud Networks2021 IEEE 32nd International Symposium on Software Reliability Engineering (ISSRE)10.1109/ISSRE52982.2021.00046(367-377)Online publication date: Oct-2021
  • (2021)A Two-Stage Heavy Hitter Detection System Based on CPU Spikes at Cloud-Scale Gateways2021 IEEE 41st International Conference on Distributed Computing Systems (ICDCS)10.1109/ICDCS51616.2021.00041(348-358)Online publication date: Jul-2021
  • (2017)A Modular Traffic Sampling ArchitectureJournal of Network and Systems Management10.1007/s10922-017-9404-525:3(643-668)Online publication date: 1-Jul-2017
  • (2016)Inside packet sampling techniques: exploring modularity to enhance network measurementsInternational Journal of Communication Systems10.1002/dac.313530:6Online publication date: 29-Mar-2016
  • (2015)Analysing traffic flows through samplingProceedings of the 2015 IEEE Symposium on Computers and Communication (ISCC)10.1109/ISCC.2015.7405538(341-346)Online publication date: 6-Jul-2015
  • (2014)Computational weight of network traffic sampling techniques2014 IEEE Symposium on Computers and Communications (ISCC)10.1109/ISCC.2014.6912467(1-6)Online publication date: Jun-2014
  • (2014)NNSDS: Network Nodes’ Social Attributes Discovery System Based on NetflowWeb Technologies and Applications10.1007/978-3-319-11119-3_22(235-245)Online publication date: 2014
  • (2013)Living on the edge: Monitoring network flows at the edge in cloud data centers2013 Fifth International Conference on Communication Systems and Networks (COMSNETS)10.1109/COMSNETS.2013.6465540(1-9)Online publication date: Jan-2013
  • Show More Cited By

View Options

Login options

View options

PDF

View or Download as a PDF file.

PDF

eReader

View online with eReader.

eReader

Figures

Tables

Media

Share

Share

Share this Publication link

Share on social media