SuperSpreaders are hosts exhibiting an unusual number of unique connections exceeding a specified threshold value. Detecting SuperSpreaders is a critical task for networks, particularly in the context of SDN, aiming to enhance network management, abnormal flow monitoring, and security. In contrast to heavy hitters detection, identifying super-spreaders hosts in high-speed networks poses significant challenges due to memory and processing requirements. Existing solutions often cannot overcome the memory and accuracy limitations imposed on network monitoring points. To tackle this issue, we propose an SSD (Space-saving detector) mechanism comprising of two filtering layers to count distinct connections per host. Additionally, we used a multi-stage data structure (hashpipe), which is employed to maintain flows with the highest cardinality while removing those with lower cardinality. We implemented our solution on SDN P4-programmable switches to confirm the feasibility of deploying our solution in physical SDN networks. Experimental results demonstrate the superiority of our solution, achieving higher F1-score and reducing Average-Absolute-Error and Average-Relative-Error compared to the closest competitor.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Space-Saving Technique in SDN for Identifying Top-k Super-Spreaders Using P4-Enabled Switches

  • Ali Nadim Alhaj,
  • Wilson Naik Bhukya,
  • Rajendra Prasad Lal

摘要

SuperSpreaders are hosts exhibiting an unusual number of unique connections exceeding a specified threshold value. Detecting SuperSpreaders is a critical task for networks, particularly in the context of SDN, aiming to enhance network management, abnormal flow monitoring, and security. In contrast to heavy hitters detection, identifying super-spreaders hosts in high-speed networks poses significant challenges due to memory and processing requirements. Existing solutions often cannot overcome the memory and accuracy limitations imposed on network monitoring points. To tackle this issue, we propose an SSD (Space-saving detector) mechanism comprising of two filtering layers to count distinct connections per host. Additionally, we used a multi-stage data structure (hashpipe), which is employed to maintain flows with the highest cardinality while removing those with lower cardinality. We implemented our solution on SDN P4-programmable switches to confirm the feasibility of deploying our solution in physical SDN networks. Experimental results demonstrate the superiority of our solution, achieving higher F1-score and reducing Average-Absolute-Error and Average-Relative-Error compared to the closest competitor.