Study of adaptive aggregation on IPFIX
Hitoshi Irino, Masaru Katayama, Shinichiro Chaki · 2008
We report on the design, implementation, and evaluation of a solution to two traffic management problems concerning the inability of an Exporter to manage the number of Flow Records. IPFIX will be a standard protocol for measuring traffic by collecting Flow Records made from packets going through “Exporters”, which are generally routers. IPFIX Exporters send Collectors packets containing flow information observed by an Exporter at observation points. When too many flows are observed by an Exporter, two problems occur: 1) when a transport protocol without congestion avoidance, e.g., UDP, is used, packets that include Flow Records could congest the network between the Exporter and Collector. 2) When a congestion avoidance transport protocol, e.g., TCP or SCTP, is used, Flow Records dropped because of buffer overflow in the Exporting Process cause inaccuracy in the exported Flow Records. These problems occur because the number of generated Flow Records cannot be uncontrolled in the Exporter. We solve these problems by introducing a new adaptive aggregation method designed for IPFIX. This method utilizes a new concept, Flow Key precedence. Adaptive aggregation is achieved by reducing the number of Information Elements that serve as Flow Keys gradually based on Flow Key precedence. Moreover, this method needs only an extension for the Exporter; no extensions of the protocol specifications or Collector implementations are needed.