Stroboscope: Declarative Network Monitoring on a Budget

Olivier Tilmans, Tobias Bühler, Ingmar Poese, Stefano Vissicchio, Laurent Vanbever · Digital Access to Libraries (Université catholique de Louvain (UCL), l'Université de Namur (UNamur) and the Université Saint-Louis (USL-B)) · 2018

For an Internet Service Provider (ISP), getting an accurate picture of how its network behaves is challenging.Indeed, given the carried traffic volume and the impossibility to control end-hosts, ISPs often have no other choice but to rely on heavily sampled traffic statistics, which provide them with coarse-grained visibility at a less than ideal time resolution (seconds or minutes).We present Stroboscope, a system that enables finegrained monitoring of any traffic flow by instructing routers to mirror millisecond-long traffic slices in a programmatic way.Stroboscope takes as input high-level monitoring queries together with a budget and automatically determines: (i) which flows to mirror; (ii) where to place mirroring rules, using fast and provably correct algorithms; and (iii) when to schedule these rules to maximize coverage while meeting the input budget.We implemented Stroboscope, and show that it scales well: it computes schedules for large networks and query sizes in few seconds, and produces a number of mirroring rules well within the limits of current routers.We also show that Stroboscope works on existing routers and is therefore immediately deployable.Stroboscope This paper presents Stroboscope, a scalable monitoring system that complements existing tools like NetFlow, by enabling fine-grained monitoring of any traffic flow.Stroboscope exploits the possibility to extract small traffic samples (i.e., slices) in a programmatic way, by activating and deactivating traffic mirroring for any destination prefix, up to a single IP address, networkwide, and within milliseconds.Our tests confirm that this possibility is available today, on currently deployed routers, making Stroboscope immediately deployable.By coordinating packet mirroring across routers, Stroboscope implements deterministic packet sampling: it collects copies of the same packets from multiple locations, following such packets as they cross the network.This enables Stroboscope to precisely measure the network forwarding behavior including traffic paths, one-way delays and load-balancing ratios.Traffic slices with no packets are also informative: Stroboscope uses them to determine additional forwarding properties, like packet loss and devices not receiving specific flows. Optimizing Mirroring LocationsStroboscope runs distinct algorithms to select mirroring locations for MIRROR ( §4.1) and CONFINE ( §4.2) queries.These algorithms minimize the number of mirroring locations while also providing high accuracy guarantees

Read the paper · More papers on PaperTik