Building a Better NetFlow: Technical Report
Cristian Estan, Ken Keys, David Moore, George Varghese · 2004
Network operators need to determine the composition of the trac mix on links when looking for dominant applications, users, or estimating trac matrices. Cisco’s NetFlow has evolved into a solution that satises this need by reporting o w records that summarize a sample of the trac traversing the link. But sampled NetFlow has shortcomings that hinder the collection and analysis of trac data. First, during o oding attacks router memory and network bandwidth consumed by o w records can increase beyond what is available; second, selecting the right static sampling rate is dicult because no single rate gives the right tradeo of memory use versus accuracy for all trac mixes; third, the heuristics routers use to decide when a o w is reported are a poor match to most applications that work with time bins; nally, it is impossible to estimate without bias the number of active o ws for aggregates with non-TCP trac. In this paper we propose Adaptive NetFlow, deployable through an update to router software, which addresses many shortcomings of NetFlow by dynamically adapting the sampling rate to achieve robustness without sacricing accuracy. To enable counting of non-TCP o ws, we propose an optional Flow Counting Extension that requires augmenting existing hardware at routers. Both our proposed solutions readily provide descriptions of the trac of progressively smaller sizes. Transmitting these at progressively higher levels of reliability allows graceful degradation of the accuracy of trac reports in response to network congestion on the reporting path.