Pith. sign in

REVIEW 1 cited by

Seek and Push: Detecting Large Traffic Aggregates in the Dataplane

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1805.05993 v1 pith:VPKMXHOJ submitted 2018-05-15 cs.NI cs.DS

classification cs.NIcs.DS
keywords trafficdataplanenetworkclusterscontrollerdetectionelastichigh-volume
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

High level goals such as bandwidth provisioning, accounting and network anomaly detection can be easily met if high-volume traffic clusters are detected in real time. This paper presents Elastic Trie, an alternative to approaches leveraging controller-dataplane architectures. Our solution is a novel push-based network monitoring approach that allows detection, within the dataplane, of high-volume traffic clusters. Notifications from the switch to the controller can be sent only as required, avoiding the transmission or processing of unnecessary data. Furthermore, the dataplane can iteratively refine the responsible IP prefixes allowing a controller to receive a flexible granularity information. We report and discuss an evaluation of our P4-based prototype, showing our solution to be able to detect (with 95% of precision), hierarchical heavy hitters and superspreaders using less than 8KB or 80KB of active memory respectively. Finally, Elastic Trie can identify changes in the network traffic patterns, symptomatic of Denial-of-Service attack events.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Programmable Data Planes for Network Security

    cs.CR 2025-07 conditional novelty 2.0 of 10

    Programmable P4 switches can support a broad range of line-rate security functions, from DDoS defense and firewalls to limited cryptography and machine-learning inference, via techniques such as recirculate-and-trunca...

Pith tools