WO2020106105A1 - 샘플링 기법을 이용한 네트워크 트래픽 모니터링 시스템 및 방법 - Google Patents
샘플링 기법을 이용한 네트워크 트래픽 모니터링 시스템 및 방법Info
- Publication number
- WO2020106105A1 WO2020106105A1 PCT/KR2019/016156 KR2019016156W WO2020106105A1 WO 2020106105 A1 WO2020106105 A1 WO 2020106105A1 KR 2019016156 W KR2019016156 W KR 2019016156W WO 2020106105 A1 WO2020106105 A1 WO 2020106105A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- metadata
- network
- criterion
- packet
- sampling
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/02—Capturing of monitoring data
- H04L43/022—Capturing of monitoring data by sampling
- H04L43/024—Capturing of monitoring data by sampling by adaptive sampling
Definitions
- the present invention relates to a system and method for monitoring network traffic, and more particularly, to a system and method for monitoring a network by adding a sampling technique to an in-band network monitoring technology.
- INT In-band network telemetry
- the packet that is processed by the switch is inserted into a packet processed by the switch, and the INT metadata (eg, Switch ID, Hop Latency, Queue Occupancy, etc.) containing the network information of the switch is inserted and collected by the remote monitoring engine (ME).
- ME remote monitoring engine
- sampling technique should be applied differently depending on the network environment or monitoring purpose in order to minimize network overhead and obtain reliable measurement accuracy. For example, in a network environment having a stable traffic pattern, sampling may be performed by increasing the time interval. However, in a network environment having a bursty traffic pattern, measurement accuracy is deteriorated when a technique of sampling at a fixed time interval is used. Therefore, in order to increase the accuracy of the measurement, it is necessary to flexibly apply a sampling technique according to the purpose and environment.
- the purpose of the present invention is to prevent the network performance degradation according to the metadata inserted to monitor the network status in INT (In-band Network Telemetry), and flexible sampling techniques according to the purpose and environment to increase the accuracy of the measurement It is to provide a network monitoring system and method that can be applied.
- INT In-band Network Telemetry
- the network monitoring system transfers packets between hosts, and at least one network device that inserts metadata for network monitoring into the packets in the process of delivering the packets, the at least one A monitoring engine that collects the metadata from the above network devices and monitors the network overhead caused by the metadata, and when the network overhead satisfies a preset monitoring criterion, the at least one or more network devices according to the sampling criteria It may include a controller for controlling to insert the metadata in the packet.
- a network monitoring method is a network monitoring method performed by a network monitoring system.
- the method includes inserting metadata for network monitoring into packets transmitted between hosts, and the metadata. Collecting and monitoring network overhead caused by the metadata, and controlling at least one network device to insert the metadata into the packet according to a sampling criterion when the network overhead satisfies a preset monitoring criterion And inserting the metadata into the packet according to the sampling criterion.
- performance degradation of a network according to metadata inserted to monitor a network state in in-band network telemetry (INT) may be prevented.
- the sampling technique can be flexibly applied to increase the accuracy of the measurement.
- 1 is a view for explaining the operation of the existing INT system.
- Figure 2 shows a network monitoring system according to an embodiment of the present invention.
- FIG. 3 shows the configuration of a packet header in which metadata is inserted according to each sampling criterion.
- FIG. 4 is a flowchart of a network monitoring method according to an embodiment of the present invention.
- 5 is a view for explaining a change in the network overhead of each INT technique according to the length of the path.
- first or second may be used to describe various components, but the components should not be limited by the terms. The above terms are only for the purpose of distinguishing one component from other components, for example, without departing from the scope of rights according to the concept of the present invention, the first component may be referred to as the second component, Similarly, the second component may also be referred to as the first component.
- 1 is a view for explaining the operation of the existing INT system.
- INT in order to perform an existing in-band network telemetry (INT), a header of an INT is defined through a P4 language and a process of updating the metadata of the INT is defined.
- the INT metadata is information related to a network switch, for example, a network device ID, an ingress / egress port ID, hop latency, queue occupancy, and reception / transmission. And a timestamp.
- Network switches programmed to perform INT are classified into the following three categories according to their role.
- One) INT Source Inserts INT metadata into the packet for the first time as the starting point of INT.
- Host H1 generates a flow destined for host H2, and data packets in the flow are delivered to H2 through three network switches programmed to support INT.
- INT Network Switches
- the INT Source located on the first switch inserts an INT header for traffic from H1 to H2. At this time, it displays the INT metadata information to be collected through the INT Instruction Bitmap included in the INT header, inserts the corresponding INT metadata into the INT header, and sends the packet to the next switch.
- the INT Transit node located in the second switch additionally inserts the INT metadata included in the INT Instruction Bitmap in the INT header into the INT header and delivers the packet to the next switch.
- the INT Sink node of the third switch similarly inserts the INT metadata and then separates the finally collected INT metadata from the original data packet and delivers it to the monitoring engine (ME).
- the INT Sink node delivers the separated original data packet to the destination H2.
- INT's network monitoring provides packet-level network visibility and can understand the status of network equipment through P4 programming.
- the present invention proposes a network monitoring system and method according to a flexible sampling-based in-band network telemetry (FS-INT) technique that can flexibly apply a sampling technique in consideration of the purpose and environment of the network.
- FS-INT flexible sampling-based in-band network telemetry
- Figure 2 shows a network monitoring system according to an embodiment of the present invention.
- the network monitoring system 1 can be applied to the INT environment, it may also be configured as an SDN system.
- SDN Software Defined Networking
- SDN provides programmability and flexibility by separating the control plane and the transmission plane (or data plane) of the network.
- SDN frees existing fixed functions and limited accessibility and allows new protocols and networking services to be freely applied, and the centralized SDN controller enables more efficient network management than the existing distributed environment.
- the network monitoring system 1 according to an embodiment of the present invention is configured with SDN is described, but is not limited thereto.
- the network monitoring system 1 includes at least one or more network devices 10a to 10e, a monitoring engine 20 and a controller 30.
- the at least one network device 10a to 10e may mean a functional element for forwarding, switching, or routing traffic or packets, such as a switch or a router.
- at least one or more network devices 10a to 10e include switches, routers, switching elements, and routing elements defined in OpenFlow, IETF, ETSI, and / or ITU-T. Or it may mean a forwarding element. It is obvious that the number of the at least one network device 10a to 10e shown in FIG. 2 does not limit the scope of the present invention.
- each of the at least one network device 10a to 10e is a packet in which metadata is inserted, a storage space (a memory or a storage unit, etc.) for the program to store and manage the INT technique or sampling technique compiled from the controller 30. ).
- At least one of the network devices 10a to 10e transfers packets between hosts, and inserts metadata for network monitoring into packets in the process of transferring packets.
- at least one or more network devices 10a to 10e may compile a program in which an INT technique and a sampling technique are defined from the controller 30.
- At least one or more network devices 10a to 10e may include an INT Source node 10a, an INT Transit node 10a, 10b, and 10c and an INT Sink node 10e.
- the INT Source node 10a inserts an INT header into a packet received from the host 1 100. Since the inserted INT header includes an INT Instruction Bitmap displaying the INT metadata information to be collected, the metadata is collected according to the INT Instruction Bitmap, and the collected metadata is inserted into the INT header to connect to the next network device (10a to 10e) To pass.
- the INT Transit nodes (10a, 10b, 10c) are all nodes located between the INT Source node (10a) and the INT Sink node (10e), and collect metadata according to the INT Instruction Bitmap included in the INT header of the received packet. , Insert the collected metadata into the INT header and deliver it to the next network device 10a to 10e.
- the INT Sink node 10e also collects metadata according to the INT Instruction Bitmap included in the INT header of the received packet, and inserts the collected metadata into the INT header. In addition, the INT Sink node 10e separates all metadata inserted in the INT header from the packet and delivers it to the monitoring engine 20, and the separated packet is delivered to the destination host 2 200. In addition, the INT Sink node 10e as well as other network devices 10a to 10e may be connected to the monitoring engine 20 to transfer metadata.
- the monitoring engine 20 collects metadata from at least one or more network devices 10a to 10e to monitor network overhead caused by the metadata.
- the monitoring engine 20 may mean a server that monitors network conditions.
- the monitoring engine 20 monitors the entire network including at least one or more network devices 10a to 10e through the collected metadata, and if the network overhead caused by the metadata satisfies a preset monitoring criterion, the controller
- the network status information is transmitted to (30).
- the preset monitoring criterion may include, for example, all criteria that can detect a network load, such as a set value for a ratio of protocol overhead such as header or delay per packet. have. When it is set for the protocol overhead as in the above example, it may be set to satisfy a preset monitoring criterion when the ratio occupied by the protocol overhead in the packet is greater than or equal to a preset threshold, but is not limited to this example.
- the controller 30 may mean an SDN controller, and may mean a functional element that controls related components (eg, switches, routers, etc.) to control the flow of traffic.
- the controller 30 is not limited by a physical implementation form or an implementation location.
- the controller 30 is a controller function element defined by OpenFlow, Internet Engineering Task Force (IETF), European Telecommunication Standards Institute (ETSI), and / or International Telecommunication Union Telecommunication (ITU-T). Can mean
- the controller 30 controls at least one network device 10a to 10e to insert metadata into the packet according to the sampling criteria.
- the controller 30 is configured to dynamically adjust at least one or more network devices 10a to 10e according to a rate based sampling event or an event based sampling criterion in consideration of at least one of a network environment and monitoring purposes. It is controlled to operate.
- At least one or more network devices 10a to 10e when considering the network environment, when the flow of the traffic flow is stable (that is, when the amount of traffic change is less than a preset threshold), at least one or more network devices 10a to 10e according to a rate-based sampling criterion to be described later ) To operate, and when the flow of the traffic flow is bursty (that is, when the amount of traffic change is greater than or equal to a preset threshold), at least one or more network devices 10a to 10e according to the event-based sampling criteria to be described later It can be controlled to work.
- the sampling criterion refers to a criterion for selectively determining data packets to insert metadata and metadata to be inserted into each data packet.
- Sampling criteria may include rate based sampling events and event based sampling criteria.
- the rate-based sampling criterion allows metadata to be inserted in only one packet per R (where R is a natural number) among packets transmitted by the at least one network device 10a to 10e. That is, when the network devices 10a to 10e operate according to a rate-based sampling criterion, an INT header is inserted into one packet per R packets, and metadata is inserted only for packets after the INT header is inserted. Therefore, according to the ratio-based sampling criterion, it is possible to reduce network overhead by selectively determining packets to which metadata is to be inserted.
- the event-based sampling criterion allows at least one network device 10a to 10e to insert only metadata that satisfies a predetermined metadata criterion into a packet.
- the preset metadata criterion is a criterion for selectively determining metadata to be inserted, for example, may be for a type of metadata, such as hop latency, network device ID, and queue occupancy. It may be a value set for metadata.
- the hop delay is determined only when it is determined that the hop delay time in the network devices 10a to 10e causes a delay in the network flow as it indicates more than a certain value. Time can be collected and inserted into packets.
- FIG. 3 shows the configuration of a packet header in which metadata is inserted according to each sampling criterion.
- the network device uses the reserved field of the Instruction Bitmap of the INT header to indicate what type of metadata is inserted according to the preset metadata criteria, and specifies it in the Insertion bitmap. Therefore, it is possible to check the type of metadata inserted by the INT Transit nodes 10a, 10b, and 10c at each hop through the insertion bitmap of the packet.
- the network monitoring system 1 is integrated in the controller 30, the controller 30 is the monitoring engine 20 of the It can also be configured to perform functions. That is, the controller 30 controls the network devices 10a to 10e to insert metadata into the packet according to the sampling criteria and the network generated by the metadata by collecting metadata from the network devices 10a to 10e. It can be configured to perform the function of monitoring the overhead together.
- FIG. 4 is a flowchart of a network monitoring method according to an embodiment of the present invention.
- detailed descriptions of parts overlapping with those described above will be omitted.
- the network monitoring method is a network monitoring method performed by the network monitoring system, the compilation step (S100), metadata insertion step (S200), overhead monitoring step (S300) ), A sampling technique switching step (S400) and a sampling step (S500).
- Step S100 is a step in which each network device compiles a program in which an INT technique for inserting metadata into a packet and a sampling technique for sampling and inserting metadata according to a specific criterion into network devices, respectively. Compilation can be performed by the controller in the SDN environment.
- Step S200 is a step of inserting metadata for network monitoring into a packet transmitted between hosts according to the compiled INT technique. Insertion of metadata can be performed in each of the INT Source node, INT Transit node, and INT Sink node.
- the INT Source node receives a packet from the host, the INT header is inserted into the packet before metadata insertion. Accordingly, the INT Transit node receiving the packet and the INT Sink node may collect metadata by referring to the INT Instruction bitmap included in the INT header.
- the step S300 is a step of monitoring the network overhead caused by the metadata by collecting metadata from each network device.
- the network overhead increases as the length of the path increases and as more metadata is inserted into the packet. Therefore, there is a need to monitor such network overhead to prevent network degradation.
- it is continuously determined whether the network overhead caused by the metadata satisfies a preset monitoring criterion (S350).
- step S400 the network device controls to insert metadata into the packet according to the sampling criterion. That is, in step S400, the controller switches the operation of the network device so that the network device collects metadata according to the sampling technique compiled in step S100 and inserts the collected metadata into the packet.
- the sampling criterion may include a rate-based sampling criterion and an event-based sampling criterion as described above.
- step S400 may further include a step of selecting any one of the above-described sampling criteria as an optimal sampling criterion in consideration of at least one of a network environment and monitoring purposes.
- the step of selecting a sampling criterion calculates network overhead that may occur when each sampling criterion is applied to a network device, and compares the calculated network overhead to select a sampling criterion when having less network overhead.
- the network device may be operated according to the selected optimal sampling criterion.
- step S500 the network device whose operation is switched by step S400 is a step of collecting metadata and inserting it into a packet according to a sampling criterion, not an INT technique. That is, in steps S200 to S300, the network device collects metadata by the INT technique, monitors it, and when it is converted from the INT technique to the sampling technique by the S400 stage, collects metadata by the sampling technique and monitors it. . In addition, when the network overhead is reduced after the step S500, the applied sampling criterion may be maintained, and if it is monitored that the measurement accuracy is degraded, the sampling criterion is canceled again and the network device is operated to operate according to the existing INT technique. You can also switch actions.
- 5 is a view for explaining a change in the network overhead of each INT technique according to the length of the path.
- INT means network overhead (ie, protocol overhead) by the existing INT technique
- R-INT means network overhead by the rate-based sampling technique proposed in the present invention
- DBS-INT means network overhead by the rate-based event-based sampling method proposed in the present invention.
- the network overhead increases as the length of the path (ie, the number of hops) increases, so the proportion of metadata inserted into the packet increases.
- the network overhead caused by metadata is reduced by more than half compared to the existing INT technique. This is because in the case of the network monitoring system and method according to an embodiment of the present invention, all metadata is not collected and inserted, but metadata is efficiently collected and inserted according to a preset sampling criterion.
- Table 1 below shows the average hop delay time of each INT technique according to the length of the path.
- the average hop delay time observed by the DBS-INT technique is similar to the value observed by the existing INT technique.
- the metadata of the DBS-INT technique targeting hop latency there is a field for storing hop latency collected based on an event. Calculates the difference between the value of this field at each hop and the hop latency on the current network device, and only clears the field if the calculated value is outside the preset hop latency threshold (i.e., based on pre-set metadata). Update. That is, the hop delay time that is not collected means that the difference from the collected hop delay time is not large.
- the network monitoring system and method according to an embodiment of the present invention are not simply using the R-INT technique in which the number of sampling times is reduced, but the existing INT through flexible use of the sampling technique together with the DBS-INT technique. You can get results similar to the information you can get.
- the device described above may be implemented with hardware components, software components, and / or combinations of hardware components and software components.
- the devices and components described in the embodiments include, for example, processors, controllers, arithmetic logic units (ALUs), digital signal processors (micro signal processors), microcomputers, field programmable arrays (FPAs), It may be implemented using one or more general purpose computers or special purpose computers, such as a programmable logic unit (PLU), microprocessor, or any other device capable of executing and responding to instructions.
- the processing device may run an operating system (OS) and one or more software applications running on the operating system.
- the processing device may access, store, manipulate, process, and generate data in response to the execution of the software.
- OS operating system
- the processing device may access, store, manipulate, process, and generate data in response to the execution of the software.
- a processing device may be described as one being used, but a person having ordinary skill in the art, the processing device may include a plurality of processing elements and / or a plurality of types of processing elements. It can be seen that may include.
- the processing device may include a plurality of processors or a processor and a controller.
- other processing configurations such as parallel processors, are possible.
- the software may include a computer program, code, instruction, or a combination of one or more of these, and configure the processing device to operate as desired, or process independently or collectively You can command the device.
- Software and / or data may be interpreted by a processing device, or to provide instructions or data to a processing device, of any type of machine, component, physical device, virtual equipment, computer storage medium or device. , Or may be permanently or temporarily embodied in the transmitted signal wave.
- the software may be distributed over networked computer systems, and stored or executed in a distributed manner.
- Software and data may be stored in one or more computer-readable recording media.
- the method according to the embodiment may be implemented in the form of program instructions that can be executed through various computer means and recorded on a computer-readable medium.
- the computer-readable medium may include program instructions, data files, data structures, or the like alone or in combination.
- the program instructions recorded in the medium may be specially designed and configured for the embodiments or may be known and usable by those skilled in computer software.
- Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical media such as CD-ROMs, DVDs, and magnetic media such as floptical disks.
- -Hardware devices specifically configured to store and execute program instructions such as magneto-optical media, and ROM, RAM, flash memory, and the like.
- program instructions include high-level language codes that can be executed by a computer using an interpreter, etc., as well as machine language codes produced by a compiler.
- the hardware device described above may be configured to operate as one or more software modules to perform the operations of the embodiments, and vice versa.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
네트워크 모니터링 시스템이 개시된다. 상기 네트워크 모니터링 시스템은 호스트 간에 패킷을 전달하고, 상기 패킷을 전달하는 과정에서 네트워크 모니터링을 위한 메타데이터(metadata)를 상기 패킷에 삽입하는 적어도 하나 이상의 네트워크 장치, 상기 적어도 하나 이상의 네트워크 장치로부터 상기 메타데이터를 수집하여 상기 메타데이터로 인해 발생하는 네트워크 오버헤드를 모니터링하는 모니터링 엔진, 및 상기 네트워크 오버헤드가 기 설정된 모니터링 기준을 만족할 경우 상기 적어도 하나 이상의 네트워크 장치가 샘플링 기준에 따라 상기 패킷에 상기 메타데이터를 삽입하도록 제어하는 컨트롤러를 포함한다.
Description
본 발명은 네트워크 트래픽을 모니터링하는 시스템 및 방법에 대한 것으로서, 보다 구체적으로 인 밴드 방식(In-band)의 네트워크 모니터링 기술에 샘플링 기법을 추가하여 네트워크를 모니터링하는 시스템 및 방법에 대한 것이다.
클라우드, 모바일 서비스 등의 다양한 네트워크 서비스의 수요가 증가함에 따라 네트워크의 복잡성이 증가하고 있으며, 이에 따라 효율적인 네트워크 관리의 중요성이 부각되고 있다. 네트워크 관리를 위한 핵심요구사항은 네트워크에 대한 가시성을 얻는 것으로, 네트워크 내에 흐르는 패킷들에 대한 정보를 네트워크 모니터링 기술을 통해 수집하여 확보할 수 있다. 이를 통해 빠르고 효율적으로 이미 발생한 장애 또는 발생할 수 있는 잠재적 병목 현상을 식별하고 해소함으로써 최적의 네트워크를 관리를 수행하게 된다. 한편, 기존의 대표적인 네트워크 모니터링 기술로 SNMP, sFlow, NetFlow 등이 있는데 이러한 모니터링 기법들은 네트워크의 패킷전달 장비인 스위치, 라우터 등에서 SNMP, sFlow, NetFlow를 위한 별도의 모듈과 프로토콜을 지원해야 한다는 특징이 있다. 따라서, 기존의 모니터링 기법을 수행하기 위해서는 각 기법마다 별도의 장비가 필요하며 이에 따라 배치와 관리에 대한 비용이 증가하게 된다.
한편, 최근에 P4와 같은 고수준 언어를 통해 프로그래밍이 가능한 고성능 패킷 처리 칩을 탑재한 스위치나 라우터 등의 네트워크 장비가 등장하였다. 이러한 네트워크 장비들에서는 P4 프로그래밍을 통해 패킷 헤더 정의, 유입되는 패킷들에 대한 Parsing 규칙, 패킷 변형, Match-Action Table 등을 하드웨어 ASIC 칩을 바꾸지 않고도 다시 설정할 수 있다. 이러한 네트워크 장비의 프로그래밍을 통한 인 밴드 방식의 네트워크 모니터링 기술(In-band Network Telemetry, INT)이 제안되었다. INT에서는 스위치가 처리하는 패킷에 스위치의 네트워크 정보가 담긴 INT 메타데이터(예를 들어, Switch ID, Hop Latency, Queue Occupancy 등)를 삽입하여 원격의 모니터링 엔진(Monitoring Engine, ME)에서 이를 수집함으로써 패킷 수준의 네트워크 모니터링 기능을 제공하며 앞선 모니터링 기법들과 비교하여 별도의 장비를 구성하지 않아도 되는 장점이 있다.
INT에서는 INT 장비로 유입되는 모든 데이터 패킷들에 대해 네트워크 상태 모니터링을 위한 메타데이터를 삽입한다. 그러나, 모니터링을 위해 삽입되는 메타데이터가 결과적으로 패킷의 크기를 키우기 때문에, 많은 메타데이터가 수집될수록 네트워크의 성능을 저하시키는 문제가 발생한다. 이러한 문제를 해결하기 위해 일반적으로 샘플링 기법이 사용된다. 한편, 샘플링 기법은 네트워크 오버헤드를 최소화하며 신뢰할 수 있는 측정의 정확도를 얻기 위해 네트워크 환경 또는 모니터링 목적에 따라 다르게 적용되어야 한다. 예를 들어, 안정적 트래픽(stable traffic) 패턴을 갖는 네트워크 환경에서는 시간 인터벌을 늘리는 것으로 샘플링을 할 수 있다. 그러나, 폭발적 트래픽(bursty traffic) 패턴을 갖는 네트워크 환경에서는 고정된 시간 인터벌마다 샘플링하는 기법을 사용할 경우 측정 정확도가 떨어진다. 따라서, 측정의 정확도를 높이기 위해서는 목적 및 환경에 따라 유연하게 샘플링 기법을 적용할 필요성이 있다.
본 발명의 목적은 INT(In-band Network Telemetry)에서 네트워크 상태를 모니터링하기 위해 삽입되는 메타데이터에 따른 네트워크의 성능 저하를 방지하고, 측정의 정확도를 높이기 위해 목적 및 환경에 따라 유연하게 샘플링 기법을 적용할 수 있는 네트워크 모니터링 시스템 및 방법을 제공하는데 있다.
본 발명의 일 실시예에 따른 네트워크 모니터링 시스템은 호스트 간에 패킷을 전달하고, 상기 패킷을 전달하는 과정에서 네트워크 모니터링을 위한 메타데이터(metadata)를 상기 패킷에 삽입하는 적어도 하나 이상의 네트워크 장치, 상기 적어도 하나 이상의 네트워크 장치로부터 상기 메타데이터를 수집하여 상기 메타데이터로 인해 발생하는 네트워크 오버헤드를 모니터링하는 모니터링 엔진, 및 상기 네트워크 오버헤드가 기 설정된 모니터링 기준을 만족할 경우 상기 적어도 하나 이상의 네트워크 장치가 샘플링 기준에 따라 상기 패킷에 상기 메타데이터를 삽입하도록 제어하는 컨트롤러를 포함할 수 있다.
본 발명의 일 실시예에 따른 네트워크 모니터링 방법은 네트워크 모니터링 시스템에 의해 수행되는 네트워크 모니터링 방법으로서, 호스트 간에 전달되는 패킷에 네트워크 모니터링을 위한 메타데이터(metadata)를 상기 패킷에 삽입하는 단계, 상기 메타데이터를 수집하여 상기 메타데이터로 인해 발생하는 네트워크 오버헤드를 모니터링하는 단계, 상기 네트워크 오버헤드가 기 설정된 모니터링 기준을 만족할 경우 샘플링 기준에 따라 상기 패킷에 상기 메타데이터를 삽입하도록 적어도 하나 이상의 네트워크 장치를 제어하는 단계, 및 상기 샘플링 기준에 따라 상기 메타데이터를 상기 패킷에 삽입하는 단계를 포함할 수 있다.
본 발명의 일 실시예에 따르면, INT(In-band Network Telemetry)에서 네트워크 상태를 모니터링하기 위해 삽입되는 메타데이터에 따른 네트워크의 성능 저하를 방지할 수 있다.
또한, 목적 및 환경에 따라 유연하게 샘플링 기법을 적용하여 측정의 정확도를 높일 수 있다.
도 1은 기존의 INT 시스템의 동작을 설명하기 위한 도면이다.
도 2는 본 발명의 일 실시예에 따른 네트워크 모니터링 시스템을 도시한 것이다.
도 3은 각 샘플링 기준에 따라 메타데이터가 삽입된 패킷 헤더의 구성을 도시한 것이다.
도 4는 본 발명의 일 실시예에 따른 네트워크 모니터링 방법의 순서도이다.
도 5는 경로의 길이에 따른 각 INT 기법들의 네트워크 오버헤드의 변화를 설명하기 위한 도면이다.
본 명세서에 개시되어 있는 본 발명의 개념에 따른 실시예들에 대해서 특정한 구조적 또는 기능적 설명들은 단지 본 발명의 개념에 따른 실시예들을 설명하기 위한 목적으로 예시된 것으로서, 본 발명의 개념에 따른 실시예들은 다양한 형태로 실시될 수 있으며 본 명세서에 설명된 실시예들에 한정되지 않는다.
본 발명의 개념에 따른 실시예들은 다양한 변경들을 가할 수 있고 여러 가지 형태들을 가질 수 있으므로 실시예들을 도면에 예시하고 본 명세서에 상세하게 설명하고자 한다. 그러나 이는 본 발명의 개념에 따른 실시예들을 특정한 개시형태들에 대해 한정하려는 것이 아니며, 본 발명의 사상 및 기술 범위에 포함되는 변경, 균등물, 또는 대체물을 포함한다.
제1 또는 제2 등의 용어를 다양한 구성요소들을 설명하는데 사용될 수 있지만, 상기 구성요소들은 상기 용어들에 의해 한정되어서는 안 된다. 상기 용어들은 하나의 구성요소를 다른 구성요소로부터 구별하는 목적으로만, 예를 들어 본 발명의 개념에 따른 권리 범위로부터 이탈되지 않은 채, 제1 구성요소는 제2 구성요소로 명명될 수 있고, 유사하게 제2 구성요소는 제1 구성요소로도 명명될 수 있다.
어떤 구성요소가 다른 구성요소에 "연결되어" 있다거나 "접속되어" 있다고 언급된 때에는, 그 다른 구성요소에 직접적으로 연결되어 있거나 또는 접속되어 있을 수도 있지만, 중간에 다른 구성요소가 존재할 수도 있다고 이해되어야 할 것이다. 반면에, 어떤 구성요소가 다른 구성요소에 "직접 연결되어" 있다거나 "직접 접속되어" 있다고 언급된 때에는, 중간에 다른 구성요소가 존재하지 않는 것으로 이해되어야 할 것이다. 구성요소들 간의 관계를 설명하는 표현들, 예를 들어 "~사이에"와 "바로~사이에" 또는 "~에 직접 이웃하는" 등도 마찬가지로 해석되어야 한다.
본 명세서에서 사용한 용어는 단지 특정한 실시예들을 설명하기 위해 사용된 것으로, 본 발명을 한정하려는 의도가 아니다. 단수의 표현은 문맥상 명백하게 다르게 뜻하지 않는 한, 복수의 표현을 포함한다. 본 명세서에서, "포함하다" 또는 "가지다" 등의 용어는 설시된 특징, 숫자, 단계, 동작, 구성요소, 부분품 또는 이들을 조합한 것이 존재함으로 지정하려는 것이지, 하나 또는 그 이상의 다른 특징들이나 숫자, 단계, 동작, 구성요소, 부분품 또는 이들을 조합한 것들의 존재 또는 부가 가능성을 미리 배제하지 않는 것으로 이해되어야 한다.
다르게 정의되지 않는 한, 기술적이거나 과학적인 용어를 포함해서 여기서 사용되는 모든 용어들은 본 발명이 속하는 기술 분야에서 통상의 지식을 가진 자에 의해 일반적으로 이해되는 것과 동일한 의미를 가진다. 일반적으로 사용되는 사전에 정의되어 있는 것과 같은 용어들은 관련 기술의 문맥상 가지는 의미와 일치하는 의미를 갖는 것으로 해석되어야 하며, 본 명세서에서 명백하게 정의하지 않는 한, 이상적이거나 과도하게 형식적인 의미로 해석되지 않는다. 이하, 실시예들을 첨부된 도면을 참조하여 상세하게 설명한다.
도 1은 기존의 INT 시스템의 동작을 설명하기 위한 도면이다.
도 1을 참조하면, 기존의 INT(In-band Network Telemetry)를 수행하기 위해서는 P4 언어를 통해 INT의 헤더(Header)를 정의하고 INT의 메타데이터(Metadata)를 업데이트하는 과정을 정의하여야 한다. 여기서, INT 메타데이터란 네트워크 스위치와 관련된 정보로서 예를 들면 네트워크 장치 ID, 유입(ingress)/유출(egress) 포트 ID, 홉 지연시간(hop latency), 큐 점유도(queue occupancy), 수신/송신 대기열(timestamp) 등을 포함할 수 있다.
INT를 수행하도록 프로그래밍된 네트워크 스위치들은 그 역할에 따라 다음과 같이 3가지로 구분된다.
1)
INT Source : INT의 시작점으로서 INT 메타데이터를 처음으로 패킷에 삽입한다.
2) INT Sink : INT의 끝점으로서 통합된 INT 메타데이터를 분리하여 원래의 패킷을 복원하고 메타데이터를 모니터링 엔진(ME)으로 전송한다.
3) INT Transit : INT Source와 Sink 사이에서 INT 메타데이터를 삽입하며 패킷을 전달한다.
호스트 H1은 호스트 H2를 목적지로 하는 플로우를 발생시키며, 해당 플로우 내의 데이터 패킷들은 INT를 지원하도록 프로그래밍된 3개의 네트워크 스위치를 거쳐 H2로 전달된다. 이하에서 플로우의 전달 과정과 메타데이터 수집 과정을 설명하기로 한다.
우선, 첫 번째 스위치에 위치한 INT Source는 H1에서 H2로의 트래픽에 대해 INT 헤더를 삽입한다. 이때, INT 헤더에 포함된 INT Instruction Bitmap을 통해 수집하고자 하는 INT 메타데이터 정보를 표시하며, 해당 INT 메타데이터를 INT 헤더에 삽입한 후 패킷을 다음 스위치로 보낸다.
다음으로, 두 번째 스위치에 위치한 INT Transit 노드는 마찬가지로 INT 헤더 내의 INT Instruction Bitmap에 포함된 INT 메타데이터를 INT 헤더에 추가적으로 삽입하고 다음 스위치로 패킷을 전달한다.
마지막으로, 세 번째 스위치의 INT Sink 노드는 마찬가지로 INT 메타데이터를 삽입한 후 최종적으로 수집된 INT 메타데이터를 원래의 데이터 패킷과 분리하여 모니터링 엔진(ME)으로 전달한다. 또한, INT Sink 노드는 분리된 원래의 데이터 패킷을 목적지인 H2로 전달한다.
이와 같은 과정을 통해 INT의 네트워크 모니터링은 패킷 수준의 네트워크 가시성을 제공하며 P4 프로그래밍을 통해 네트워크 장비의 상태정보까지 파악할 수 있다.
그러나, 기존의 INT 기법은 모니터링을 위해 패킷에 삽입되는 메타데이터에 따라 네트워크의 성능 저하가 발생하게 되며, 이를 해결하고자 샘플링 기법을 무분별하게 적용하게 되면 측정 정확도가 떨어지는 문제점이 발생한다. 따라서, 본 발명에서는 네트워크의 목적 및 환경을 고려하여 유연하게 샘플링 기법을 적용할 수 있는 FS-INT(Flexible Sampling-based In-band Network Telemetry) 기법에 따른 네트워크 모니터링 시스템 및 방법을 제안한다.
도 2는 본 발명의 일 실시예에 따른 네트워크 모니터링 시스템을 도시한 것이다.
도 2를 참조하면, 본 발명의 일 실시예에 따른 네트워크 모니터링 시스템(1)은 INT 환경에 적용될 수 있으며, 또한 SDN 시스템으로 구성될 수도 있다.
SDN(Software Defined Networking)은 기존의 통합형 네트워크와 달리 네트워크의 제어 평면(control plane)과 전송 평면(또는 데이터 평면, data plane)을 분리하여 프로그래밍가능성(programmability)과 유연성(flexibility)을 제공한다. SDN은 기존의 고정된 기능과 제한된 접근성에서 벗어나 새로운 프로토콜과 네트워킹 서비스를 자유롭게 적용할 수 있게 해주며, 중앙집중화된 SDN 컨트롤러를 통해 기존의 분산 환경보다 더욱 효과적으로 네트워크를 관리할 수 있게 한다. 이하에서는 본 발명의 일 실시예에 따른 네트워크 모니터링 시스템(1)이 SDN으로 구성된 경우에 대하여 설명하기로 하나, 이에 한정되는 것은 아니다.
본 발명의 일 실시예에 따른 네트워크 모니터링 시스템(1)은 적어도 하나 이상의 네트워크 장치(10a 내지 10e), 모니터링 엔진(20) 및 컨트롤러(30)를 포함한다.
적어도 하나 이상의 네트워크 장치(10a 내지 10e)는 스위치(switch) 또는 라우터(router)와 같이 트래픽 또는 패킷을 포워딩하거나 스위칭 또는 라우팅하는 기능 요소를 의미할 수 있다. 예컨대, 적어도 하나 이상의 네트워크 장치(10a 내지 10e)는 오픈플로(OpenFlow), IETF, ETSI 및/또는 ITU-T 등에서 정의하고 있는 스위치, 라우터, 스위칭 요소(Switching Element), 라우팅 요소(Routing Element), 또는 포워딩 요소(Forwarding Element) 등을 의미할 수 있다. 도 2에 도시된 적어도 하나 이상의 네트워크 장치(10a 내지 10e)들의 개수가 본 발명의 권리범위를 제한하는 것이 아님은 자명하다. 또한, 적어도 하나 이상의 네트워크 장치(10a 내지 10e) 각각은 메타데이터가 삽입되는 패킷, 컨트롤러(30)로부터 컴파일되는 INT 기법이나 샘플링 기법에 대한 프로그램이 저장 및 관리하기 위한 저장 공간(메모리 또는 저장부 등)을 포함할 수 있다.
적어도 하나 이상의 네트워크 장치(10a 내지 10e)는 호스트 간에 패킷을 전달하고, 패킷을 전달하는 과정에서 네트워크 모니터링을 위한 메타데이터를 패킷에 삽입한다. 이를 위하여, 적어도 하나 이상의 네트워크 장치(10a 내지 10e)는 컨트롤러(30)로부터 INT 기법과 샘플링 기법이 정의된 프로그램이 컴파일될 수 있다.
도 1에서 상술한 바와 같이, 적어도 하나 이상의 네트워크 장치(10a 내지 10e)는 INT Source 노드(10a), INT Transit 노드(10a, 10b, 10c) 및 INT Sink 노드(10e)를 포함할 수 있다. INT Source 노드(10a)에서는 호스트 1(100)로부터 전달받은 패킷에 INT 헤더를 삽입한다. 삽입된 INT 헤더에는 수집하고자 하는 INT 메타데이터 정보가 표시된 INT Instruction Bitmap이 포함되므로, INT Instruction Bitmap에 따라 메타데이터를 수집하고, 수집된 메타데이터를 INT 헤더에 삽입하여 다음 네트워크 장치(10a 내지 10e)로 전달한다.
INT Transit 노드(10a, 10b, 10c)는 INT Source 노드(10a)와 INT Sink 노드(10e) 사이에 위치한 모든 노드들로서, 전달받은 패킷의 INT 헤더에 포함된 INT Instruction Bitmap에 따라 메타데이터를 수집하고, 수집된 메타데이터를 INT 헤더에 삽입하여 다음 네트워크 장치(10a 내지 10e)로 전달한다.
INT Sink 노드(10e)도 마찬가지로 전달받은 패킷의 INT 헤더에 포함된 INT Instruction Bitmap에 따라 메타데이터를 수집하고, 수집된 메타데이터를 INT 헤더에 삽입한다. 또한, INT Sink 노드(10e)는 INT 헤더에 삽입된 모든 메타데이터를 패킷과 분리하여 모니터링 엔진(20)에 전달하며, 분리된 패킷은 목적지인 호스트 2(200)로 전달한다. 또한, INT Sink 노드(10e) 뿐만 아니라, 다른 네트워크 장치(10a 내지 10e)들도 모니터링 엔진(20)과 연결되어 메타데이터를 전달할 수도 있다.
모니터링 엔진(20)은 적어도 하나 이상의 네트워크 장치(10a 내지 10e)로부터 메타데이터를 수집하여 메타데이터로 인해 발생하는 네트워크 오버헤드를 모니터링한다. 여기서, 모니터링 엔진(20)은 네트워크 상황을 모니터링하는 서버를 의미할 수 있다. 모니터링 엔진(20)은 수집된 메타데이터를 통해 적어도 하나 이상의 네트워크 장치(10a 내지 10e)가 포함된 전체 네트워크를 모니터링하며, 만약 메타데이터로 인해 발생하는 네트워크 오버헤드가 기 설정된 모니터링 기준을 만족할 경우 컨트롤러(30)에 네트워크 상황 정보를 전달한다. 여기서, 기 설정된 모니터링 기준은 예를 들면 헤더 또는 패킷 당 지연과 같은 프로토콜 오버헤드(protocol overhead)가 패킷에서 차지하는 비율에 대하여 설정된 수치와 같이 네트워크 부하를 감지할 수 있는 모든 기준에 대한 것을 포함할 수 있다. 상술한 예와 같이 프로토콜 오버헤드에 대하여 설정될 경우, 패킷에서 프로토콜 오버헤드가 차지하는 비율이 기 설정된 임계값 이상일 경우 기 설정된 모니터링 기준을 만족하는 것으로 설정할 수도 있으나, 이러한 예에 한정되는 것은 아니다.
컨트롤러(30)는 SDN 컨트롤러를 의미할 수 있으며, 트래픽의 흐름을 제어하기 위해 관련 구성 요소(예컨대, 스위치, 라우터 등)를 제어하는 기능 요소(entity)를 의미할 수 있다. 또한, 컨트롤러(30)는 물리적인 구현 형태나 구현 위치 등에 의해 한정되지 않는다. 예컨대, 컨트롤러(30)는 오픈플로(OpenFlow), IETF(Internet Engineering Task Force), ETSI(European Telecommunication Standards Institute) 및/또는 ITU-T(International Telecommunication Union Telecommunication) 등에서 정의하고 있는 컨트롤러 기능 요소(entity)를 의미할 수 있다.
컨트롤러(30)는 모니터링 엔진(20)으로부터 네트워크 상황 정보를 전달받으면, 적어도 하나 이상의 네트워크 장치(10a 내지 10e)가 샘플링 기준에 따라 패킷에 메타데이터를 삽입하도록 제어한다. 이때, 컨트롤러(30)는 네트워크 환경 및 모니터링 목적 중 적어도 어느 하나를 고려하여 적어도 하나 이상의 네트워크 장치(10a 내지 10e)가 비율 기반(rate based) 샘플링 기준 또는 이벤트 기반(event based) 샘플링 기준에 따라 동적으로 동작하도록 제어한다. 일 예로서, 네트워크 환경을 고려할 때 트래픽 플로우의 흐름이 안정적(stable)일 경우(즉, 트래픽 변화량이 기 설정된 임계값 미만인 경우) 후술할 비율 기반 샘플링 기준에 따라 적어도 하나 이상의 네트워크 장치(10a 내지 10e)가 동작하도록 제어하고, 트래픽 플로우의 흐름이 폭발적(bursty)일 경우(즉, 트래픽 변화량이 기 설정된 임계값 이상인 경우) 후술할 이벤트 기반 샘플링 기준에 따라 적어도 하나 이상의 네트워크 장치(10a 내지 10e)가 동작하도록 제어할 수 있다.
샘플링 기준은 메타데이터를 삽입할 데이터 패킷들과 각 데이터 패킷에 삽입될 메타데이터를 선택적으로 결정하기 위한 기준을 의미한다. 샘플링 기준은 비율 기반(rate based) 샘플링 기준과 이벤트 기반(event based) 샘플링 기준을 포함할 수 있다.
비율 기반 샘플링 기준은 적어도 하나 이상의 네트워크 장치(10a 내지 10e)가 전달하는 패킷들 중에서 R개(여기서, R은 자연수)의 패킷당 하나의 패킷에만 메타데이터를 삽입하도록 한다. 즉, 네트워크 장치(10a 내지 10e)가 비율 기반 샘플링 기준에 따라 동작하는 경우 R개의 패킷당 하나의 패킷에 INT 헤더를 삽입하고, 이후 INT 헤더가 삽입된 패킷에 대하여만 메타데이터가 삽입되도록 한다. 따라서, 비율 기반 샘플링 기준에 의할 경우 메타데이터가 삽입될 패킷을 선택적으로 결정하여 네트워크 오버헤드를 줄일 수 있다.
이벤트 기반 샘플링 기준은 적어도 하나 이상의 네트워크 장치(10a 내지 10e)가 기 설정된 메타데이터 기준을 만족하는 메타데이터만을 패킷에 삽입하도록 한다. 여기서, 기 설정된 메타데이터 기준은 삽입되는 메타데이터를 선택적으로 결정하기 위한 기준으로서, 예를 들면 메타데이터의 유형(type)에 대한 것일 수도 있으며, 홉 지연시간, 네트워크 장치 ID 및 큐 점유도 등과 같은 메타데이터에 대하여 설정되는 수치일 수도 있다. 보다 상세한 예로서, 홉 지연시간에 대하여 메타데이터 기준이 설정되는 경우 네트워크 장치(10a 내지 10e)에서의 홉 지연시간이 특정 수치 이상을 나타냄에 따라 네트워크 플로우에 지연을 초래한다고 판단되는 경우에만 홉 지연시간을 수집 및 패킷에 삽입할 수 있다.
도 3은 각 샘플링 기준에 따라 메타데이터가 삽입된 패킷 헤더의 구성을 도시한 것이다.
도 3을 참조하면, 비율 기반 샘플링 기준에 의하여 메타데이터를 삽입할 경우, 설정된 R값에 따라 메타데이터가 수집된다. R=2인 경우, 두 개당 하나의 비율에 해당하는 패킷에 INT 헤더가 삽입되고, 삽입된 INT 헤더의 메타데이터 정보에 해당하는 메타데이터가 패킷에 삽입된다. 또한, 나머지 하나의 패킷에는 INT 헤더가 삽입되어있지 않으므로 메타데이터 또한 삽입되지 않는다.
이벤트 기반 샘플링 기준에 의하여 메타데이터를 삽입할 경우, 기 설정된 메타데이터 기준을 만족하는 메타데이터만이 삽입된다. 여기서, 기 설정된 메타데이터 기준에 대한 정보는 패킷에 삽입된 INT 헤더에 포함될 수 있다. 한편, 네트워크 장치는 기 설정된 메타데이터 기준에 따라 어떠한 유형의 메타데이터가 삽입되었는지를 나타내기 위해 INT 헤더의 Instruction Bitmap의 예비 필드(Reserved Field)를 활용하여 Insertion bitmap에 명시한다. 따라서, 패킷의 Insertion bitmap을 통해 각 홉에서 INT Transit 노드(10a,10b,10c)에 의해 삽입되는 메타데이터의 종류를 확인할 수 있다.
한편, 상술한 실시예와는 달리 본 발명의 다른 실시예에 따른 네트워크 모니터링 시스템(1)은 상술한 모니터링 엔진(20)이 컨트롤러(30)에 통합되어 컨트롤러(30)가 모니터링 엔진(20)의 기능까지 수행하도록 구성될 수도 있다. 즉, 컨트롤러(30)는 네트워크 장치(10a 내지 10e)가 샘플링 기준에 따라 패킷에 메타데이터를 삽입하도록 제어하는 기능과 네트워크 장치(10a 내지 10e)로부터 메타데이터를 수집하여 메타데이터로 인해 발생하는 네트워크 오버헤드를 모니터링하는 기능을 함께 수행하도록 구성될 수 있다.
도 4는 본 발명의 일 실시예에 따른 네트워크 모니터링 방법의 순서도이다. 이하에서는 앞서 설명한 부분과 중복되는 부분에 대한 상세한 설명은 생략하기로 한다.
도 4를 참조하면, 본 발명의 일 실시예에 따른 네트워크 모니터링 방법은 네트워크 모니터링 시스템에 의해 수행되는 네트워크 모니터링 방법으로서, 컴파일 단계(S100), 메타데이터 삽입 단계(S200), 오버헤드 모니터링 단계(S300), 샘플링 기법 전환 단계(S400) 및 샘플링 단계(S500)를 포함한다.
S100 단계는 각 네트워크 장치가 패킷에 메타데이터를 삽입하는 INT 기법과 메타데이터를 특정 기준에 따라 샘플링하여 삽입하는 샘플링 기법이 정의된 프로그램을 네트워크 장치들에 각각 컴파일하는 단계이다. 컴파일은 SDN 환경일 경우 컨트롤러에 의해 수행될 수 있다.
S200 단계는 컴파일된 INT 기법에 따라 호스트 간에 전달되는 패킷에 네트워크 모니터링을 위한 메타데이터를 패킷에 삽입하는 단계이다. 메타데이터의 삽입은 INT Source 노드, INT Transit 노드 및 INT Sink 노드 각각에서 모두 수행될 수 있다. 또한, INT Source 노드에서는 호스트로부터 패킷을 수신하면 메타데이터 삽입 이전에 INT 헤더를 패킷에 삽입한다. 이에 따라, 패킷을 전달받는 INT Transit 노드와 INT Sink 노드에서는 INT 헤더에 포함된 INT Instruction bitmap을 참조하여 메타데이터를 수집할 수 있다.
S300 단계는 각 네트워크 장치로부터 메타데이터를 수집하여 메타데이터로 인해 발생하는 네트워크 오버헤드를 모니터링하는 단계이다. 네트워크 오버헤드는 경로의 길이가 증가할수록, 패킷에 삽입되는 메타데이터가 많아질수록 증가하게 된다. 따라서, 이러한 네트워크 오버헤드를 모니터링하여 네트워크의 성능 저하를 방지할 필요성이 있다. 또한, S300 단계에서는 메타데이터로 인해 발생하는 네트워크 오버헤드가 기 설정된 모니터링 기준을 만족하는지 여부를 지속적으로 판단한다(S350).
오버헤드 모니터링 단계에서 메타데이터로 인해 발생하는 네트워크 오버헤드가 기 설정된 모니터링 기준을 만족하는 것으로 판단될 경우, S400 단계에서는 네트워크 장치가 샘플링 기준에 따라 패킷에 메타데이터를 삽입하도록 제어한다. 즉, S400 단계에서 컨트롤러는 네트워크 장치가 S100 단계를 통해 컴파일된 샘플링 기법에 따라 메타데이터를 수집하고, 패킷에 수집된 메타데이터를 삽입하도록 네트워크 장치의 동작을 전환한다. 여기서, 샘플링 기준은 상술한 바와 같이 비율 기반 샘플링 기준 및 이벤트 기반 샘플링 기준을 포함할 수 있다.
또한, S400 단계는 네트워크 환경 및 모니터링 목적 중 적어도 어느 하나를 고려하여 상술한 샘플링 기준 중 어느 하나를 최적의 샘플링 기준으로서 선택하는 단계를 더 포함할 수도 있다. 이를 위하여, 샘플링 기준을 선택하는 단계는 각 샘플링 기준을 네트워크 장치에 적용시 발생할 수 있는 네트워크 오버헤드를 계산하고, 계산된 네트워크 오버헤드를 비교하여 보다 적은 네트워크 오버헤드를 가질 때의 샘플링 기준을 선택하여 선택된 최적의 샘플링 기준에 따라 네트워크 장치가 동작하도록 할 수 있다.
S500 단계는 S400 단계에 의해 동작이 전환된 네트워크 장치가 INT 기법이 아닌 샘플링 기준에 따라 메타데이터를 수집하고, 패킷에 삽입하는 단계이다. 즉, S200 단계 내지 S300 단계에서는 네트워크 장치가 INT 기법에 의하여 메타데이터를 수집하고, 이를 모니터링하다가 S400 단계에 의해 INT 기법에서 샘플링 기법으로 전환되면 샘플링 기법에 의하여 메타데이터를 수집하고, 이를 모니터링하게 된다. 또한, S500 단계 이후에 네트워크 오버헤드가 감소하였을 경우 적용된 샘플링 기준을 계속 유지할 수도 있으며, 그로 인해 측정 정확도가 떨어진 것으로 모니터링될 경우 다시 샘플링 기준 적용을 해제하고 기존의 INT 기법에 따라 동작하도록 네트워크 장치의 동작을 전환할 수도 있다.
도 5는 경로의 길이에 따른 각 INT 기법들의 네트워크 오버헤드의 변화를 설명하기 위한 도면이다.
도 5를 참조하면, INT는 기존의 INT 기법에 의한 네트워크 오버헤드(즉, 프로토콜 오버헤드)를 의미하고, R-INT는 본 발명에서 제안된 비율 기반 샘플링 기법에 의한 네트워크 오버헤드를 의미하고, DBS-INT는 본 발명에서 제안된 비율 기반 이벤트 기반 샘플링 기법에 의한 네트워크 오버헤드를 의미한다. 대체로 네트워크 오버헤드는 경로의 길이(즉, 홉의 수)가 증가함에 따라 패킷에 삽입되는 메타데이터의 비율이 증가하므로 함께 증가한다. 또한, 기존의 INT 기법에 비하여 메타데이터로 인해 발생하는 네트워크 오버헤드가 절반 이상으로 감소한 것을 확인할 수 있다. 이는 본 발명의 일 실시예에 따른 네트워크 모니터링 시스템 및 방법의 경우 모든 메타데이터를 수집 및 삽입하는 것이 아니라, 기 설정된 샘플링 기준에 따라 효율적으로 메타데이터를 수집 및 삽입하기 때문이다.
아래의 표 1은 경로의 길이에 따른 각 INT 기법들의 평균 홉 지연시간을 측정한 것이다.
| Path Length | 10 | 20 | 30 |
| INT | 11.87[ms] | 10.7[ms] | 10.16[ms] |
| R-INT (R=4) | 10.28[ms] | 9.22[ms] | 9.15[ms] |
| DBS-INT (△=30[ms]) | 11.85[ms] | 10.25[ms] | 10.03[ms] |
표 1을 참조하면, DBS-INT 기법에 의해 관측된 평균 홉 지연시간은 기존의 INT 기법에 의해 관측된 값과 유사한 것을 확인할 수 있다. 홉 지연시간을 타겟으로 하는 DBS-INT 기법의 메타데이터에는 이벤트 기반으로 수집되는 홉 지연시간을 저장하는 필드가 존재한다. 매 홉에서 이 필드의 값과 현재 네트워크 장치에서의 홉 지연시간과의 차이를 계산하고, 계산된 값이 기 설정된 홉 지연시간의 임계값(즉, 기 설정된 메타데이터 기준)을 벗어나는 경우에만 필드를 업데이트한다. 즉, 수집되지 않은 홉 지연시간은 수집된 홉 지연시간과의 차이가 크지 않다는 것을 의미한다. 따라서, 본 발명의 일 실시예에 따른 네트워크 모니터링 시스템 및 방법은 단순히 샘플링 횟수를 감소시킨 R-INT 기법만을 사용하는 것이 아니라, DBS-INT 기법과 함께 샘플링 기법을 유연하게 사용하여 기존의 INT를 통해 얻을 수 있는 정보와 유사한 결과를 얻을 수 있다.
이상에서 설명된 장치는 하드웨어 구성요소, 소프트웨어 구성요소, 및/또는 하드웨어 구성요소 및 소프트웨어 구성요소의 조합으로 구현될 수 있다. 예를 들어, 실시예들에서 설명된 장치 및 구성요소는, 예를 들어, 프로세서, 콘트롤러, ALU(arithmetic logic unit), 디지털 신호 프로세서(digital signal processor), 마이크로컴퓨터, FPA(field programmable array), PLU(programmable logic unit), 마이크로프로세서, 또는 명령(instruction)을 실행하고 응답할 수 있는 다른 어떠한 장치와 같이, 하나 이상의 범용 컴퓨터 또는 특수 목적 컴퓨터를 이용하여 구현될 수 있다. 처리 장치는 운영 체제(OS) 및 상기 운영 체제상에서 수행되는 하나 이상의 소프트웨어 애플리케이션을 수행할 수 있다. 또한, 처리 장치는 소프트웨어의 실행에 응답하여, 데이터를 접근, 저장, 조작, 처리 및 생성할 수도 있다. 이해의 편의를 위하여, 처리 장치는 하나가 사용되는 것으로 설명된 경우도 있지만, 해당 기술분야에서 통상의 지식을 가진 자는, 처리 장치가 복수 개의 처리 요소(processing element) 및/또는 복수 유형의 처리 요소를 포함할 수 있음을 알 수 있다. 예를 들어, 처리 장치는 복수 개의 프로세서 또는 하나의 프로세서 및 하나의 콘트롤러를 포함할 수 있다. 또한, 병렬 프로세서(parallel processor)와 같은, 다른 처리 구성(processing configuration)도 가능하다.
소프트웨어는 컴퓨터 프로그램(computer program), 코드(code), 명령(instruction), 또는 이들 중 하나 이상의 조합을 포함할 수 있으며, 원하는 대로 동작하도록 처리 장치를 구성하거나 독립적으로 또는 결합적으로(collectively) 처리 장치를 명령할 수 있다. 소프트웨어 및/또는 데이터는, 처리 장치에 의하여 해석되거나 처리 장치에 명령 또는 데이터를 제공하기 위하여, 어떤 유형의 기계, 구성요소(component), 물리적 장치, 가상 장치(virtual equipment), 컴퓨터 저장 매체 또는 장치, 또는 전송되는 신호 파(signal wave)에 영구적으로, 또는 일시적으로 구체화(embody)될 수 있다. 소프트웨어는 네트워크로 연결된 컴퓨터 시스템 상에 분산되어서, 분산된 방법으로 저장되거나 실행될 수도 있다. 소프트웨어 및 데이터는 하나 이상의 컴퓨터 판독 가능 기록 매체에 저장될 수 있다.
실시예에 따른 방법은 다양한 컴퓨터 수단을 통하여 수행될 수 있는 프로그램 명령 형태로 구현되어 컴퓨터 판독 가능 매체에 기록될 수 있다. 상기 컴퓨터 판독 가능 매체는 프로그램 명령, 데이터 파일, 데이터 구조 등을 단독으로 또는 조합하여 포함할 수 있다. 상기 매체에 기록되는 프로그램 명령은 실시예를 위하여 특별히 설계되고 구성된 것들이거나 컴퓨터 소프트웨어 당업자에게 공지되어 사용 가능한 것일 수도 있다. 컴퓨터 판독 가능 기록 매체의 예에는 하드 디스크, 플로피 디스크 및 자기 테이프와 같은 자기 매체(magnetic media), CD-ROM, DVD와 같은 광기록 매체(optical media), 플롭티컬 디스크(floptical disk)와 같은 자기-광 매체(magneto-optical media), 및 롬(ROM), 램(RAM), 플래시 메모리 등과 같은 프로그램 명령을 저장하고 수행하도록 특별히 구성된 하드웨어 장치가 포함된다. 프로그램 명령의 예에는 컴파일러에 의해 만들어지는 것과 같은 기계어 코드뿐만 아니라 인터프리터 등을 사용해서 컴퓨터에 의해서 실행될 수 있는 고급 언어 코드를 포함한다. 상기된 하드웨어 장치는 실시예의 동작을 수행하기 위해 하나 이상의 소프트웨어 모듈로서 작동하도록 구성될 수 있으며, 그 역도 마찬가지이다.
이상과 같이 실시예들이 비록 한정된 도면에 의해 설명되었으나, 해당 기술분야에서 통상의 지식을 가진 자라면 상기의 기재로부터 다양한 수정 및 변형이 가능하다. 예를 들어, 설명된 기술들이 설명된 방법과 다른 순서로 수행되거나, 및/또는 설명된 시스템, 구조, 장치, 회로 등의 구성요소들이 설명된 방법과 다른 형태로 결합 또는 조합되거나, 다른 구성요소 또는 균등물에 의하여 대치되거나 치환되더라도 적절한 결과가 달성될 수 있다.
그러므로, 다른 구현들, 다른 실시예들 및 특허청구범위와 균등한 것들도 후술하는 특허청구범위의 범위에 속한다.
Claims (9)
- 호스트 간에 패킷을 전달하고, 상기 패킷을 전달하는 과정에서 네트워크 모니터링을 위한 메타데이터(metadata)를 상기 패킷에 삽입하는 적어도 하나 이상의 네트워크 장치;상기 적어도 하나 이상의 네트워크 장치로부터 상기 메타데이터를 수집하여 상기 메타데이터로 인해 발생하는 네트워크 오버헤드를 모니터링하는 모니터링 엔진; 및상기 네트워크 오버헤드가 기 설정된 모니터링 기준을 만족할 경우 상기 적어도 하나 이상의 네트워크 장치가 샘플링 기준에 따라 상기 패킷에 상기 메타데이터를 삽입하도록 제어하는 컨트롤러를 포함하는 네트워크 모니터링 시스템.
- 제1항에 있어서,상기 컨트롤러는 상기 적어도 하나 이상의 네트워크 장치가 비율 기반(rate based) 샘플링 기준 또는 이벤트 기반(event based) 샘플링 기준에 따라 동작하도록 제어하는 네트워크 모니터링 시스템.
- 제2항에 있어서,상기 비율 기반 샘플링 기준은 상기 적어도 하나 이상의 네트워크 장치가 전달하는 패킷들 중에서 R개의 패킷당 하나의 패킷에만 상기 메타데이터를 삽입하도록 하는 네트워크 모니터링 시스템.여기서, R은 자연수임.
- 제2항에 있어서,상기 이벤트 기반 샘플링 기준은 상기 적어도 하나 이상의 네트워크 장치가 기 설정된 메타데이터 기준을 만족하는 메타데이터만을 상기 패킷에 삽입하도록 하는 네트워크 모니터링 시스템.
- 제4항에 있어서,상기 기 설정된 메타데이터 기준은 홉 지연시간(hop latency), 네트워크 장치 ID 및 큐 점유도(queue occupancy) 중 적어도 어느 하나에 대한 기준인 네트워크 모니터링 시스템.
- 제2항에 있어서,상기 컨트롤러는 트래픽 변화량이 기 설정된 임계값 미만인 경우 상기 적어도 하나 이상의 네트워크 장치가 상기 비율 기반 샘플링 기준에 따라 동작하도록 제어하고, 트래픽 변화량이 기 설정된 임계값 이상인 경우 상기 적어도 하나 이상의 네트워크 장치가 상기 이벤트 기반 샘플링 기준에 따라 동작하도록 제어하는 네트워크 모니터링 시스템.
- 네트워크 모니터링 시스템에 의해 수행되는 네트워크 모니터링 방법으로서,호스트 간에 전달되는 패킷에 네트워크 모니터링을 위한 메타데이터(metadata)를 상기 패킷에 삽입하는 단계;상기 메타데이터를 수집하여 상기 메타데이터로 인해 발생하는 네트워크 오버헤드를 모니터링하는 단계;상기 네트워크 오버헤드가 기 설정된 모니터링 기준을 만족할 경우 샘플링 기준에 따라 상기 패킷에 상기 메타데이터를 삽입하도록 적어도 하나 이상의 네트워크 장치를 제어하는 단계; 및상기 샘플링 기준에 따라 상기 메타데이터를 상기 패킷에 삽입하는 단계를 포함하는 네트워크 모니터링 방법.
- 제7항에 있어서,비율 기반(rate based) 샘플링 기준 또는 이벤트 기반(event based) 샘플링 기준 중 최적의 샘플링 기준을 선택하는 단계를 더 포함하고,상기 적어도 하나 이상의 네트워크 장치를 제어하는 단계는, 상기 적어도 하나 이상의 네트워크 장치가 상기 최적의 샘플링 기준에 따라 상기 패킷에 상기 메타데이터를 삽입하도록 제어하고,상기 메타데이터를 상기 패킷에 삽입하는 단계는, 상기 최적의 샘플링 기준에 따라 상기 메타데이터를 상기 패킷에 삽입하는 네트워크 모니터링 방법.
- 제8항에 있어서,상기 비율 기반 샘플링 기준은 상기 적어도 하나 이상의 네트워크 장치가 전달하는 패킷들 중에서 R개의 패킷당 하나의 패킷에만 상기 메타데이터를 삽입하도록 하고,상기 이벤트 기반 샘플링 기준은 상기 적어도 하나 이상의 네트워크 장치가 기 설정된 메타데이터 기준을 만족하는 메타데이터만을 상기 패킷에 삽입하도록 하는 네트워크 모니터링 방법.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| KR1020180145463A KR102071371B1 (ko) | 2018-11-22 | 2018-11-22 | 샘플링 기법을 이용한 네트워크 트래픽 모니터링 시스템 및 방법 |
| KR10-2018-0145463 | 2018-11-22 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2020106105A1 true WO2020106105A1 (ko) | 2020-05-28 |
Family
ID=69321306
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/KR2019/016156 Ceased WO2020106105A1 (ko) | 2018-11-22 | 2019-11-22 | 샘플링 기법을 이용한 네트워크 트래픽 모니터링 시스템 및 방법 |
Country Status (2)
| Country | Link |
|---|---|
| KR (1) | KR102071371B1 (ko) |
| WO (1) | WO2020106105A1 (ko) |
Families Citing this family (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN115885503B (zh) * | 2020-07-15 | 2024-09-20 | 华为技术有限公司 | 利用网络内int采样和聚合进行实时全网链路延迟监控 |
| KR20250128636A (ko) | 2024-02-21 | 2025-08-28 | 고려대학교 산학협력단 | 6g 코어 망에서의 nf 간 int 아이템별 샘플링 비율 결정 장치 및 방법 |
| KR20250137300A (ko) | 2024-03-11 | 2025-09-18 | 고려대학교 산학협력단 | 인-밴드 네트워크 텔레메트리 아이템 인코딩 장치 및 방법 |
| KR102890093B1 (ko) | 2024-03-11 | 2025-11-24 | 고려대학교 산학협력단 | 6g 코어망에서의 네트워크 기능 간 int 인코딩 아이템 전송 처리 장치 및 방법 |
| KR20250137305A (ko) | 2024-03-11 | 2025-09-18 | 고려대학교 산학협력단 | 6g 코어 망에서의 nf 간 int 아이템별 샘플링 비율을 고려한 확률론적 모니터링 장치 및 방법 |
| KR20250148272A (ko) | 2024-04-05 | 2025-10-14 | 고려대학교 산학협력단 | 6g 코어 망에서의 네트워크 기능 간 다중 인-밴드 네트워크 텔레메트리 데이터 인코딩 장치 및 방법 |
| KR20250159849A (ko) | 2024-05-03 | 2025-11-11 | 고려대학교 산학협력단 | 6g 코어 망에서의 네트워크 이상 탐지를 위한 선택적 인-밴드 네트워크 텔레메트리 데이터 수집 장치 및 방법 |
| KR20260019940A (ko) | 2024-08-02 | 2026-02-10 | 고려대학교 산학협력단 | 6g 코어 망에서의 혼잡 정도에 따른 동적 인-밴드 네트워크 텔레메트리 수집 장치 및 방법 |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR20080001303A (ko) * | 2006-06-29 | 2008-01-03 | 주식회사 케이티 | Ip망에서 플로우를 이용한 트래픽 분석장치 및 그 방법 |
| KR20120028745A (ko) * | 2010-09-15 | 2012-03-23 | 한국전자통신연구원 | 메타데이터 분류를 이용한 패킷 검사 방법 및 그 장치 |
| US20140090058A1 (en) * | 2012-08-31 | 2014-03-27 | Damballa, Inc. | Traffic simulation to identify malicious activity |
Family Cites Families (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR100870182B1 (ko) | 2007-04-05 | 2008-11-25 | 삼성전자주식회사 | L2/l3 기반 라우터쌍의 플로우 별 트래픽 양 추정시스템 및 방법 |
| US10044583B2 (en) | 2015-08-21 | 2018-08-07 | Barefoot Networks, Inc. | Fast detection and identification of lost packets |
-
2018
- 2018-11-22 KR KR1020180145463A patent/KR102071371B1/ko active Active
-
2019
- 2019-11-22 WO PCT/KR2019/016156 patent/WO2020106105A1/ko not_active Ceased
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR20080001303A (ko) * | 2006-06-29 | 2008-01-03 | 주식회사 케이티 | Ip망에서 플로우를 이용한 트래픽 분석장치 및 그 방법 |
| KR20120028745A (ko) * | 2010-09-15 | 2012-03-23 | 한국전자통신연구원 | 메타데이터 분류를 이용한 패킷 검사 방법 및 그 장치 |
| US20140090058A1 (en) * | 2012-08-31 | 2014-03-27 | Damballa, Inc. | Traffic simulation to identify malicious activity |
Non-Patent Citations (2)
| Title |
|---|
| TAL MIZRAHI , ET. AL.: "Network Telemetry Solutions for Data Center and Enterprise Networks", WHITE PAPER , MARVELL, 20 March 2018 (2018-03-20), pages 3 - 4, 6-8, XP055710056, Retrieved from the Internet <URL:https://www.researchgate.net/publication/323884683> [retrieved on 20200220] * |
| VINH HAO NGUYEN -§: "Networked Estimation for Event-Based Sampling Systems with Packet Dropouts", SENSORS, 24 April 2009 (2009-04-24), XP055710061, Retrieved from the Internet <URL:https://www.researchgate.net/publication/224933984> [retrieved on 20200220], DOI: 10.3390/s90403078 * |
Also Published As
| Publication number | Publication date |
|---|---|
| KR102071371B1 (ko) | 2020-01-30 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| KR102071371B1 (ko) | 샘플링 기법을 이용한 네트워크 트래픽 모니터링 시스템 및 방법 | |
| JP7035227B2 (ja) | データパケット検出方法、デバイス、及びシステム | |
| US6510135B1 (en) | Flow-level demultiplexing within routers | |
| US6952396B1 (en) | Enhanced dual counter rotating ring network control system | |
| US7145867B2 (en) | System and method for slot deflection routing | |
| US8243729B2 (en) | Multiple chassis stacking using front end ports | |
| US20120320929A9 (en) | Packet forwarding using multiple stacked chassis | |
| CN101971575B (zh) | 链形和环形网络中用于透明自动恢复的方法和装置 | |
| EP2652923B1 (en) | Communication path control system, path control device, communication path control method, and path control program | |
| US20100172365A1 (en) | HiGig AUTOTRUNKING | |
| EP0926859B1 (en) | Multiple virtual router | |
| US6205121B1 (en) | Method of establishing logical connections in a synchronous digital communications network, as well as network elements and management system | |
| EP2924934B1 (en) | Ethernet switch and method for establishing forwarding patterns in an ethernet switch | |
| EP2613480A1 (en) | Communication quality monitoring system, communication quality monitoring method, and storage medium | |
| AU1675901A (en) | Data channel reservation in optical burst-switched networks | |
| US20030031177A1 (en) | Systems and methods for exchanging information between optical nodes | |
| KR101228284B1 (ko) | 데이타 통신 시스템 및 방법 | |
| US7307995B1 (en) | System and method for linking a plurality of network switches | |
| CA2341939C (en) | Label request packet transmission method, packet transfer network and method thereof, and packet transfer device | |
| WO2020055149A1 (ko) | 데이터센터 네트워크의 부하 균형을 위한 신용 기반 다중경로 데이터 전송 방법 | |
| US11381419B2 (en) | Communication network | |
| JP2002504793A (ja) | 仮想接続の保護切替 | |
| JP2004505527A (ja) | 通信システム | |
| US6985443B2 (en) | Method and apparatus for alleviating traffic congestion in a computer network | |
| Narula-Tam et al. | Analysis of reconfiguration in IP over WDM access networks |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 19887084 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 19887084 Country of ref document: EP Kind code of ref document: A1 |