PSSketch: Finding Persistent and Sparse Flow with High Accuracy and Efficiency

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wang, Jiayao, Shi, Qilong, Liang, Xiyan, Wang, Han, Li, Wenjun, Wei, Ziling, Zhang, Weizhe, Chen, Shuhui
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916726062448640
author Wang, Jiayao
Shi, Qilong
Liang, Xiyan
Wang, Han
Li, Wenjun
Wei, Ziling
Zhang, Weizhe
Chen, Shuhui
author_facet Wang, Jiayao
Shi, Qilong
Liang, Xiyan
Wang, Han
Li, Wenjun
Wei, Ziling
Zhang, Weizhe
Chen, Shuhui
contents Finding persistent sparse (PS) flow is critical to early warning of many threats. Previous works have predominantly focused on either heavy or persistent flows, with limited attention given to PS flows. Although some recent studies pay attention to PS flows, they struggle to establish an objective criterion due to insufficient data-driven observations, resulting in reduced accuracy. In this paper, we define a new criterion "anomaly boundary" to distinguish PS flows from regular flows. Specifically, a flow whose persistence exceeds a threshold will be protected, while a protected flow with a density lower than a threshold is reported as a PS flow. We then introduce PSSketch, a high-precision layered sketch to find PS flows. PSSketch employs variable-length bitwise counters, where the first layer tracks the frequency and persistence of all flows, and the second layer protects potential PS flows and records overflow counts from the first layer. Some optimizations have also been implemented to reduce memory consumption further and improve accuracy. The experiments show that PSSketch reduces memory consumption by an order of magnitude compared to the strawman solution combined with existing work. Compared with SOTA solutions for finding PS flows, it outperforms up to 2.94x in F1 score and reduces ARE by 1-2 orders of magnitude. Meanwhile, PSSketch achieves a higher throughput than these solutions.
format Preprint
id arxiv_https___arxiv_org_abs_2505_04892
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle PSSketch: Finding Persistent and Sparse Flow with High Accuracy and Efficiency
Wang, Jiayao
Shi, Qilong
Liang, Xiyan
Wang, Han
Li, Wenjun
Wei, Ziling
Zhang, Weizhe
Chen, Shuhui
Data Structures and Algorithms
Finding persistent sparse (PS) flow is critical to early warning of many threats. Previous works have predominantly focused on either heavy or persistent flows, with limited attention given to PS flows. Although some recent studies pay attention to PS flows, they struggle to establish an objective criterion due to insufficient data-driven observations, resulting in reduced accuracy. In this paper, we define a new criterion "anomaly boundary" to distinguish PS flows from regular flows. Specifically, a flow whose persistence exceeds a threshold will be protected, while a protected flow with a density lower than a threshold is reported as a PS flow. We then introduce PSSketch, a high-precision layered sketch to find PS flows. PSSketch employs variable-length bitwise counters, where the first layer tracks the frequency and persistence of all flows, and the second layer protects potential PS flows and records overflow counts from the first layer. Some optimizations have also been implemented to reduce memory consumption further and improve accuracy. The experiments show that PSSketch reduces memory consumption by an order of magnitude compared to the strawman solution combined with existing work. Compared with SOTA solutions for finding PS flows, it outperforms up to 2.94x in F1 score and reduces ARE by 1-2 orders of magnitude. Meanwhile, PSSketch achieves a higher throughput than these solutions.
title PSSketch: Finding Persistent and Sparse Flow with High Accuracy and Efficiency
topic Data Structures and Algorithms
url https://arxiv.org/abs/2505.04892