Characterizing the trade-off between network monitoring and network overload

Operators of networks are interested in performance anomalies that may occur, e.g., timing problems or traffic loss. To detect such anomalies, probing devices can be placed throughout the network; these devices can send test packets to each other, measure properties of the transmission (e.g., delay), and alert the operator when something abnormal is detected. However, there is a trade-off among the number of probe devices, amount of test traffic, and overhead that negatively affects regular network traffic. Some work [1] has been done on algorithms to choose locations for probing devices such that the paths between the devices adequately cover the network). However, this work is only one of many possible ways to approach the trade-off between adequate probing and network overhead. The purpose of this project is to work towards characterizing this trade-off by (1) formalizing metrics by which to evaluate probing strategies and (2) identifying example strategies and studying their effects on such metrics.

This project is related to the project Mitigating Exploits of the Current Interdomain Routing Infrastructure at Rutgers and Colgate.