We present a per-flow packet sampling method that enables the real-time classification of high-speed network traffic. Our method, based upon the partial sampling of each flow (i.e., performing sampling at only early stages in each flow's lifetime), provides a sufficient reduction in total traffic (e.g., a factor of five in packets, a factor of ten in bytes) as to allow practical implementations at one Gigabit/s, and, using limited hardware assistance, ten Gigabit/s.
Canini, M., Fay, D., Miller, D. J., Moore, A. W., & Bolla, R. (2009). Per Flow Packet Sampling for High-Speed Network Monitoring. Proceedings of the First International Conference on Communication Systems And NETworks. Published. COMSNETS ’09. https://doi.org/10.1109/COMSNETS.2009.4808888