{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,25]],"date-time":"2026-04-25T08:36:07Z","timestamp":1777106167344,"version":"3.51.4"},"reference-count":45,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2023,5,26]],"date-time":"2023-05-26T00:00:00Z","timestamp":1685059200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100001809","name":"The National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["No. 61972189"],"award-info":[{"award-number":["No. 61972189"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"name":"The National Key Research and Development Program of China","award":["No. 2020YFB1804704"],"award-info":[{"award-number":["No. 2020YFB1804704"]}]},{"name":"The Major Key Project of PCL","award":["No. PCL2021A03-1"],"award-info":[{"award-number":["No. PCL2021A03-1"]}]},{"name":"Shenzhen Science and Technology Innovation Commission: Research Center for Computer Network (Shenzhen) Ministry of Education, and the Shenzhen Key Lab of Software Defined Networking","award":["No. ZDSYS20140509172959989"],"award-info":[{"award-number":["No. ZDSYS20140509172959989"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Proc. ACM Manag. Data"],"published-print":{"date-parts":[[2023,5,26]]},"abstract":"<jats:p>The bumps and dips in data streams are valuable patterns for data mining and networking scenarios such as online advertising and botnet detection. In this paper, we define the wave, a data stream pattern with a serious deviation from the stable arrival rate for a period of time. We then propose Pontus, an efficient framework for wave detection and estimation. In Pontus, a lightweight data structure is utilized for the preliminary processing of incoming packets in the data plane to take advantage of its high processing speed; then, the powerful control plane carries out computationally intensive wave detection and estimation. In particular, we propose the Multi-Stage Progressive Tracking strategy which detects waves in stages and removes any disqualified items promptly to save memory. Hash collisions are addressed by a Stage Variance Maximization technique to reduce estimation error. Moreover, we prove the theoretical error bound and establish upper bounds of false positive and false negative. Experiment results show that the software version of Pontus can achieve around 97% F1-Score even under scarce memory when baselines fail. Furthermore, the implemented prototype of Pontus based on P4 achieves 842x higher throughput than the baseline strawman solution.<\/jats:p>","DOI":"10.1145\/3588960","type":"journal-article","created":{"date-parts":[[2023,5,30]],"date-time":"2023-05-30T17:42:05Z","timestamp":1685468525000},"page":"1-26","source":"Crossref","is-referenced-by-count":5,"title":["Pontus: Finding Waves in Data Streams"],"prefix":"10.1145","volume":"1","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1578-2597","authenticated-orcid":false,"given":"Zhengxin","family":"Zhang","sequence":"first","affiliation":[{"name":"Tsinghua University &amp; Peng Cheng Laboratory, Shenzhen, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6071-473X","authenticated-orcid":false,"given":"Qing","family":"Li","sequence":"additional","affiliation":[{"name":"Peng Cheng Laboratory, Shenzhen, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-4917-9536","authenticated-orcid":false,"given":"Guanglin","family":"Duan","sequence":"additional","affiliation":[{"name":"Tsinghua University &amp; Peng Cheng Laboratory, Shenzhen, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9016-5594","authenticated-orcid":false,"given":"Dan","family":"Zhao","sequence":"additional","affiliation":[{"name":"Peng Cheng Laboratory, Shenzhen, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2394-2995","authenticated-orcid":false,"given":"Jingyu","family":"Xiao","sequence":"additional","affiliation":[{"name":"Tsinghua University &amp; Peng Cheng Laboratory, Shenzhen, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7532-9116","authenticated-orcid":false,"given":"Guorui","family":"Xie","sequence":"additional","affiliation":[{"name":"Tsinghua University &amp; Peng Cheng Laboratory, Shenzhen, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4260-1395","authenticated-orcid":false,"given":"Yong","family":"Jiang","sequence":"additional","affiliation":[{"name":"Tsinghua Shenzhen International School &amp; Peng Cheng Laboratory, Shenzhen, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,5,30]]},"reference":[{"key":"e_1_2_2_1_1","unstructured":"Aditya Akella Theophilus Benson. 2010. Data center dataset. https:\/\/pages.cs.wisc.edu\/~tbenson\/IMC10_Data.html. (2010)."},{"key":"e_1_2_2_2_1","volume-title":"26th USENIX Security Symposium, USENIX Security","author":"Antonakakis Manos","year":"2017","unstructured":"Manos Antonakakis and Tim April. 2017. Understanding the mirai botnet. In 26th USENIX Security Symposium, USENIX Security 2017, 1093--1110."},{"key":"e_1_2_2_3_1","unstructured":"Barefoot Networks. 2021. Tofino switch. https:\/\/www.barefootnetworks.com\/products\/brief-tofino. (2021)."},{"key":"e_1_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2017.8057215"},{"key":"e_1_2_2_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/2656877.2656890"},{"key":"e_1_2_2_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/2486001.2486011"},{"key":"e_1_2_2_7_1","unstructured":"Caida. 2019. Anonymized 2019 internet traces. http:\/\/www.caida.org\/data\/overview\/. (2019)."},{"key":"e_1_2_2_8_1","volume-title":"29th International Colloquium, ICALP 2002, Proceedings, 693--703","author":"Charikar Moses","unstructured":"Moses Charikar and Kevin C. Chen. 2002. Finding frequent items in data streams. In Automata, Languages and Programming, 29th International Colloquium, ICALP 2002, Proceedings, 693--703."},{"key":"e_1_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3448016.3452784"},{"key":"e_1_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.5555\/1116162.1116196"},{"key":"e_1_2_2_11_1","unstructured":"Cloudflare DDoS Team. 2021. Meris botnet. https:\/\/radar.cloudflare.com\/notebooks\/meris-botnet#meris_attacks_over_time. (2021)."},{"key":"e_1_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jalgor.2003.12.001"},{"key":"e_1_2_2_13_1","first-page":"1","article-title":"Intentional network monitoring: finding the needle without capturing the haystack. In Proceedings of the 13th ACM Workshop on Hot Topics in Networks","volume":"5","author":"Donovan Sean Patrick","year":"2014","unstructured":"Sean Patrick Donovan and Nick Feamster. 2014. Intentional network monitoring: finding the needle without capturing the haystack. In Proceedings of the 13th ACM Workshop on Hot Topics in Networks, HotNets-XIII, 5:1--5:7.","journal-title":"HotNets-XIII"},{"key":"e_1_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/948205.948225"},{"key":"e_1_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/633025.633056"},{"key":"e_1_2_2_16_1","doi-asserted-by":"crossref","unstructured":"Flajolet and Philippe. 2007. Hyperloglog: the analysis of a near-optimal cardinality estimation algorithm. In Discrete Mathematics and Theoretical Computer Science 137--156.","DOI":"10.46298\/dmtcs.3545"},{"key":"e_1_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1016\/0022-0000(85)90041-8"},{"key":"e_1_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/2987443.2987483"},{"key":"e_1_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/948205.948227"},{"key":"e_1_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3359989.3365433"},{"key":"e_1_2_2_21_1","unstructured":"Robert J. Jenkins Jr. 1995. Bob hash website. http:\/\/burtleburtle.net\/bob\/hash\/evahash.html. (1995)."},{"key":"e_1_2_2_22_1","volume-title":"IEEE 57th Annual Symposium on Foundations of Computer Science, FOCS 2016, 71--78","author":"Karnin Z.","unstructured":"Z.Karnin and K. Lang. 2016. Optimal quantile approximation in streams. In IEEE 57th Annual Symposium on Foundations of Computer Science, FOCS 2016, 71--78."},{"key":"e_1_2_2_23_1","volume-title":"Proceedings of the Freenix Track: 2000 USENIX Annual Technical Conference, 263--270","author":"Kenjiro Cho Koushirou Mitsuya","year":"2000","unstructured":"Koushirou Mitsuya Kenjiro Cho. 2000. Traffic data repository at the wide project. In Proceedings of the Freenix Track: 2000 USENIX Annual Technical Conference, 263--270."},{"key":"e_1_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3482898.3483357"},{"key":"e_1_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/775047.775061"},{"key":"e_1_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1016\/0167-4048(86)90016-7"},{"key":"e_1_2_2_27_1","volume-title":"10th International Conference, Proceedings, 398--412","author":"Metwally Ahmed","year":"2005","unstructured":"Ahmed Metwally and Divyakant Agrawal. 2005. Efficient computation of frequent and top-k elements in data streams. In Database Theory - ICDT 2005, 10th International Conference, Proceedings, 398--412."},{"key":"e_1_2_2_28_1","volume-title":"19th USENIX Symposium on Networked Systems Design and Implementation, NSDI","author":"Miao Congcong","year":"2022","unstructured":"Congcong Miao and Jingyu Xiao. 2022. Detecting ephemeral optical events with optel. In 19th USENIX Symposium on Networked Systems Design and Implementation, NSDI 2022, 339--353."},{"key":"e_1_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.2019.00124"},{"key":"e_1_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.5555\/1603899.1603924"},{"key":"e_1_2_2_31_1","volume-title":"10th International Conference, DASFAA 2005, Proceedings, 435--446","author":"Qin Shouke","year":"2005","unstructured":"Shouke Qin and Weining Qian. 2005. Adaptively detecting aggregation bursts in data streams. In Database Systems for Advanced Applications, 10th International Conference, DASFAA 2005, Proceedings, 435--446."},{"key":"e_1_2_2_32_1","volume-title":"Proceedings of the 22nd International Conference on Data Engineering, ICDE 2006, 67--67","author":"Qin Shouke","year":"2006","unstructured":"Shouke Qin and Weining Qian. 2006. Approximately processing multi-granularity aggregate queries over data streams. In Proceedings of the 22nd International Conference on Data Engineering, ICDE 2006, 67--67."},{"key":"e_1_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1002\/spe.576"},{"key":"e_1_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.5555\/645382.651657"},{"key":"e_1_2_2_35_1","volume-title":"Proceedings of the 10th ACM SIGCOMM Internet Measurement Conference, IMC 2010, 267--280","author":"Theophilus Benson Aditya Akella","year":"2010","unstructured":"Aditya Akella Theophilus Benson. 2010. Network traffic characteristics of data centers in the wild. In Proceedings of the 10th ACM SIGCOMM Internet Measurement Conference, IMC 2010, 267--280."},{"key":"e_1_2_2_36_1","volume-title":"Proceedings of the Network and Distributed System Security Symposium, NDSS","author":"Venkataraman Shobha","year":"2005","unstructured":"Shobha Venkataraman and Dawn Xiaodong Song. 2005. New streaming algorithms for fast detection of superspreaders. In Proceedings of the Network and Distributed System Security Symposium, NDSS 2005."},{"key":"e_1_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.14778\/2732219.2732220"},{"key":"e_1_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2013.86"},{"key":"e_1_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2662369"},{"key":"e_1_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.14778\/3425879.3425884"},{"key":"e_1_2_2_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3452296.3472892"},{"key":"e_1_2_2_42_1","unstructured":"Zhengxin Zhang. 2022. Source code of pontus. https:\/\/github.com\/YouAreSpecialToMe\/Pontus. (2022)."},{"key":"e_1_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/3448016.3452775"},{"key":"e_1_2_2_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/956750.956789"},{"key":"e_1_2_2_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFCOM.2003.1208709"}],"container-title":["Proceedings of the ACM on Management of Data"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3588960","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3588960","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:47:38Z","timestamp":1750178858000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3588960"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5,26]]},"references-count":45,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2023,5,26]]}},"alternative-id":["10.1145\/3588960"],"URL":"https:\/\/doi.org\/10.1145\/3588960","relation":{},"ISSN":["2836-6573"],"issn-type":[{"value":"2836-6573","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,5,26]]}}}