2021 · 12 citations · 16 references
EngineeringHigh Performance Computer NetworkComputer ArchitectureInformation ForensicsEmbedded SystemsHardware SystemsIntrusion Detection SystemsHardware SecurityData ScienceData MiningComputing SystemsData IntegrationNetwork ManagementParallel ComputingData ManagementIntrusion Detection SystemThreat DetectionKnowledge DiscoveryComputer EngineeringComputer ScienceNetwork ForensicsHardware AccelerationOperating SystemsProgrammable Data PlaneBig Data
Today's communication networks process an increasing amount of traffic, while simultaneously providing services to a larger and more diverse quantity of devices. This enhances the complexity of the network and imposes a larger attack space, impacting network management and security efforts. Deployed hardware middle-boxes, like firewalls and Intrusion Detection Systems (IDSs) often lack the flexibility to adapt to this dynamic environment, which Network Function Virtualization (NFV) addresses by implementing these services in software. Yet, this may impose a bottleneck, due to the absence of hardware acceleration. To mitigate this drawback, the functionality can be offloaded to programmable hardware, using P4. In this work we implement an IDS, capable of operating in core and backbone networks up to 100Gbps. This is achieved by using the hardware acceleration of P4-enabled Intel <sup xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">©</sup> Tofino™ switches for high performance metadata extraction, in order to train an ML-based detection engine. The system is evaluated regarding its throughput and obtainable aggregation levels as well as its accuracy for detecting a variety of network attacks.
16
Survey of intrusion detection systems: techniques, datasets and challenges
Ansam Khraisat, Iqbal Gondal, Peter Vamplew et al. · Cybersecurity · 2019 · 1.7K citations · Full text
Heavy-Hitter Detection Entirely in the Data Plane
Vibhaalakshmi Sivaraman, Srinivas Narayana, Ori Rottenstreich et al. · 2017 · 433 citations · Full text
Cluster Computing, Internet Traffic Analysis, Heavy Flows +24