Metis: Understanding and Enhancing In-Network Regular Expressions
Zhengxin Zhang, Yucheng Huang, Guanglin Duan, Qing Li, Dan Zhao, Yong Jiang, Lianbo Ma, Xi Xiao, Hengyang Xu
Abstract
Regular expressions (REs) offer one-shot solutions for many networking tasks, e.g., network intrusion detection. However, REs purely rely on expert knowledge and cannot learn from massive ubiquitous network data for automatic management. Today, neural networks (NNs) have shown superior accuracy and flexibility, thanks to their ability to learn from rich labeled data. Nevertheless, NNs are often incompetent in cold-start scenarios and too complex for deployment on network devices. In this paper, we propose Metis, a general framework that converts REs to network device affordable models for superior accuracy and throughput by taking advantage of REs’ expert knowledge and NNs’ learning ability. In Metis, we convert REs to byte-level recurrent neural networks (BRNNs) without training. The BRNNs preserve expert knowledge from REs and offer adequate accuracy in cold-start scenarios. When rich labeled data is available, the performance of BRNNs can be improved by training. Furthermore, we design a semi-supervised knowledge distillation to transform the BRNNs into pooling soft random forests (PSRFs) that can be deployed on network devices. We collect network traffic data on a large data center for three weeks and evaluate Metis on them. Experimental results show that Metis is more accurate than original REs and other baselines, achieving superior throughput when deployed on network devices.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0f728aa4-7f05-4f5e-a9e5-29c7a0bda7abCited by top-tier papers1
Ask how each one uses itBuilds on10
- Kitsune: An Ensemble of Autoencoders for Online Network Intrusion DetectionYisroel Mirsky, Tomer Doitshman, Yuval Elovici, Asaf ShabtaiNDSS 2018 · 945 citations
- Cross-Layer Distillation with Semantic CalibrationDefang Chen, Jian-Ping Mei, Yuan Zhang, Can Wang et al.AAAI 2021 · 368 citations
- Realtime Robust Malicious Traffic Detection via Frequency Domain AnalysisChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2021 · 194 citations
- PANIC: A High-Performance Programmable NIC for Multi-tenant NetworksJiaxin Lin, Kiran Patel, Brent E. Stephens, Anirudh Sivaraman et al.OSDI 2020 · 104 citations
- How Great is the Great Firewall? Measuring China's DNS CensorshipNguyen Phong Hoang, Arian Akhavan Niaki, Jakub Dalek, Jeffrey Knockel et al.USENIX Security 2021 · 80 citations
Related papers
- Learning-Enhanced High-Throughput Pattern Matching Based on Programmable Data PlaneGuanglin Duan, Yucheng Huang, Zhengxin Zhang, Qing Li et al.USENIX ATC 2025
- Cold-Start and Interpretability: Turning Regular Expressions into Trainable Recurrent Neural NetworksChengyue Jiang, Yinggong Zhao, Shanbo Chu, Libin Shen et al.EMNLP 2020 · 23 citations
- Genos: General In-Network Unsupervised Intrusion Detection by Rule ExtractionRuoyu Li, Qing Li, Yu Zhang, Dan Zhao et al.INFOCOM 2024 · 11 citations
- RIDS: Towards Advanced IDS via RNN Model and Programmable Switches Co-Designed ApproachesZiming Zhao, Zhaoxuan Li, Zhuoxue Song, Fan Zhang et al.INFOCOM 2024 · 21 citations
- Exploring Motif-based Heterogeneous Graph Learning for ReDoS DetectionHong Huang, Chengyu Yao, Rongchen Li, Weihao Su et al.ICML 2026
