USENIX Security2023Top-tier venue
HorusEye: A Realtime IoT Malicious Traffic Detection Framework using Programmable Switches
Yutao Dong, Qing Li, Kaidong Wu, Ruoyu Li, Dan Zhao, Gareth Tyson, Junkun Peng, Yong Jiang, Shutao Xia, Mingwei Xu
Abstract
The ever-growing volume of IoT traffic brings challenges to IoT anomaly detection systems. Existing anomaly detection systems perform all traffic detection on the control plane, which struggles to scale to the growing rates of traffic. In this paper, we propose HorusEye, a high throughput and accurate two-stage anomaly detection framework. In the first stage, preliminary burst-level anomaly detection is implemented on the data plane to exploit its high-throughput capability (e.g., 100Gbps). We design an algorithm that converts a trained iForest model into white list matching rules, and implement the first unsupervised model that can detect unseen attacks on the data plane. The suspicious traffic is then reported to the control plane for further investigation. To reduce the falsepositive rate, the control plane carries out the second stage, where more thorough anomaly detection is performed over the reported suspicious traffic using flow-level features and a deep detection model. We implement a prototype of HorusEye and evaluate its performance through a comprehensive set of experiments. The experimental results illustrate that the data plane can detect 99% of the anomalies and offload 76% of the traffic from the control plane. Compared with the state-ofthe-art schemes, our framework has superior throughput and detection performance.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 22344011-0258-45fa-83c1-5d7ff0c7e8ffCited by top-tier papers8
- A Principled Approach for Detecting APTs in Massive Networks via Multi-Stage Causal AnalyticsJiaping Gui, Mingjie Nie, Jinyao Guo, Futai Zou et al.INFOCOM 2025 · 6 citations
- Helios: Learning and Adaptation of Matching Rules for Continual In-Network Malicious Traffic DetectionZhenning Shi, Dan Zhao, Yijia Zhu, Guorui Xie et al.WWW 2025 · 6 citations
- SuperFE: A Scalable and Flexible Feature Extractor for ML-based Traffic Analysis ApplicationsMenghao Zhang, Guanyu Li, Cheng Guo, Renyu Yang et al.EuroSys 2025 · 4 citations
- SentinelX: A Lightweight Malicious Traffic Detection System Based on Programmable SwitchesZutao Zhang, Zeyu Luan, Qing Li, Zhuyun Qi et al.INFOCOM 2025 · 4 citations
- SPLIDT: Partitioned Decision Trees for Scalable Stateful Inference at Line RateMurayyiam Parvez, Annus Zulfiqar, Roman Beltiukov, Shir Landau Feibish et al.NSDI 2026 · 1 citation
Builds on13
- Kitsune: An Ensemble of Autoencoders for Online Network Intrusion DetectionYisroel Mirsky, Tomer Doitshman, Yuval Elovici, Asaf ShabtaiNDSS 2018 · 945 citations
- SoK: Security Evaluation of Home-Based IoT DeploymentsOmar Alrawi, Chaz Lever, Manos Antonakakis, Fabian MonroseS&P 2019 · 411 citations
- ATP: In-network Aggregation for Multi-tenant LearningChonLam Lao, Yanfang Le, Kshiteej Mahajan, Yixi Chen et al.NSDI 2021 · 359 citations
- IoTGuard: Dynamic Enforcement of Security and Safety Policy in Commodity IoTZ. Berkay Celik, Gang Tan, Patrick D. McDanielNDSS 2019 · 254 citations
- Jaqen: A High-Performance Switch-Native Approach for Detecting and Mitigating Volumetric DDoS Attacks with Programmable SwitchesZaoxing Liu, Hun Namkung, Georgios Nikolaidis, Jeongkeun Lee et al.USENIX Security 2021 · 221 citations
Related papers
- Detecting Unknown Encrypted Malicious Traffic in Real Time via Flow Interaction Graph AnalysisChuanpu Fu, Qi Li, Ke XuNDSS 2023
- Adaptive Model Pooling for Online Deep Anomaly Detection from a Complex Evolving Data StreamSusik Yoon, Youngjun Lee, Jae-Gil Lee, Byung Suk LeeKDD 2022 · 39 citations
- Pontus: Finding Waves in Data StreamsZhengxin Zhang, Qing Li, Guanglin Duan, Dan Zhao et al.SIGMOD 2023 · 7 citations
- Realtime Robust Malicious Traffic Detection via Frequency Domain AnalysisChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2021 · 194 citations
- Hardware-Accelerated Flow Interaction Graph Compression for High-Speed Anomaly DetectionTong Yun, Yinxin Kuang, Haoyu Song, Zhongyi Gu et al.INFOCOM 2025 · 2 citations
