Towards High-Performance Intrusion Detection with Robustness Guarantees on Programmable Switches at ISP Scale
Han Zhang, Xuefeng Liu, Linqiang Qian, Guyue (Grace) Liu, Tianyu Zhang, Kaiyang Zhao, Yantu Tong, Zeji Xiao, Dongbiao He, Yahui Li, Ke Ruan, Jilong Wang
Abstract
In order to provide security connections to the enterprise campus sites, internet service providers are offering comprehensive intrusion detection services at the network layer. However, existing network intrusion detection systems (NIDS) are either ineffective or inefficient for high-speed network protection, especially for encrypted traffic analysis. In this paper, we design and implement SiteGuard, an inline network intrusion detection system with programmable switches specifically developed to protect enterprise campus sites connecting to ISP. SiteGuard proposes a dual-plane feature extraction model to extract extensive traffic features at near line-speed. SiteGuard also proposes a lightweight one-class classification model that trains the best parameters exclusively on benign traffic to identify malicious traffic. In addition, SiteGuard introduces an online update mechanism that aims to dynamically adjust the detection model in response to environmental changes. SiteGuard has been in production for more than three years. Our production and testbed evaluations demonstrate SiteGuard can detect malicious traffic with approximately 90% accuracy in minutes.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 4860fc68-b5a2-4520-bb78-7fbab3feaa9cRelated papers
- Proteus: Towards Accurate and Low-overhead In-Network Malicious Traffic DetectionLonglong Zhu, Linying Zheng, Qing Shu, Zedi Chen et al.WWW 2026
- Genos: General In-Network Unsupervised Intrusion Detection by Rule ExtractionRuoyu Li, Qing Li, Yu Zhang, Dan Zhao et al.INFOCOM 2024 · 11 citations
- Helios: Learning and Adaptation of Matching Rules for Continual In-Network Malicious Traffic DetectionZhenning Shi, Dan Zhao, Yijia Zhu, Guorui Xie et al.WWW 2025 · 6 citations
- vNIDS: Towards Elastic Security with Safe and Efficient Virtualization of Network Intrusion Detection SystemsHongda Li, Hongxin Hu, Guofei Gu, Gail-Joon Ahn et al.CCS 2018 · 47 citations
- Trident: A Universal Framework for Fine-Grained and Class-Incremental Unknown Traffic DetectionZiming Zhao, Zhaoxuan Li, Zhuoxue Song, Wenhao Li et al.WWW 2024 · 38 citations
