vNIDS: Towards Elastic Security with Safe and Efficient Virtualization of Network Intrusion Detection Systems
Hongda Li, Hongxin Hu, Guofei Gu, Gail-Joon Ahn, Fuqiang Zhang
Abstract
Traditional Network Intrusion Detection Systems (NIDSes) are generally implemented on vendor proprietary appliances or middleboxes with poor versatility and flexibility. Emerging Network Function Virtualization (NFV) and Software-Defined Networking (SDN) technologies can virtualize NIDSes and elastically scale them to deal with attack traffic variations. However, such an elasticity feature must not come at the cost of decreased detection effectiveness and expensive provisioning. In this paper, we propose an innovative NIDS architecture, vNIDS, to enable safe and efficient virtualization of NIDSes. vNIDS addresses two key challenges with respect to effective intrusion detection and non-monolithic NIDS provisioning in virtualizing NIDSes. The former challenge is addressed by detection state sharing while minimizing the sharing overhead in virtualized environments. In particular, static program analysis is employed to determine which detection states need to be shared. vNIDS addresses the latter challenge by provisioning virtual NID-Ses as microservices and employing program slicing to partition the detection logic programs so that they can be executed by each microservice separately. We implement a prototype of vNIDS to demonstrate the feasibility of our approach. Our evaluation results show that vNIDS could offer both effective intrusion detection and efficient provisioning for NIDS virtualization.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 48e72d0d-a0f8-426e-9e29-8a7f55d1a676Cited by top-tier papers3
- Realtime Robust Malicious Traffic Detection via Frequency Domain AnalysisChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2021 · 194 citations
- Re-architecting Traffic Analysis with Neural Network Interface CardsGiuseppe Siracusano, Salvator Galea, Davide Sanvito, Mohammad Malekzadeh et al.NSDI 2022 · 99 citations
- Poseidon: Mitigating Volumetric DDoS Attacks with Programmable SwitchesMenghao Zhang, Guanyu Li, Shicheng Wang, Chang Liu et al.NDSS 2020
Builds on3
- Kitsune: An Ensemble of Autoencoders for Online Network Intrusion DetectionYisroel Mirsky, Tomer Doitshman, Yuval Elovici, Asaf ShabtaiNDSS 2018 · 945 citations
- PSI: Precise Security Instrumentation for Enterprise NetworksTianlong Yu, Seyed Kaveh Fayaz, Michael P. Collins, Vyas Sekar et al.NDSS 2017 · 64 citations
- On the Safety and Efficiency of Virtual Firewall Elasticity ControlJuan Deng, Hongda Li, Hongxin Hu, Kuang-Ching Wang et al.NDSS 2017
Related papers
- NFlow and MVT Abstractions for NFV ScalingZiyan Wu, Yang Zhang, Wendi Feng, Zhi-Li ZhangINFOCOM 2022 · 6 citations
- Network Monitoring for SDN Virtual NetworksGyeongsik Yang, Heesang Jin, Minkoo Kang, Gi Jun Moon et al.INFOCOM 2020 · 15 citations
- Proteus: Towards Accurate and Low-overhead In-Network Malicious Traffic DetectionLonglong Zhu, Linying Zheng, Qing Shu, Zedi Chen et al.WWW 2026
- Genos: General In-Network Unsupervised Intrusion Detection by Rule ExtractionRuoyu Li, Qing Li, Yu Zhang, Dan Zhao et al.INFOCOM 2024 · 11 citations
- AIM-SDN: Attacking Information Mismanagement in SDN-datastoresVaibhav Hemant Dixit, Adam Doupé, Yan Shoshitaishvili, Ziming Zhao et al.CCS 2018 · 31 citations
