SentinelX: A Lightweight Malicious Traffic Detection System Based on Programmable Switches
Zutao Zhang, Zeyu Luan, Qing Li, Zhuyun Qi, Kejun Li, Yong Jiang, Zhenhui Yuan
Abstract
In recent years, programmable switches have emerged as robust platforms for deploying high-performance network services to detect malicious traffic. However, current researches face several challenges: firstly, the flow tables generated by model deployment are cumbersome; secondly, existing unsupervised methods have difficulty handling repetitive traffic; and thirdly, the flow-level inference is coarse-grained and susceptible to attacks. To address these challenges, we propose SentinelX, which offers several advancements. Initially, we design a space-saving multi-level flow table representation method. We then introduce TreeDivider, an innovative model-splitting algorithm that achieves significant space reductions of up to 63.88% after only two subdivisions. Next, we propose DualTree, a hardware-specific unsupervised decision tree utilizing a dual threshold mode, which enhances detection accuracy by approximately 30.24%. Finally, we design a fine-grained method for determining the inference point, boosting the detection rate of bypass attacks by 30.03%. Extensive experiments on the H3C S9830-32H-H1 switch demonstrate that SentinelX can reach 99.99% of the maximum bandwidth of switch ports with nanosecond-level latency, approximately 1.38 times the delay of L3 (network layer) base forwarding.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a90682b2-ae01-4f65-adae-34c31faf42c6Cited by top-tier papers1
Ask how each one uses itBuilds on5
- Realtime Robust Malicious Traffic Detection via Frequency Domain AnalysisChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2021 · 194 citations
- Flowrest: Practical Flow-Level Inference in Programmable Switches with Random ForestsAristide Tanyi-Jong Akem, Michele Gucciardo, Marco FioreINFOCOM 2023 · 63 citations
- T-cache: Dependency-free Ternary Rule Cache for Policy-based ForwardingYing Wan, Haoyu Song, Yang Xu, Yilun Wang et al.INFOCOM 2020 · 23 citations
- HorusEye: A Realtime IoT Malicious Traffic Detection Framework using Programmable SwitchesYutao Dong, Qing Li, Kaidong Wu, Ruoyu Li et al.USENIX Security 2023
- An Efficient Design of Intelligent Network Data PlaneGuangmeng Zhou, Zhuotao Liu, Chuanpu Fu, Qi Li et al.USENIX Security 2023
Related papers
- Proteus: Towards Accurate and Low-overhead In-Network Malicious Traffic DetectionLonglong Zhu, Linying Zheng, Qing Shu, Zedi Chen et al.WWW 2026
- Genos: General In-Network Unsupervised Intrusion Detection by Rule ExtractionRuoyu Li, Qing Li, Yu Zhang, Dan Zhao et al.INFOCOM 2024 · 11 citations
- SPLIDT: Partitioned Decision Trees for Scalable Stateful Inference at Line RateMurayyiam Parvez, Annus Zulfiqar, Roman Beltiukov, Shir Landau Feibish et al.NSDI 2026 · 1 citation
- Leo: Online ML-based Traffic Classification at Multi-Terabit Line RateSyed Usman Jafri, Sanjay G. Rao, Vishal Shrivastav, Mohit TawarmalaniNSDI 2024 · 46 citations
- Elixir: A High-performance and Low-cost Approach to Managing Hardware/Software Hybrid Flow Tables Considering Flow BurstinessYanshu Wang, Dan Li, Yuanwei Lu, Jianping Wu et al.NSDI 2022 · 20 citations
