Helios: Learning and Adaptation of Matching Rules for Continual In-Network Malicious Traffic Detection
Zhenning Shi, Dan Zhao, Yijia Zhu, Guorui Xie, Qing Li, Yong Jiang
Abstract
Network Intrusion Detection Systems (NIDS) are critical for web security by identifying and blocking malicious traffic. In-network NIDS leverage programmable switches for high-speed traffic processing. However, they are unable to reconcile the fine-grained classification of known classes and the identification of unseen attacks. Moreover, they lack support for incremental updates. In this paper, we propose Helios, an in-network malicious traffic detection system, for continual adaptation in attack-incremental scenarios. First, we design a novel Supervised Mixture Prototypical Learning (SMPL) method combined with clustering initialization to learn prototypes that encapsulate the knowledge, based on the weighted infinity norm distance. SMPL enables known class classification and unseen attack identification through similarity comparison between prototypes and samples. Then, we design boundary calibration and overlap refinement to transform learned prototypes into priority-guided matching rules, ensuring precise and efficient in-network deployment. Additionally, Helios supports incremental prototype learning and rule updates, achieving low-cost hardware reconfiguration. We implement Helios on a Tofino switch and evaluation on three datasets shows that Helios achieves superior performance in classifying known classes (92%+ in ACC and F1) as well as identifying unseen attacks (62% - 98% in TPR). Helios has also reduced resource consumption and reconfiguration time, demonstrating its scalability and efficiency for real-world deployment.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- PANDORA: Lightweight Adversarial Defense for Edge IoT using Uncertainty-Aware Metric LearningAvinash Awasthi, Pritam Vediya, Hemant Miranka, Ramesh Babu Battula et al.NDSS 2026 · 1 citation
- Learning to Evolve: Bayesian-Guided Continual Knowledge Graph EmbeddingLinYu Li, Zhi Jin, Yuanpeng He, Dongming Jin et al.WWW 2026 · 1 citation
- A Unified Framework for Rule Learning: Integrating Commonsense Knowledge from LLMs with Structured Knowledge from Knowledge GraphsQirui Hao, Kewei Cheng, Tongze Zhang, Hongyuan Liu et al.WWW 2026
Builds on19
- Mitigating Neural Network Overconfidence with Logit NormalizationHongxin Wei, Renchunzi Xie, Hao Cheng, Lei Feng et al.ICML 2022 · 386 citations
- ViM: Out-Of-Distribution with Virtual-logit MatchingHaoqi Wang, Zhizhong Li, Litong Feng, Wayne ZhangCVPR 2022 · 227 citations
- Jaqen: A High-Performance Switch-Native Approach for Detecting and Mitigating Volumetric DDoS Attacks with Programmable SwitchesZaoxing Liu, Hun Namkung, Georgios Nikolaidis, Jeongkeun Lee et al.USENIX Security 2021 · 221 citations
- Realtime Robust Malicious Traffic Detection via Frequency Domain AnalysisChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2021 · 194 citations
- SIREN: Shaping Representations for Detecting Out-of-Distribution ObjectsXuefeng Du, Gabriel Gozum, Yifei Ming, Yixuan LiNeurIPS 2022 · 105 citations
Related papers
- Proteus: Towards Accurate and Low-overhead In-Network Malicious Traffic DetectionLonglong Zhu, Linying Zheng, Qing Shu, Zedi Chen et al.WWW 2026
- Genos: General In-Network Unsupervised Intrusion Detection by Rule ExtractionRuoyu Li, Qing Li, Yu Zhang, Dan Zhao et al.INFOCOM 2024 · 11 citations
- Leo: Online ML-based Traffic Classification at Multi-Terabit Line RateSyed Usman Jafri, Sanjay G. Rao, Vishal Shrivastav, Mohit TawarmalaniNSDI 2024 · 46 citations
- RIDS: Towards Advanced IDS via RNN Model and Programmable Switches Co-Designed ApproachesZiming Zhao, Zhaoxuan Li, Zhuoxue Song, Fan Zhang et al.INFOCOM 2024 · 21 citations
- Kitsune: An Ensemble of Autoencoders for Online Network Intrusion DetectionYisroel Mirsky, Tomer Doitshman, Yuval Elovici, Asaf ShabtaiNDSS 2018 · 945 citations
