RIDS: Towards Advanced IDS via RNN Model and Programmable Switches Co-Designed Approaches
Ziming Zhao, Zhaoxuan Li, Zhuoxue Song, Fan Zhang, Binbin Chen
摘要
Existing Deep Learning (DL)-based network Intrusion Detection System (IDS) is able to characterize sequence semantics of traffic and discover malicious behaviors. Yet DL models are often nonlinear and highly non-convex functions that are difficult for in-network deployment. In this paper, we present RIDS, a hardware-friendly Recurrent Neural Network (RNN) model that is co-designed with programmable switches. As its core, RIDS is powered by two tightly-coupled components: (i) rLearner, the RNN learning module with in-network deployability as the first-class requirement; and (ii) rEnforcer, the concrete pipeline design to realize rLearner-generated models inside the network dataplane. We implement a prototype of RIDS and evaluate it on our physical testbed. The experiments show that RIDS could satisfy both detection performance and high-speed bandwidth adaptation simultaneously, when none of the other existing approaches could do so. Inspiringly, RIDS realizes remarkable intrusion/malware detection effect (e.g., 99% F1 score) and model deployment (e.g., 100 Gbps per port), while only imposing nanoseconds of latency.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper3
- DUNE: Distributed Inference in the User PlaneBeyza Bütün, David De Andres Hernandez, Michele Gucciardo, Marco FioreINFOCOM 2025 · 被引用 7 次
- Towards Context-Aware Traffic Classification via Time-Wavelet Fusion NetworkZiming Zhao, Zhuoxue Song, Xiaofei Xie, Zhaoxuan Li 等KDD 2025 · 被引用 5 次
- Synecdoche: Efficient and Accurate In-Network Traffic Classification via Direct Packet Sequential Pattern MatchingMinyuan Xiao, Yunchun Li, Yuchen Zhao, Tong Guan 等INFOCOM 2026 · 被引用 2 次
相关 Paper
- Brain-on-Switch: Towards Advanced Intelligent Network Data Plane via NN-Driven Traffic Analysis at Line-SpeedJinzhu Yan, Haotian Xu, Zhuotao Liu, Qi Li 等NSDI 2024 · 被引用 60 次
- Genos: General In-Network Unsupervised Intrusion Detection by Rule ExtractionRuoyu Li, Qing Li, Yu Zhang, Dan Zhao 等INFOCOM 2024 · 被引用 11 次
- Proteus: Towards Accurate and Low-overhead In-Network Malicious Traffic DetectionLonglong Zhu, Linying Zheng, Qing Shu, Zedi Chen 等WWW 2026
- Metis: Understanding and Enhancing In-Network Regular ExpressionsZhengxin Zhang, Yucheng Huang, Guanglin Duan, Qing Li 等NeurIPS 2023 · 被引用 3 次
- FENIX: Enabling In-Network DNN Inference with FPGA-Enhanced Programmable SwitchesXiangyu Gao, Tong Li, Yinchao Zhang, Ziqiang Wang 等NSDI 2026 · 被引用 12 次
