SentinelX: A Lightweight Malicious Traffic Detection System Based on Programmable Switches
Zutao Zhang, Zeyu Luan, Qing Li, Zhuyun Qi, Kejun Li, Yong Jiang, Zhenhui Yuan
摘要
In recent years, programmable switches have emerged as robust platforms for deploying high-performance network services to detect malicious traffic. However, current researches face several challenges: firstly, the flow tables generated by model deployment are cumbersome; secondly, existing unsupervised methods have difficulty handling repetitive traffic; and thirdly, the flow-level inference is coarse-grained and susceptible to attacks. To address these challenges, we propose SentinelX, which offers several advancements. Initially, we design a space-saving multi-level flow table representation method. We then introduce TreeDivider, an innovative model-splitting algorithm that achieves significant space reductions of up to 63.88% after only two subdivisions. Next, we propose DualTree, a hardware-specific unsupervised decision tree utilizing a dual threshold mode, which enhances detection accuracy by approximately 30.24%. Finally, we design a fine-grained method for determining the inference point, boosting the detection rate of bypass attacks by 30.03%. Extensive experiments on the H3C S9830-32H-H1 switch demonstrate that SentinelX can reach 99.99% of the maximum bandwidth of switch ports with nanosecond-level latency, approximately 1.38 times the delay of L3 (network layer) base forwarding.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper5
- Realtime Robust Malicious Traffic Detection via Frequency Domain AnalysisChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2021 · 被引用 194 次
- Flowrest: Practical Flow-Level Inference in Programmable Switches with Random ForestsAristide Tanyi-Jong Akem, Michele Gucciardo, Marco FioreINFOCOM 2023 · 被引用 63 次
- T-cache: Dependency-free Ternary Rule Cache for Policy-based ForwardingYing Wan, Haoyu Song, Yang Xu, Yilun Wang 等INFOCOM 2020 · 被引用 23 次
- HorusEye: A Realtime IoT Malicious Traffic Detection Framework using Programmable SwitchesYutao Dong, Qing Li, Kaidong Wu, Ruoyu Li 等USENIX Security 2023
- An Efficient Design of Intelligent Network Data PlaneGuangmeng Zhou, Zhuotao Liu, Chuanpu Fu, Qi Li 等USENIX Security 2023
相关 Paper
- Proteus: Towards Accurate and Low-overhead In-Network Malicious Traffic DetectionLonglong Zhu, Linying Zheng, Qing Shu, Zedi Chen 等WWW 2026
- Genos: General In-Network Unsupervised Intrusion Detection by Rule ExtractionRuoyu Li, Qing Li, Yu Zhang, Dan Zhao 等INFOCOM 2024 · 被引用 11 次
- SPLIDT: Partitioned Decision Trees for Scalable Stateful Inference at Line RateMurayyiam Parvez, Annus Zulfiqar, Roman Beltiukov, Shir Landau Feibish 等NSDI 2026 · 被引用 1 次
- Leo: Online ML-based Traffic Classification at Multi-Terabit Line RateSyed Usman Jafri, Sanjay G. Rao, Vishal Shrivastav, Mohit TawarmalaniNSDI 2024 · 被引用 46 次
- Elixir: A High-performance and Low-cost Approach to Managing Hardware/Software Hybrid Flow Tables Considering Flow BurstinessYanshu Wang, Dan Li, Yuanwei Lu, Jianping Wu 等NSDI 2022 · 被引用 20 次
