Helios: Learning and Adaptation of Matching Rules for Continual In-Network Malicious Traffic Detection
Zhenning Shi, Dan Zhao, Yijia Zhu, Guorui Xie, Qing Li, Yong Jiang
摘要
Network Intrusion Detection Systems (NIDS) are critical for web security by identifying and blocking malicious traffic. In-network NIDS leverage programmable switches for high-speed traffic processing. However, they are unable to reconcile the fine-grained classification of known classes and the identification of unseen attacks. Moreover, they lack support for incremental updates. In this paper, we propose Helios, an in-network malicious traffic detection system, for continual adaptation in attack-incremental scenarios. First, we design a novel Supervised Mixture Prototypical Learning (SMPL) method combined with clustering initialization to learn prototypes that encapsulate the knowledge, based on the weighted infinity norm distance. SMPL enables known class classification and unseen attack identification through similarity comparison between prototypes and samples. Then, we design boundary calibration and overlap refinement to transform learned prototypes into priority-guided matching rules, ensuring precise and efficient in-network deployment. Additionally, Helios supports incremental prototype learning and rule updates, achieving low-cost hardware reconfiguration. We implement Helios on a Tofino switch and evaluation on three datasets shows that Helios achieves superior performance in classifying known classes (92%+ in ACC and F1) as well as identifying unseen attacks (62% - 98% in TPR). Helios has also reduced resource consumption and reconfiguration time, demonstrating its scalability and efficiency for real-world deployment.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- PANDORA: Lightweight Adversarial Defense for Edge IoT using Uncertainty-Aware Metric LearningAvinash Awasthi, Pritam Vediya, Hemant Miranka, Ramesh Babu Battula 等NDSS 2026 · 被引用 1 次
- Learning to Evolve: Bayesian-Guided Continual Knowledge Graph EmbeddingLinYu Li, Zhi Jin, Yuanpeng He, Dongming Jin 等WWW 2026 · 被引用 1 次
- A Unified Framework for Rule Learning: Integrating Commonsense Knowledge from LLMs with Structured Knowledge from Knowledge GraphsQirui Hao, Kewei Cheng, Tongze Zhang, Hongyuan Liu 等WWW 2026
它引用的顶会 Paper19
- Mitigating Neural Network Overconfidence with Logit NormalizationHongxin Wei, Renchunzi Xie, Hao Cheng, Lei Feng 等ICML 2022 · 被引用 386 次
- ViM: Out-Of-Distribution with Virtual-logit MatchingHaoqi Wang, Zhizhong Li, Litong Feng, Wayne ZhangCVPR 2022 · 被引用 227 次
- Jaqen: A High-Performance Switch-Native Approach for Detecting and Mitigating Volumetric DDoS Attacks with Programmable SwitchesZaoxing Liu, Hun Namkung, Georgios Nikolaidis, Jeongkeun Lee 等USENIX Security 2021 · 被引用 221 次
- Realtime Robust Malicious Traffic Detection via Frequency Domain AnalysisChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2021 · 被引用 194 次
- SIREN: Shaping Representations for Detecting Out-of-Distribution ObjectsXuefeng Du, Gabriel Gozum, Yifei Ming, Yixuan LiNeurIPS 2022 · 被引用 105 次
相关 Paper
- Proteus: Towards Accurate and Low-overhead In-Network Malicious Traffic DetectionLonglong Zhu, Linying Zheng, Qing Shu, Zedi Chen 等WWW 2026
- Genos: General In-Network Unsupervised Intrusion Detection by Rule ExtractionRuoyu Li, Qing Li, Yu Zhang, Dan Zhao 等INFOCOM 2024 · 被引用 11 次
- Leo: Online ML-based Traffic Classification at Multi-Terabit Line RateSyed Usman Jafri, Sanjay G. Rao, Vishal Shrivastav, Mohit TawarmalaniNSDI 2024 · 被引用 46 次
- RIDS: Towards Advanced IDS via RNN Model and Programmable Switches Co-Designed ApproachesZiming Zhao, Zhaoxuan Li, Zhuoxue Song, Fan Zhang 等INFOCOM 2024 · 被引用 21 次
- Kitsune: An Ensemble of Autoencoders for Online Network Intrusion DetectionYisroel Mirsky, Tomer Doitshman, Yuval Elovici, Asaf ShabtaiNDSS 2018 · 被引用 945 次
