Cerberus: Enabling Efficient and Effective In-Network Monitoring on Programmable Switches
Huancheng Zhou, Guofei Gu
摘要
With the increasing volume of network traffic and the emergence of new types of attacks, traditional network monitoring is facing significant challenges in ensuring network security and performance. In-network monitoring (INM) systems based on programmable switches, e.g., P4-based INM systems, have emerged as a more promising approach for high-performance and real-time network monitoring. However, existing P4-based INM systems have resource limitations in handling diverse and high-volume INM tasks such as multi-vector DDoS defenses. Worse still, attackers may try to dynamically change attack vectors to disrupt inadaptable systems and even lead to denial-of-service (DoS) attacks against INM.To address these challenges, we present Cerberus, an efficient and effective in-network security monitoring system. To support various INM tasks, we abstract them into key-feature (K-F) pairs and design a novel memory slicing mechanism to share memory among multiple K-F pairs. To handle high-volume traffic, we propose a new co-monitoring mechanism that complements the data and control planes, thereby greatly enhancing the efficiency of Cerberus. To adapt to changing network conditions, we design a new resource manager that dynamically reallocates resources for INM tasks and adjusts loads for the data and control planes without interrupting running services. We design a series of INM modules, including DDoS defenses, and develop a prototype of Cerberus. We conduct extensive evaluations to demonstrate that Cerberus can enhance the concurrency and capacity of programmable switches by an order of magnitude. Moreover, Cerberus is more adaptable in handling various INM tasks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- When Address Learning Goes Wrong: Inducing Forwarding Loops and DoS Amplification in SDNDezhang Kong, Yilun Zhang, Zekun Xie, Ningpeng Zheng 等USENIX Security 2026
- On the Security Risks of Memory Adaptation and Augmentation in Data-plane DoS MitigationHocheol Nam, Daehyun Lim, Huancheng Zhou, Guofei Gu 等NDSS 2026
- Janus: Enabling Expressive and Efficient ACLs in High-speed RDMA CloudsZiteng Chen, Menghao Zhang, Jiahao Cao, Xuzheng Chen 等NDSS 2026
它引用的顶会 Paper9
- Jaqen: A High-Performance Switch-Native Approach for Detecting and Mitigating Volumetric DDoS Attacks with Programmable SwitchesZaoxing Liu, Hun Namkung, Georgios Nikolaidis, Jeongkeun Lee 等USENIX Security 2021 · 被引用 221 次
- Flow Event Telemetry on Programmable Data PlaneYu Zhou, Chen Sun, Hongqiang Harry Liu, Rui Miao 等SIGCOMM 2020 · 被引用 139 次
- OmniMon: Re-architecting Network Telemetry with Resource Efficiency and Full AccuracyQun Huang, Haifeng Sun, Patrick P. C. Lee, Wei Bai 等SIGCOMM 2020 · 被引用 109 次
- Contra: A Programmable System for Performance-aware RoutingKuo-Feng Hsu, Ryan Beckett, Ang Chen, Jennifer Rexford 等NSDI 2020 · 被引用 104 次
- Ripple: A Programmable, Decentralized Link-Flooding Defense Against Adaptive AdversariesJiarong Xing, Wenqing Wu, Ang ChenUSENIX Security 2021 · 被引用 100 次
相关 Paper
- Continuous in-network round-trip time monitoringSatadal Sengupta, Hyojoon Kim, Jennifer RexfordSIGCOMM 2022 · 被引用 54 次
- Poseidon: Mitigating Volumetric DDoS Attacks with Programmable SwitchesMenghao Zhang, Guanyu Li, Shicheng Wang, Chang Liu 等NDSS 2020
- Mew: Enabling Large-Scale and Dynamic Link-Flooding Defenses on Programmable SwitchesHuancheng Zhou, Sungmin Hong, Yangyang Liu, Xiapu Luo 等S&P 2023
- Programmable In-Network Security for Context-aware BYOD PoliciesQiao Kang, Lei Xue, Adam Morrison, Yuxin Tang 等USENIX Security 2020
- Memory Management in ActiveRMT: Towards Runtime-programmable SwitchesRajdeep Das, Alex C. SnoerenSIGCOMM 2023 · 被引用 10 次
