| Full text | |
| Author(s): |
Hagen, Lucas Sonntag
;
Ilha, Alexandre da Silveira
;
Parizotto, Ricardo
;
Gaspary, Luciano Paschoal
Total Authors: 4
|
| Document type: | Journal article |
| Source: | NOMS 2025-2025 IEEE NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM; v. N/A, p. 9-pg., 2025-01-01. |
| Abstract | |
Intrusion Detection and Prevention Systems (IDS/IPSs) are essential for identifying and preventing the increasingly complex and growing number of cyber-attacks. These systems analyze streams of network packets, providing ways to identify attack patterns and notify operators about possible threats. Nonetheless, server-only approaches are inefficient, overwhelming server resources since servers typically operate at a Mbps scale, which is drastically slower than the Tbps scale of high-speed networks. In this paper, we propose RNA, a system that offloads to programmable forwarding devices the identification of critical events (per-packet) that are "consumed" by IDS/IPSs, thereby reducing the resource overhead of a serveronly solution. At its core, RNA provides a mechanism for distilling events of interest from security signature specifications and an approach for automatically generating code to offload IDS/IPS event processing to programmable switches. The proposed system "envelops" this functionality into interfaces that allow for transparent communication between forwarding devices and IDS/IPS systems transparently. We implement a proof-of-concept of RNA on top of Zeek. Our evaluations with real datasets show that RNA can identify attacks while releasing resources from the server-only solution. We also show that RNA minimizes the effort by operators to code P4 software. (AU) | |
| FAPESP's process: | 20/05183-0 - SkyNet: towards smart data planes |
| Grantee: | Luciano Paschoal Gaspary |
| Support Opportunities: | Research Projects - Thematic Grants |
| FAPESP's process: | 23/00673-7 - Distributed intelligence in communications networks and in the internet of things |
| Grantee: | Nelson Luis Saldanha da Fonseca |
| Support Opportunities: | Research Projects - Thematic Grants |