Busca avançada
Ano de início
Entree


FEVER: Intelligent Behavioral Fingerprinting for Anomaly Detection in P4-Based Programmable Networks

Texto completo
Autor(es):
Saueressig, Matheus ; Franco, Muriel Figueredo ; Scheid, Eder J. ; Huertas, Alberto ; Bovet, Gerome ; Stiller, Burkhard ; Granville, Lisandro Z.
Número total de Autores: 7
Tipo de documento: Artigo Científico
Fonte: ADVANCED INFORMATION NETWORKING AND APPLICATIONS, VOL 3, AINA 2024; v. 201, p. 12-pg., 2024-01-01.
Resumo

The evolving computer network landscape has enabled programmability in various network aspects, including Software-defined Networking (SDN) for control plane programmability and the introduction of the Programming Protocol-independent Packet Processors (P4). P4, a vendor-independent protocol, allows programmability on the data plane, offering flexibility for new services and applications. However, this flexibility introduces the need for automated solutions to monitor and manage the security of evolving networks and services. In this work, we propose FEVER, a framework utilizing P4-based telemetry and network device (switch) resource consumption to create fingerprints of network and P4 application behaviors. FEVER provides a comprehensive approach to identifying network anomalies through various metrics. The framework was evaluated in a virtualized scenario using unsupervised Machine Learning (ML) algorithms to detect diverse P4 program behaviors and traffic overload, demonstrating its potential for early detection of malicious activities in programmable networks. The results indicate high accuracy in identifying misbehavior and detecting sudden changes in P4 programs affecting the network. (AU)

Processo FAPESP: 20/05152-7 - PROFISSA: internet do futuro programável para arquiteturas e softwares seguros
Beneficiário:Lisandro Zambenedetti Granville
Modalidade de apoio: Auxílio à Pesquisa - Temático