Busca avançada
Ano de início
Entree


Texto completo
Autor(es):
Hagen, Lucas Sonntag ; Ilha, Alexandre da Silveira ; Parizotto, Ricardo ; Gaspary, Luciano Paschoal
Número total de Autores: 4
Tipo de documento: Artigo Científico
Fonte: NOMS 2025-2025 IEEE NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM; v. N/A, p. 9-pg., 2025-01-01.
Resumo

Intrusion Detection and Prevention Systems (IDS/IPSs) are essential for identifying and preventing the increasingly complex and growing number of cyber-attacks. These systems analyze streams of network packets, providing ways to identify attack patterns and notify operators about possible threats. Nonetheless, server-only approaches are inefficient, overwhelming server resources since servers typically operate at a Mbps scale, which is drastically slower than the Tbps scale of high-speed networks. In this paper, we propose RNA, a system that offloads to programmable forwarding devices the identification of critical events (per-packet) that are "consumed" by IDS/IPSs, thereby reducing the resource overhead of a serveronly solution. At its core, RNA provides a mechanism for distilling events of interest from security signature specifications and an approach for automatically generating code to offload IDS/IPS event processing to programmable switches. The proposed system "envelops" this functionality into interfaces that allow for transparent communication between forwarding devices and IDS/IPS systems transparently. We implement a proof-of-concept of RNA on top of Zeek. Our evaluations with real datasets show that RNA can identify attacks while releasing resources from the server-only solution. We also show that RNA minimizes the effort by operators to code P4 software. (AU)

Processo FAPESP: 20/05183-0 - SkyNet: rumo à era dos planos de dados inteligentes
Beneficiário:Luciano Paschoal Gaspary
Modalidade de apoio: Auxílio à Pesquisa - Temático
Processo FAPESP: 23/00673-7 - Inteligência distribuída em redes de comunicação e internet das coisas
Beneficiário:Nelson Luis Saldanha da Fonseca
Modalidade de apoio: Auxílio à Pesquisa - Temático