This paper introduces XNET, a system that monitors traffic at line rate using commodity hardware and applies dynamic sampling to amplify the visibility of high security value traffic and demonstrates XNET's scalability up to 100Gbps.
Abstract
Growing network speeds, with 100GbE line rates becoming common in modern enterprise networks, pose challenges to operators and security applications, as they struggle to scale their operational efficiency accordingly, without relying on costly hardware, excessive sampling, or complex distributed deployments. Unintentional loss due to stochastic packet sampling often produces low-quality traffic, further risking missed detection of critical security incidents, particularly those hidden in typically low-rate traffic, such as APT/malware command-and-control communications. In this paper, we introduce XNET, a system that monitors traffic at line rate using commodity hardware and applies dynamic sampling to amplify the visibility of high security value traffic. XNET leverages Linux's XDP technology to process packets efficiently, classify them based on their security value, and sample them as per configured policies. The outcome is a reduced packet stream in which the security-relevant portion of the traffic is amplified at the expense of less interesting traffic segments. XNET is a highly flexible, scalable and dynamic system that can be adapted based on a network's needs. We deployed XNET in a large real-world network using only commodity hardware, where our results show that XNET can achieve up to 84% traffic reduction with no packet loss while increasing the visibility of otherwise negligible traffic fivefold. With controlled stress tests, we further demonstrate XNET's scalability up to 100Gbps. Additionally, we show that XNET sampling led to a detection rate of 99.6% in an IDS application.
An incremental learning based framework to detect anomalous traffic patterns which may indicate any key misuse in Software-Defined Networks in dynamic and real-time environments in modern SDN environments is proposed.
Gineeth Rajeshkhanna, Tamilarasi Kathirvel Murugan, Logeswari Govindaraj et al.· Journal of Computer Virology...· 0 citations
Modern data centres require high-performance networking alongside effective real-time security. Traditional Intrusion Detection Systems (IDS) commonly rely on general-purpose processors and often struggle to inspect high-speed traffic at line rate without introducing latency or performance bottlenecks. Smart Network In...
Nise O'Cuill, Chang-Hong Li, Georgios Floros et al.· 0 citations
In modern enterprise networks, complicated rule-based signatures, fragmented alerts, encrypted traffic, and analyst workloads are delaying the ability to recognize and contain incidents, as the need grows for faster correlation of heterogeneous telemetry. This study evaluates an LLM-augmented network-forensics architec...
Mohammed Imran Choudhary· International Journal of Adv...· 0 citations
Advanced persistent threats often begin with low-volume and stealthy network activities, such as reconnaissance, command-and-control beaconing, credential probing, and slow data staging. These behaviors are difficult to detect because they may not produce obvious traffic spikes or signature-matching patterns. This stud...
Mads Jensen, Sofie Nielsen, L. Andersen et al.· The Journal of Applied Engi...· 0 citations
A flow-based detection method, making use of lightweight protocols like NetFlow and sFlow to identify SQLI attacks, which minimizes the need for computationally expensive packet inspection, which is going to render the process of detection more trustworthy and economical, particularly within high-traffic conditions.
P. Vinoth, K. Sudar, S. Muthukumar· Journal of Computer Science· 0 citations
Overall, the results show that KNIMEs no-code workflow framework can offer production-level DDoS detection comparable to conventional code-based techniques, providing a workable and extremely accurate way to safeguard programmable networks.