Skip to content
Preprint

XNET: Intelligent Dynamic Sampling for High-Speed Network Security Monitoring

Aug 2026 · 0 citations · 67 references
Computer Science

TL;DR

This paper introduces XNET, a system that monitors traffic at line rate using commodity hardware and applies dynamic sampling to amplify the visibility of high security value traffic and demonstrates XNET's scalability up to 100Gbps.

Abstract

Growing network speeds, with 100GbE line rates becoming common in modern enterprise networks, pose challenges to operators and security applications, as they struggle to scale their operational efficiency accordingly, without relying on costly hardware, excessive sampling, or complex distributed deployments. Unintentional loss due to stochastic packet sampling often produces low-quality traffic, further risking missed detection of critical security incidents, particularly those hidden in typically low-rate traffic, such as APT/malware command-and-control communications. In this paper, we introduce XNET, a system that monitors traffic at line rate using commodity hardware and applies dynamic sampling to amplify the visibility of high security value traffic. XNET leverages Linux's XDP technology to process packets efficiently, classify them based on their security value, and sample them as per configured policies. The outcome is a reduced packet stream in which the security-relevant portion of the traffic is amplified at the expense of less interesting traffic segments. XNET is a highly flexible, scalable and dynamic system that can be adapted based on a network's needs. We deployed XNET in a large real-world network using only commodity hardware, where our results show that XNET can achieve up to 84% traffic reduction with no packet loss while increasing the visibility of otherwise negligible traffic fivefold. With controlled stress tests, we further demonstrate XNET's scalability up to 100Gbps. Additionally, we show that XNET sampling led to a detection rate of 99.6% in an IDS application.

View source

Similar papers

Real-time detection of cryptographic key misuse in software-defined networks using incremental learning

An incremental learning based framework to detect anomalous traffic patterns which may indicate any key misuse in Software-Defined Networks in dynamic and real-time environments in modern SDN environments is proposed.

Gineeth Rajeshkhanna, Tamilarasi Kathirvel Murugan, Logeswari Govindaraj et al. · 0 citations
Preprint Sep 2026

FSNIC: A Low-Latency Flow-Based Intrusion Detection Architecture for FPGA SmartNICs

Modern data centres require high-performance networking alongside effective real-time security. Traditional Intrusion Detection Systems (IDS) commonly rely on general-purpose processors and often struggle to inspect high-speed traffic at line rate without introducing latency or performance bottlenecks. Smart Network In...

Nise O'Cuill, Chang-Hong Li, Georgios Floros et al. · 0 citations
Open access Sep 2026

AI-Augmented Network-Forensics: Leveraging LLMs for Real-Time Threat Detection and Automated Response in Enterprise Environments

In modern enterprise networks, complicated rule-based signatures, fragmented alerts, encrypted traffic, and analyst workloads are delaying the ability to recognize and contain incidents, as the need grows for faster correlation of heterogeneous telemetry. This study evaluates an LLM-augmented network-forensics architec...

Mohammed Imran Choudhary · 0 citations
Aug 2026

Early Warning of Advanced Persistent Threats Through Enterprise Network Behavior Profiling

Advanced persistent threats often begin with low-volume and stealthy network activities, such as reconnaissance, command-and-control beaconing, credential probing, and slow data staging. These behaviors are difficult to detect because they may not produce obvious traffic spikes or signature-matching patterns. This stud...

Mads Jensen, Sofie Nielsen, L. Andersen et al. · 0 citations
Open access Aug 2026

Enhancing SQL Injection Detection: A Machine Learning Approach Using Network Flow Data

A flow-based detection method, making use of lightweight protocols like NetFlow and sFlow to identify SQLI attacks, which minimizes the need for computationally expensive packet inspection, which is going to render the process of detection more trustworthy and economical, particularly within high-traffic conditions.

P. Vinoth, K. Sudar, S. Muthukumar · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.