将入侵检测模型分布部署到网络设备,实现高效自防护。
Optimal In-Network Distribution of Learning Functions for a Secure-by-Design Programmable Data Plane of Next-Generation Networks
- 提出模型优化学习任务在数据平面的分配方式。
- 可实现全网分布式防御,设备负载增加低于15%。
- 适合需要自主安全防护的下一代网络系统使用。
可编程数据平面(PDP)与网络内计算(INC)范式使网络设备(如交换机、网卡等)具备执行高级处理任务的能力,可在网络内部运行各类算法,包括机器学习,以支持用户与网络服务。本文聚焦于在网络内部署学习模型,旨在构建完全分布式的入侵检测系统(IDS)或入侵防御系统(IPS)。提出一种模型,用于优化将IDS/IPS工作负载分布在数据平面设备之间,确保全网安全的同时,避免对设备正常操作造成过重负担。此外,设计了一种元启发式方法,以降低数学模型精确解所需的长计算时间,并对其性能进行了评估。分析与结果表明,该方法在构建智能数据平面方面具有巨大潜力,能作为抵御网络攻击的第一道防线,且对所涉网络设备的额外负载极小。
原文摘要 · Abstract (English)
The rise of programmable data plane (PDP) and in-network computing (INC) paradigms paves the way for the development of network devices (switches, network interface cards, etc.) capable of performing advanced processing tasks. This allows running various types of algorithms, including machine learning, within the network itself to support user and network services. In particular, this paper delves into the deployment of in-network learning models with the aim of implementing fully distributed intrusion detection systems (IDS) or intrusion prevention systems (IPS). Specifically, a model is proposed for the optimal distribution of the IDS/IPS workload among data plane devices with the aim of ensuring complete network security without excessively burdening the normal operations of the devices. Furthermore, a meta-heuristic approach is proposed to reduce the long computation time required by the exact solution provided by the mathematical model and its performance is evaluated. The analysis conducted and the results obtained demonstrate the enormous potential of the proposed new approach for the creation of intelligent data planes that act effectively and autonomously as the first line of defense against cyber attacks, with minimal additional workload on the network devices involved.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。