Aug 2026· Conference on Applications, Technologies, Architectures, and Protocols for Computer Communication· 0 citations· 58 references
Computer Science
TL;DR
SiteGuard, an inline network intrusion detection system with programmable switches specifically developed to protect enterprise campus sites connecting to ISP, is designed and implemented and proposes a dual-plane feature extraction model to extract extensive traffic features at near line-speed.
Abstract
In order to provide security connections to the enterprise campus sites, internet service providers are offering comprehensive intrusion detection services at the network layer. However, existing network intrusion detection systems (NIDS) are either ineffective or inefficient for high-speed network protection, especially for encrypted traffic analysis. In this paper, we design and implement SiteGuard, an inline network intrusion detection system with programmable switches specifically developed to protect enterprise campus sites connecting to ISP. SiteGuard proposes a dual-plane feature extraction model to extract extensive traffic features at near line-speed. SiteGuard also proposes a lightweight one-class classification model that trains the best parameters exclusively on benign traffic to identify malicious traffic. In addition, SiteGuard introduces an online update mechanism that aims to dynamically adjust the detection model in response to environmental changes. SiteGuard has been in production for more than three years. Our production and testbed evaluations demonstrate SiteGuard can detect malicious traffic with approximately 90% accuracy in minutes.
Open Platform Communications Unified Architecture (OPC UA) is increasingly deployed over private 5G networks in industrial environments, where end-to-end encryption prevents payload inspection by network-based intrusion detection systems (IDSs). Although payload-agnostic statistical features extracted from encrypted tr...
Son-Ha Song, Florian Foerster, Henry Beuster et al.· 0 citations
Per-ID behavioral residualization is presented, a CAN-specific representation that extracts fourteen temporal, protocol, and payload features from sliding windows and residualizes them against each arbitration ID's normal baseline, which improves mean F1 in the majority of evaluations.
The findings indicate that the detector can serve network administrators as an open-source instrument for continuous security monitoring and forensic reconstruction.
Base Jay-ar B., Palmares Serafin C., Soberano Kristine T.· World Journal of Advanced En...· 0 citations
As interconnected devices increasingly transmit personal and sensitive data, security attacks are becoming more sophisticated and prevalent, highlighting the critical need for effective security solutions in Internet of Things (IoT) environments. An automated Network Intrusion Detection (NID) system plays a vital role...
Rangu Shashidhar, M. Raju· International Journal of Eng...· 1 citation
Modern data centres require high-performance networking alongside effective real-time security. Traditional Intrusion Detection Systems (IDS) commonly rely on general-purpose processors and often struggle to inspect high-speed traffic at line rate without introducing latency or performance bottlenecks. Smart Network In...
Nise O'Cuill, Chang-Hong Li, Georgios Floros et al.· 0 citations
With programmability and centralized control, Software-Defined Networking (SDN) has become a revolutionary networking paradigm that makes network administration easier. Nevertheless, vulnerabilities are also introduced by this architectural flexibility, especially Internet Control Message Protocol (ICMP) flooding assau...
Tsehaynesh Babil Wassie, Bayew Dessie Fenta, Habtamu Molla Belachew et al.· IEEE Access· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.