Skip to content
Book Open access

Towards High-Performance Intrusion Detection with Robustness Guarantees on Programmable Switches at ISP Scale

Aug 2026 · Conference on Applications, Technologies, Architectures, and Protocols for Computer Communication · 0 citations · 58 references
Computer Science

TL;DR

SiteGuard, an inline network intrusion detection system with programmable switches specifically developed to protect enterprise campus sites connecting to ISP, is designed and implemented and proposes a dual-plane feature extraction model to extract extensive traffic features at near line-speed.

Abstract

In order to provide security connections to the enterprise campus sites, internet service providers are offering comprehensive intrusion detection services at the network layer. However, existing network intrusion detection systems (NIDS) are either ineffective or inefficient for high-speed network protection, especially for encrypted traffic analysis. In this paper, we design and implement SiteGuard, an inline network intrusion detection system with programmable switches specifically developed to protect enterprise campus sites connecting to ISP. SiteGuard proposes a dual-plane feature extraction model to extract extensive traffic features at near line-speed. SiteGuard also proposes a lightweight one-class classification model that trains the best parameters exclusively on benign traffic to identify malicious traffic. In addition, SiteGuard introduces an online update mechanism that aims to dynamically adjust the detection model in response to environmental changes. SiteGuard has been in production for more than three years. Our production and testbed evaluations demonstrate SiteGuard can detect malicious traffic with approximately 90% accuracy in minutes.

Read PDF

Similar papers

Preprint Sep 2026

Improving the Reliability of Anomaly Detection for Encrypted OPC UA Traffic over Private 5G

Open Platform Communications Unified Architecture (OPC UA) is increasingly deployed over private 5G networks in industrial environments, where end-to-end encryption prevents payload inspection by network-based intrusion detection systems (IDSs). Although payload-agnostic statistical features extracted from encrypted tr...

Son-Ha Song, Florian Foerster, Henry Beuster et al. · 0 citations
Preprint Aug 2026

Behavioral Residualization for Unsupervised Intrusion Detection in Automotive CAN Networks

Per-ID behavioral residualization is presented, a CAN-specific representation that extracts fourteen temporal, protocol, and payload features from sliding windows and residualizes them against each arbitration ID's normal baseline, which improves mean F1 in the majority of evaluations.

Chandan Hegde, M. R. Reddy · 0 citations
Open access Aug 2026

Automated Network Intrusion Detection for Internet of Things Security Enhancements

As interconnected devices increasingly transmit personal and sensitive data, security attacks are becoming more sophisticated and prevalent, highlighting the critical need for effective security solutions in Internet of Things (IoT) environments. An automated Network Intrusion Detection (NID) system plays a vital role...

Rangu Shashidhar, M. Raju · 1 citation
Preprint Sep 2026

FSNIC: A Low-Latency Flow-Based Intrusion Detection Architecture for FPGA SmartNICs

Modern data centres require high-performance networking alongside effective real-time security. Traditional Intrusion Detection Systems (IDS) commonly rely on general-purpose processors and often struggle to inspect high-speed traffic at line rate without introducing latency or performance bottlenecks. Smart Network In...

Nise O'Cuill, Chang-Hong Li, Georgios Floros et al. · 0 citations
Open access 2026

Detection and Prevention of Internet Control Message Protocol Flood Attack in Software-Defined Network Using Dynamic Threshold and Machine Learning

With programmability and centralized control, Software-Defined Networking (SDN) has become a revolutionary networking paradigm that makes network administration easier. Nevertheless, vulnerabilities are also introduced by this architectural flexibility, especially Internet Control Message Protocol (ICMP) flooding assau...

Tsehaynesh Babil Wassie, Bayew Dessie Fenta, Habtamu Molla Belachew et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.