FastFE: Accelerating ML-based Traffic Analysis with Programmable Switches

FastFE: Accelerating ML-based Traffic Analysis with Programmable Switches
复制标题

FastFE:利用可编程交换机加速基于 ML 的流量分析

DOI:
10.1145/3405669.3405818
复制
发表时间:
2020
期刊:
SPIN '20: Proceedings of the Workshop on Secure Programmable Network Infrastructure
影响因子:
--
通讯作者:
Hu, Hongxin
Hu, Hongxin
中科院分区:
--
文献类型:
--
作者:
Bai, Jiasong;Zhang, Menghao;Li, Guanyu;Liu, Chang;Xu, Mingwei;Hu, Hongxin

文献摘要

参考文献

被引文献

相似文献

现代流量分析应用程序通常被设计为通过使用机器学习(ML)技术从网络流量中推断敏感信息来识别恶意行为,并且随着加密和其他规避技术的日益使用,使得经典的基于内容的分析变得不可行,它们对安全性非常重要。然而,随着网络吞吐量达到数百Gbps的飙升,流量分析应用程序跟上当今高速大容量网络流量变得越来越具有挑战性。特别地,流量分析中的现有特征提取器组件遭受不期望的通信、存储和计算瓶颈。为此,本文提出了FastFE,高速特征提取器,利用新一代可编程交换机的能力,灵活,高效地生成所需的流量特征。我们提供了一组通用的,易于使用的,和富有表现力的接口,运营商表达他们想要的traic功能,和一个策略执行引擎,可以有效地将这些政策转化为可编程交换机和商品服务器的底层原语。我们对最先进的基于ML的流量分析应用Kitsune的案例研究表明了FastFE的显著进步及其低开销。作为一个持续的工作,我们正在进行一个完整的原型设计和实现,并希望FastFE可以作为一个关键的构建块,为未来的ML为基础的流量分析应用。
Modern traffic analysis applications are usually designed to identify malicious behaviors by inferring sensitive information with machine learning (ML) techniques from network traffic, and they are of great importance to security with the growing use of encryption and other evasion techniques that make classic content-based analysis infeasible. However, with the soaring throughput of networks reaching hundreds of Gbps, it becomes more and more challenging for traffic analysis applications to keep up with today's high-speed large-volume network traffic. In particular, existing feature extractor components in traffic analysis are suffering from undesirable communications, storage, and computation bottleneck. To this end, this paper presents FastFE, a high-speed feature extractor that leverages the capability of new-generation programmable switches to generate desired traffic features flexibly and efficiently. We provide a set of general, easy-to-use, and expressive interfaces for operators to express which traic features they desire, and a policy enforcement engine that can effectively translate these policies into underlying primitives in programmable switches and commodity servers. Our case study on a state-of-the-art ML-based traffic analysis application, Kitsune, demonstrates the significant advancement of FastFE and its low overheads. As an ongoing work, we are working on a full prototype design and implementation, and hope FastFE can serve as a crucial build block for future ML-based traffic analysis applications.
DOI: 10.1109/spw.2014.25
发表时间: 2014-05
期刊: 2014 IEEE Security and Privacy Workshops
影响因子: --
作者:
Pratik Narang;S. Ray;C. Hota;V. Venkatakrishnan
通讯作者: Pratik Narang;S. Ray;C. Hota;V. Venkatakrishnan
DOI: --
发表时间: 2020
期刊: --
影响因子: --
作者:
Jiarong Xing;Qiao Kang;Ang Chen
通讯作者: Jiarong Xing;Qiao Kang;Ang Chen
DOI: 10.1007/10722599_12
发表时间: 2000-10
期刊: --
影响因子: --
作者:
K. Yoda;H. Etoh
通讯作者: K. Yoda;H. Etoh
DOI: 10.1007/978-3-540-87403-4_4
发表时间: 2008-09
期刊: --
影响因子: --
作者:
Daniel Ramsbrock;Xinyuan Wang;Xuxian Jiang
通讯作者: Daniel Ramsbrock;Xinyuan Wang;Xuxian Jiang
使用逻辑回归模型扫描超大型网络上的检测
DOI: 10.1109/iscc.2006.142
发表时间: 2006
期刊: 11th IEEE Symposium on Computers and Communications (ISCC'06)
影响因子: --
作者:
C. Gates;Josh McNutt;J. Kadane;M. Kellner
通讯作者: M. Kellner