arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.12605cs.CRcs.DCcs.NI

一个基于eBPF/XDP的特征丰富的嵌入式网络入侵检测系统:检测器与架构权衡

A Feature-Rich Embedded NIDS with eBPF/XDP: Detector and Architecture Trade-offs

  • Chalmers University of Technology(查尔姆斯理工大学)
  • University of Gothenburg(哥德堡大学)
  • Ericsson AB(爱立信公司)

机构由 AI 辅助整理,请以论文原文为准。

Shiqi Wu, Oleksii Koshovyi, Georgios Pseiridis Pseiras, Victor Morel, Romaric Duvignau

AI总结:

本文提出一个基于eBPF/XDP的嵌入式NIDS,使用Isolation Forest和GoFlowMeter特征提取,比较三种部署架构,发现检测器主导质量,gRPC开销最小,Kafka延迟较高。

AI中文摘要:

分布式拒绝服务(DDoS)攻击仍然是传输网络面临的严重威胁,最近的攻击流量已超过30 Tbps,电信行业是主要目标。近期的工作尚未研究宿主软件架构对网络监控解决方案的影响,也未评估用于改进攻击检测的最新算法。本文介绍了一种用于传输网络中DDoS检测的网络入侵检测系统(NIDS),该系统是与爱立信合作开发的。在统计基线的基础上,我们通过使用Isolation Forest(孤立森林)算法提高了检测有效性,该算法基于更广泛的流特征进行训练,这些特征由GoFlowMeter(我们开源的CICFlowMeter的Go实现)提取,并且我们集成了eBPF/XDP,使NIDS能够在内核级别过滤真实流量。我们进一步在Raspberry Pi 5测试平台上比较了三种部署方式:单体架构、基于Kafka的架构和基于gRPC的微服务架构,并将CIC-DDoS2019数据集作为真实网络流量进行重放。检测质量主要由检测器的选择而非传输方式决定:Isolation Forest通过标记基线遗漏的低流量攻击窗口,将召回率和F1分数(单体变体中实时为0.965)提高到基线之上。然而,传输方式并非中性:gRPC达到了与单体变体几乎相同的准确性,同时每个窗口增加的传输时间不到2毫秒,而异步Kafka管道则落后约9个百分点,并增加了约27毫秒的延迟。这些发现阐明了在资源受限硬件上部署NIDS时,检测质量与架构开销之间的权衡。

英文摘要:

Distributed Denial-of-Service (DDoS) attacks remain a serious threat to transport networks, with recent attack volumes exceeding 30 Tbps, and the telecommunications industry being the main target. Recent work has yet to study the impact of the hosting software architecture on network monitoring solutions, or to assess recent algorithms for improving attack detection. This paper presents a Network Intrusion Detection System (NIDS) for DDoS detection in transport networks, developed in collaboration with Ericsson. Building on a statistical baseline, we improve detection effectiveness with an Isolation Forest trained on a wider set of flow features, extracted by GoFlowMeter, our open-source Go implementation of CICFlowMeter, and we integrate eBPF/XDP so that the NIDS filters real traffic at the kernel level. We further compare three deployments, monolithic, Kafka-based, and gRPC-based microservices, on a Raspberry Pi 5 testbed replaying the CIC-DDoS2019 dataset as real network traffic. Detection quality is governed mainly by the choice of detector rather than by the transport: the Isolation Forest raises recall and F1 score (0.965 live in the monolithic variant) over the baseline by flagging low-volume attack windows that the baseline misses. The transport is not neutral, however: gRPC reaches almost the same accuracy as the monolithic variant while adding less than 2 milliseconds of transport time per window, whereas the asynchronous Kafka pipeline trails by roughly nine percentage points and adds about 27 milliseconds. These findings clarify the trade-off between detection quality and architectural overhead when deploying a NIDS on resource-constrained hardware.

↑