PS-IPS: Deploying Intrusion Prevention System with Machine Learning on Programmable Switch
DOI:
10.2139/ssrn.4440724
Publication Date:
2023-05-10T16:15:57Z
AUTHORS (4)
ABSTRACT
Intrusion prevention is significant to avoid device damage and financial losses. Researchers have proposed various Prevention Systems (IPS) prevent malware, including traditional SDN-based IPS. However, existing IPSs suffer from low throughput problems caused by detection rule-installation delays. Here, we propose a programmable switch-base IPS (named PS-IPS), which utilizes the switch CPU pipeline detect malware. PSIPS consists of four main components: (1) parser, (2) flow filter, (3) recirculation director, (4) malware detector. According experiment, achieves 183X than The response time also reduced 99.99%, showing that effectively prevents malware
with single switch.
SUPPLEMENTAL MATERIAL
Coming soon ....
REFERENCES (0)
CITATIONS (0)
EXTERNAL LINKS
PlumX Metrics
RECOMMENDATIONS
FAIR ASSESSMENT
Coming soon ....
JUPYTER LAB
Coming soon ....