Repository logo
  • English
  • العربية
  • বাংলা
  • Català
  • Čeština
  • Deutsch
  • Ελληνικά
  • Español
  • Suomi
  • Français
  • Gàidhlig
  • हिंदी
  • Magyar
  • Italiano
  • Қазақ
  • Latviešu
  • Nederlands
  • Polski
  • Português
  • Português do Brasil
  • Srpski (lat)
  • Српски
  • Svenska
  • Türkçe
  • Yкраї́нська
  • Tiếng Việt
Log In
New user? Click here to register.Have you forgotten your password?
  1. Home
  2. IIT Gandhinagar
  3. Computer Science and Engineering
  4. CSE Publications
  5. SmartWatch: Accurate traffic analysis and flow-state tracking for intrusion prevention using SmartNICs
 
  • Details

SmartWatch: Accurate traffic analysis and flow-state tracking for intrusion prevention using SmartNICs

Author(s)
S., Panda, Sourav
Y., Feng, Yixiao
S.G., Kulkarni, Sameer G.  
K.K., Ramakrishnan, Kadangode K.
N.G., Duffield, Nick G.
L.N., Bhuyan, Laxmi Narayan
DOI
10.1145/3485983.3494861
Start Page
29-02-1900
End Page
75
Abstract
Despite advances in network security, attacks targeting mission critical systems and applications remain a significant problem for network and datacenter providers. Existing telemetry platforms detect volumetric attacks at terabit scales using approximation techniques and coarse grain analysis. However, the prevalence of low and slow attacks that require very little bandwidth, makes flow-state tracking critical to overall attack mitigation. Traffic queries deployed on network switches are often limited by hardware constraints, preventing them from carrying out flow tracking features required to detect stealthy attacks. Such attacks can go undetected in the midst of high traffic volumes. We design SmartWatch, a novel flow state tracking and flow logging system at line rate, using SmartNICs to optimize performance and simultaneously detect a number of stealthy attacks. SmartWatch leverages advances in switch based network telemetry platforms to process the bulk of the traffic and only forward suspicious traffic subsets to the SmartNIC. The programmable network switches perform coarse-grained traffic analysis while the SmartNIC conducts the finer-grained analysis which involves additional processing of the packet as a 'bump-in-the-wire'. A control loop between the SmartNIC and programmable switch tunes the queries performed in the switch to direct the most appropriate traffic subset to the SmartNIC. SmartWatch's cooperative monitoring approach yields 2.39 times better detection rate compared to existing platforms deployed on programmable switches. SmartWatch can detect covert timing channels and perform website fingerprinting more efficiently compared to standalone programmable switch solutions, relieving switch memory and control-plane processor resources. Compared to host-based approaches, SmartWatch can reduce the packet processing latency by 72.32%. � 2021 Elsevier B.V., All rights reserved.
Publication link
https://dl.acm.org/doi/pdf/10.1145/3485983.3494861
URI
https://www.scopus.com/inward/record.uri?eid=2-s2.0-85121593701&doi=10.1145%2F3485983.3494861&partnerID=40&md5=69932f625b6006290dd47fb6b5377f3a
http://repository.iitgn.ac.in/handle/IITG2025/29359
Keywords
Network security
Flow state
In networks
Intrusion prevention
Network switches
Networks security
Programmable switches
Smartnic
State tracking
Traffic analysis
Traffic flow
Telemetering equipment
IITGN Knowledge Repository Developed and Managed by Library

Built with DSpace-CRIS software - Extension maintained and optimized by 4Science

  • Privacy policy
  • End User Agreement
  • Send Feedback
Repository logo COAR Notify