Toward an Intrusion Detection System for a Virtualization Framework in Edge Computing
Fuente:
arXiv
Salvato in:
| Autori principali: | , , , , |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2025
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
| _version_ | 1866917075915636736 |
|---|---|
| author | de Matos, Everton Alameri, Hazaa Lunardi, Willian Tessaro Andreoni, Martin Viegas, Eduardo |
| author_facet | de Matos, Everton Alameri, Hazaa Lunardi, Willian Tessaro Andreoni, Martin Viegas, Eduardo |
| contents | Edge computing pushes computation closer to data sources, but it also expands the attack surface on resource-constrained devices. This work explores the deployment of the Lightweight Deep Anomaly Detection for Network Traffic (LDPI) integrated as an isolated service within a virtualization framework that provides security by separation. LDPI, adopting a Deep Learning approach, achieved strong training performance, reaching AUC 0.999 (5-fold mean) across the evaluated packet-window settings (n, l), with high F1 at conservative operating points. We deploy LDPI on a laptop-class edge node and evaluate its overhead and performance in two scenarios: (i) comparing it with representative signature-based IDSes (Suricata and Snort) deployed on the same framework under identical workloads, and (ii) while detecting network flooding attacks. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2511_09068 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | Toward an Intrusion Detection System for a Virtualization Framework in Edge Computing de Matos, Everton Alameri, Hazaa Lunardi, Willian Tessaro Andreoni, Martin Viegas, Eduardo Cryptography and Security Edge computing pushes computation closer to data sources, but it also expands the attack surface on resource-constrained devices. This work explores the deployment of the Lightweight Deep Anomaly Detection for Network Traffic (LDPI) integrated as an isolated service within a virtualization framework that provides security by separation. LDPI, adopting a Deep Learning approach, achieved strong training performance, reaching AUC 0.999 (5-fold mean) across the evaluated packet-window settings (n, l), with high F1 at conservative operating points. We deploy LDPI on a laptop-class edge node and evaluate its overhead and performance in two scenarios: (i) comparing it with representative signature-based IDSes (Suricata and Snort) deployed on the same framework under identical workloads, and (ii) while detecting network flooding attacks. |
| title | Toward an Intrusion Detection System for a Virtualization Framework in Edge Computing |
| topic | Cryptography and Security |
| url | https://arxiv.org/abs/2511.09068 |