Toward an Intrusion Detection System for a Virtualization Framework in Edge Computing

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: de Matos, Everton, Alameri, Hazaa, Lunardi, Willian Tessaro, Andreoni, Martin, Viegas, Eduardo
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866917075915636736
author de Matos, Everton
Alameri, Hazaa
Lunardi, Willian Tessaro
Andreoni, Martin
Viegas, Eduardo
author_facet de Matos, Everton
Alameri, Hazaa
Lunardi, Willian Tessaro
Andreoni, Martin
Viegas, Eduardo
contents Edge computing pushes computation closer to data sources, but it also expands the attack surface on resource-constrained devices. This work explores the deployment of the Lightweight Deep Anomaly Detection for Network Traffic (LDPI) integrated as an isolated service within a virtualization framework that provides security by separation. LDPI, adopting a Deep Learning approach, achieved strong training performance, reaching AUC 0.999 (5-fold mean) across the evaluated packet-window settings (n, l), with high F1 at conservative operating points. We deploy LDPI on a laptop-class edge node and evaluate its overhead and performance in two scenarios: (i) comparing it with representative signature-based IDSes (Suricata and Snort) deployed on the same framework under identical workloads, and (ii) while detecting network flooding attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2511_09068
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Toward an Intrusion Detection System for a Virtualization Framework in Edge Computing
de Matos, Everton
Alameri, Hazaa
Lunardi, Willian Tessaro
Andreoni, Martin
Viegas, Eduardo
Cryptography and Security
Edge computing pushes computation closer to data sources, but it also expands the attack surface on resource-constrained devices. This work explores the deployment of the Lightweight Deep Anomaly Detection for Network Traffic (LDPI) integrated as an isolated service within a virtualization framework that provides security by separation. LDPI, adopting a Deep Learning approach, achieved strong training performance, reaching AUC 0.999 (5-fold mean) across the evaluated packet-window settings (n, l), with high F1 at conservative operating points. We deploy LDPI on a laptop-class edge node and evaluate its overhead and performance in two scenarios: (i) comparing it with representative signature-based IDSes (Suricata and Snort) deployed on the same framework under identical workloads, and (ii) while detecting network flooding attacks.
title Toward an Intrusion Detection System for a Virtualization Framework in Edge Computing
topic Cryptography and Security
url https://arxiv.org/abs/2511.09068