immUNITY: Detecting and Mitigating Low Volume & Slow Attacks with Programmable Switches and SmartNICs

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Wei, Cuidi, Tu, Shaoyu, Hata, Daiki, Hasegawa, Toru, Koizumi, Yuki, Ramakrishnan, K. K., Takemasa, Junji, Wood, Timothy
Formato: Preprint
Publicado: 2026
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866908903422296064
author Wei, Cuidi
Tu, Shaoyu
Hata, Daiki
Hasegawa, Toru
Koizumi, Yuki
Ramakrishnan, K. K.
Takemasa, Junji
Wood, Timothy
author_facet Wei, Cuidi
Tu, Shaoyu
Hata, Daiki
Hasegawa, Toru
Koizumi, Yuki
Ramakrishnan, K. K.
Takemasa, Junji
Wood, Timothy
contents Our analysis of recent Internet traces shows that up to 71% of flows contain suspicious behaviors indicative of low-volume network attacks such as port scans. However, distinguishing anomalous traffic in real time is challenging as each attack flow may comprise only a few packets. We extend prior work that tracks heavy hitter flows to also detect low-volume and slow attacks by combining the capabilities of both switches and SmartNICs. We flip the usual design approach by proposing an efficient filter data structure used to quickly route traffic marked as benign towards destination end-systems. We make careful use of limited programmable switch memory and pipeline stages, and complement them with SmartNIC resources to analyze the remaining traffic that may be anomalous. Using machine learning classifiers and intrusion detection rules deployed on the SmartNIC, we identify malicious source IPs, which then undergo more detailed forensics for attack mitigation. Finally, we develop a dataplane based protocol to rapidly coordinate data structure updates between these devices. We implement immUNITY in a testbed with Tofino v1 switch and Bluefield 3 SmartNIC, demonstrating its high accuracy, while minimizing traffic that's analyzed outside the switch.
format Preprint
id arxiv_https___arxiv_org_abs_2603_20573
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle immUNITY: Detecting and Mitigating Low Volume & Slow Attacks with Programmable Switches and SmartNICs
Wei, Cuidi
Tu, Shaoyu
Hata, Daiki
Hasegawa, Toru
Koizumi, Yuki
Ramakrishnan, K. K.
Takemasa, Junji
Wood, Timothy
Networking and Internet Architecture
Cryptography and Security
Our analysis of recent Internet traces shows that up to 71% of flows contain suspicious behaviors indicative of low-volume network attacks such as port scans. However, distinguishing anomalous traffic in real time is challenging as each attack flow may comprise only a few packets. We extend prior work that tracks heavy hitter flows to also detect low-volume and slow attacks by combining the capabilities of both switches and SmartNICs. We flip the usual design approach by proposing an efficient filter data structure used to quickly route traffic marked as benign towards destination end-systems. We make careful use of limited programmable switch memory and pipeline stages, and complement them with SmartNIC resources to analyze the remaining traffic that may be anomalous. Using machine learning classifiers and intrusion detection rules deployed on the SmartNIC, we identify malicious source IPs, which then undergo more detailed forensics for attack mitigation. Finally, we develop a dataplane based protocol to rapidly coordinate data structure updates between these devices. We implement immUNITY in a testbed with Tofino v1 switch and Bluefield 3 SmartNIC, demonstrating its high accuracy, while minimizing traffic that's analyzed outside the switch.
title immUNITY: Detecting and Mitigating Low Volume & Slow Attacks with Programmable Switches and SmartNICs
topic Networking and Internet Architecture
Cryptography and Security
url https://arxiv.org/abs/2603.20573