Titel
Poster: P4DME: DNS Threat Mitigation with P4 In-Network Machine Learning Offload
Autor*in
Stefan Schmid
TU Berlin
Abstract
The ever-evolving cybersecurity landscape demands innovative solutions to safeguard critical network infrastructure such as the Domain Name System (DNS). This paper presents P4DME, a novel approach that harnesses the potential of Machine Learning (ML) in conjunction with P4 programmable switches to tackle DNS threats efficiently. P4DME's primary benefit lies in offloading filtering from resource-intensive ML processing tasks on dedicated servers. This offloading boosts the overall traffic throughput that can be inspected or achieves the same throughput with reduced resource consumption while preserving the servers' capabilities for high-performance threat identification. This work uses P4-based in-network elements to handle crucial DNS threats, dynamic white- and blacklisting, and an online popularity-based anomaly detection heuristic. The latter serves as a trigger for dedicated ML-based inspection. Furthermore, we introduce in-network mitigation filters updated through the control plane to provide adaptable and responsive threat mitigation. Preliminary simulation results show more than 99.9% offload ratio at 5% increased False Negative Ratio.
Stichwort
DNS securityP4in-network computationmachine learningoffloadingprogrammable networks
Objekt-Typ
Sprache
Englisch [eng]
Enthalten in
Titel
EuroP4 '23
Proceedings of the 6th on European P4 Workshop
ISBN
979-8-4007-0446-8
Verlag
ACM , 2023
Zugänglichkeit
Rechteangabe
© 2023 Owner/Author

Herunterladen

Universität Wien | Universitätsring 1 | 1010 Wien | T +43-1-4277-0