The rapid growth in the usage of the Internet and the increasing sophistication of cyberattacks have heightened the need for efficient network monitoring and intrusion detection systems (IDS). Feature extraction, a critical component of an IDS, must balance computational efficiency with the accuracy and richness of the extracted data. This paper introduces NetFeatureXtract, an efficient system for traffic feature extraction utilizing the Extended Berkeley Packet Filter (eBPF) and Express Data Path (XDP). NetFeatureXtract dynamically collects and computes up to 18 customizable network traffic features in real-time, minimizing overhead and maintaining high accuracy.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

NetFeatureXtract: Efficient Traffic Feature Extraction using eBPF

  • Gustavo Henrique Ellwanger Einsfeldt,
  • Alberto Egon Schaeffer Filho

摘要

The rapid growth in the usage of the Internet and the increasing sophistication of cyberattacks have heightened the need for efficient network monitoring and intrusion detection systems (IDS). Feature extraction, a critical component of an IDS, must balance computational efficiency with the accuracy and richness of the extracted data. This paper introduces NetFeatureXtract, an efficient system for traffic feature extraction utilizing the Extended Berkeley Packet Filter (eBPF) and Express Data Path (XDP). NetFeatureXtract dynamically collects and computes up to 18 customizable network traffic features in real-time, minimizing overhead and maintaining high accuracy.