NetFeatureXtract: Efficient Traffic Feature Extraction using eBPF
摘要
The rapid growth in the usage of the Internet and the increasing sophistication of cyberattacks have heightened the need for efficient network monitoring and intrusion detection systems (IDS). Feature extraction, a critical component of an IDS, must balance computational efficiency with the accuracy and richness of the extracted data. This paper introduces NetFeatureXtract, an efficient system for traffic feature extraction utilizing the Extended Berkeley Packet Filter (eBPF) and Express Data Path (XDP). NetFeatureXtract dynamically collects and computes up to 18 customizable network traffic features in real-time, minimizing overhead and maintaining high accuracy.