From Centralized to Distributed and Ubiquitous In-Network Defense for Future 6G Networks

Mattia Giovanni Spina, Floriano De Rango, Antonio Iera · 2024

Future telecommunications networks are increasingly vulnerable to external attacks mainly due to the fast development of applications based on the massive use of IoT devices As a consequence, the perimeter of attacks on networks has expanded enormously and traditional security control techniques need to evolve to cope with this issue. A promising approach leverages the potential of Programmable Data Planes, that will characterize future networks, to implement effective in-network Intrusion Detection Systems (IDS). Initial works addressed the in-network IDS development, mainly with a centralized approach. In this paper, instead, we propose a Proof-of-Concept study dealing with a deployment approach that allows to distribute across the network nodes an in-network IDS created via a chain of Weak Learners. This, as demonstrated in the Prof-of-Concept experiments shown, allows to overcome some limitations of in-network centralized approaches, by working faster, and occupying fewer resources of the devices involved, while maintaining the level of precision sought.

Read the paper · More papers on PaperTik