PS-Sketch: Fast and Accurate Detection of Persistent-Spreaders in High-Speed Networks

Zhaohui Wang, Ye Tian, Yi-Yen Wu, Wei Chen, Xinyu Zhang, Xinming Zhang · IEEE Transactions on Networking · 2025

Large spread and high persistence are widely observed in malicious activities such as botnets and DDoS attacks in high-speed networks, while how to identify persistent-spreaders is still a challenging issue. In this work, we presentPS-Sketch, a system for estimating persistent-spreads of network flows and detecting persistent-spreaders in network data streams. PS-Sketch is based on our definitions of persistence and persistent-spread, which overcome the limitations of the conventional definitions by better capturing network flows’ behaviors, and being difficult for attackers to bypass. Within a switch’s pipeline, PS-Sketch processes packets with two adjacent sketch data structures, namely the P-sketch and the S-sketch. In the P-sketch, we employ low-pass filter (LPF) to trace an element’s persistence that incorporates occurrences in its entire history, and in the S-sketch, we extend the HyperLogLog (HLL) algorithm, and integrate an element’s persistence to the spread estimation of the flow that the element belongs to, for estimating the flow’s persistent-spread. We present theoretical analysis on the error bound of PS-Sketch. Trace-driven evaluation shows that PS-Sketch achieves high accuracy in estimating network flows’ persistent-spreads, and outperforms the existing solutions in detecting persistent-spreaders. We further prototype PS-Sketch in P4 and show that the system is deployable on commodity hardware switches.

Read the paper · More papers on PaperTik