Show simple item record

dc.contributor.authorLi, Weihe
dc.contributor.authorBütün, Beyza 
dc.contributor.authorChu, Tianyue 
dc.contributor.authorFiore, Marco 
dc.contributor.authorPatras, Paul 
dc.date.accessioned2025-10-17T16:05:19Z
dc.date.available2025-10-17T16:05:19Z
dc.date.issued2025-09-22
dc.identifier.urihttps://hdl.handle.net/20.500.12761/1983
dc.description.abstractIn high-speed data center networks, persistent flows are repeatedly observed over extended periods, potentially signaling threats such as stealthy DDoS or botnet attacks. Monitoring every flow in production-grade hardware switches that feature limited memory, however, is challenging under typical high flow rates and data volumes. To tackle this, approximate data structures, like sketches, are often employed. Yet many existing methods rely on per-time-window flag resets, which require frequent control-plane interventions that make them unsuitable for high-speed traffic. This paper introduces PALLAS, a fully data-plane-implementable sketch for detecting persistent flows in high-speed networks with high accuracy, obviating the need for time-window-based resets. We further propose OPT-PALLAS, an enhanced variant of PALLAS that improves detection accuracy by incorporating flow arrival patterns. We present a rigorous error bound analysis for both PALLAS and OPT-PALLAS, along with extensive performance evaluations using a P4-based prototype on an Intel Tofino switch. PALLAS scales persistent flow detection to line-rate capacity, while state-of-the-art solutions fail to operate beyond a few Mbps. Our results show that PALLAS and OPT-PALLAS can accurately detect persistent flows in traffic volumes over 60× higher than those handled by the best existing approach. Additionally, even under low-speed traffic, PALLAS and OPT-PALLAS achieve 4.21% and 7.85% higher lookup accuracy while consuming only 8.5% and 9.7% of switch resources, respectively. Extensive trace-driven results on a CPU platform further validate the high detection accuracy of OPT-PALLAS compared to existing methods.es
dc.language.isoenges
dc.titlePallas: A Data-Plane-Only Approach to Accurate Persistent Flow Detection on Programmable Switches in High-Speed Networkses
dc.typeconference objectes
dc.conference.date22-25 September 2025es
dc.conference.placeSeoul, South Koreaes
dc.conference.titleIEEE International Conference on Network Protocols*
dc.event.typeconferencees
dc.pres.typepaperes
dc.type.hasVersionAMes
dc.rights.accessRightsopen accesses
dc.description.refereedTRUEes
dc.description.statusinpresses


Files in this item

This item appears in the following Collection(s)

Show simple item record