Belén Brandino

dblp:397/3469 · DBLP profile ↗
← Back
1ranked-venue papers
1as first author
1since 2021 · last 2024
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 1 · 1 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer networks
1 paper
Software-defined and programmable networks · 87% Network measurement and analytics · 13%
Network and information security
1 paper
Network security · 100%

Topics — the 5 heaviest of 5, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Software-defined and programmable networks › programmable data plane
p4
0.812024
Detecting Attacks at Switching Speed: Ai/Ml and Active Learning for in-Network Monitoring in Data Planes · ICNP 2024
Software-defined and programmable networks
programmable data plane
0.812024
Detecting Attacks at Switching Speed: Ai/Ml and Active Learning for in-Network Monitoring in Data Planes · ICNP 2024
Network security › intrusion detection and prevention › intrusion detection › network intrusion detection
in-network intrusion detection
0.812024
Detecting Attacks at Switching Speed: Ai/Ml and Active Learning for in-Network Monitoring in Data Planes · ICNP 2024
Network security › intrusion detection and prevention
intrusion detection
0.812024
Detecting Attacks at Switching Speed: Ai/Ml and Active Learning for in-Network Monitoring in Data Planes · ICNP 2024
Network measurement and analytics
traffic analysis
0.212024
Detecting Attacks at Switching Speed: Ai/Ml and Active Learning for in-Network Monitoring in Data Planes · ICNP 2024

Methods — techniques the papers use, named apart from their topics

machine learning · 1.5active learning · 1.5
YearPublicationVenuePosition
2024 Detecting Attacks at Switching Speed: Ai/Ml and Active Learning for in-Network Monitoring in Data Planes
abstract
Early decision-making at the network device is crucial for network security. This entails moving beyond traditional forwarding functions towards more intelligent network devices. One possible strategy to speed up decision-making is to incorporate intelligent traffic analysis functionality directly into the data plane, such that traffic can be analyzed before forwarding. Integrating Artificial Intelligence/Machine Learning (AI/ML) models into the data plane enables quicker processing and reduced reliance on the control plane. We address the development of an AI/ML-driven Intrusion Detection System (IDS) where network devices autonomously make security decisions or defer to an expert oracle, relying on in-band and off-band traffic analysis. Programmable devices, such as those using P4, are essential to enable these functionalities and allow for network device retraining to adapt to changing traffic patterns. We introduce HALIDS, a prototype for in-band AI/ML-IDS using P4, complemented with off-band oracles which support in-network ML-driven classification with more confident classifications, targeting an active learning logic for more accurate in-band analysis. We implement HALIDS using the open source software switch BMv2, and show its operation with real traffic traces publicly available. Evaluation results show that the proposed system is sound and could be implemented in a real network as an efficient and highly adaptive security mechanism.
Belén Brandino, Pedro Casas, Eduardo Grampín
ICNP1