Netinfo Security ›› 2025, Vol. 25 ›› Issue (8): 1263-1275.doi: 10.3969/j.issn.1671-1122.2025.08.008

Previous Articles     Next Articles

Immune-Based Intrusion Detection Methods for Programmable Data Plane

SUN Nan1,2, QIN Zhongyuan1,3(), HU Aiqun1,3, LI Tao1,3   

  1. 1. School of Cyber Science and Engineering, Southeast University, Nanjing 211189, China
    2. PLA Army Academy of Artillery and Air Defense, Nanjing 211132, China
    3. Frontiers Science Center for Mobile Information Communication and Security, Southeast University, Nanjing 211189, China
  • Received:2024-06-20 Online:2025-08-10 Published:2025-09-09

Abstract:

This study, aiming at the prominent issue of performance bottlenecks in traditional intrusion detection systems, drawed inspiration from the higher biological immune system and broken through the architectural foundation of the shell-based defense approach in traditional intrusion detection systems. A bio-inspired immune intrusion detection method suitable for programmable data planes was designed. This method utilized the innate immune system to filter traffic, preliminarily intercepting some intrusive traffic. For traffic that remains suspicious, the bio-inspired adaptive immune system was activated to conduct deep feature collection, identification, and processing, achieving efficient detection of intrusive traffic. Experimental results demonstrate that this method can achieve high detection accuracy and low controller load.

Key words: bionic immunity, programmable data plane, intrusion detection, P4 language

CLC Number: