P4-NIDS: High-Performance Network Monitoring and Intrusion Detection in P4
Yaying Chen, Siamak Layeghy, Liam Daly Manocchio, Marius Portmann

TL;DR
This paper introduces P4-NIDS, a high-performance, scalable in-band network monitoring and intrusion detection system implemented in P4, capable of handling Terabit network speeds with minimal impact on throughput.
Contribution
It presents a novel in-band monitoring and intrusion detection system in P4 that achieves high accuracy and scalability in high-speed network environments.
Findings
Maintains negligible impact on throughput at 8 million packets per second
Outperforms state-of-the-art solutions in accuracy and scalability
Supports real-world P4 hardware deployment
Abstract
This paper presents a high-performance, scalable network monitoring and intrusion detection system (IDS) implemented in P4. The proposed solution is designed for high-performance environments such as cloud data centers, where ultra-low latency, high bandwidth, and resilient infrastructure are essential. Existing state-of-the-art (SoA) solutions, which rely on traditional out-of-band monitoring and intrusion detection techniques, often struggle to achieve the necessary latency and scalability in large-scale, high-speed networks. Unlike these approaches, our in-band solution provides a more efficient, scalable alternative that meets the performance needs of Terabit networks. Our monitoring component captures extended NetFlow v9 features at wire speed, while the in-band IDS achieves high-accuracy detection without compromising on performance. In evaluations on real-world P4 hardware, both…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Advanced Malware Detection Techniques
