NOS-Gate: Queue-Aware Streaming IDS for Consumer Gateways under Timing-Controlled Evasion
Muhammad Bilal, Omer Tariq, Hasan Ahmed

TL;DR
NOS-Gate is a lightweight, queue-aware streaming intrusion detection system for encrypted consumer gateways that effectively detects timing-based evasion attacks with minimal latency and resource overhead.
Contribution
It introduces NOS-Gate, a novel queue-aware streaming IDS using a two-state model for encrypted traffic, improving detection accuracy and latency under resource constraints.
Findings
Achieves 0.952 incident recall at 0.1% false positives.
Reduces queueing delay and collateral delay significantly.
Operates with a mean scoring cost of ~2.09 microseconds per flow-window.
Abstract
Timing and burst patterns can leak through encryption, and an adaptive adversary can exploit them. This undermines metadata-only detection in a stand-alone consumer gateway. Therefore, consumer gateways need streaming intrusion detection on encrypted traffic using metadata only, under tight CPU and latency budgets. We present a streaming IDS for stand-alone gateways that instantiates a lightweight two-state unit derived from Network-Optimised Spiking (NOS) dynamics per flow, named NOS-Gate. NOS-Gate scores fixed-length windows of metadata features and, under a -of- persistence rule, triggers a reversible mitigation that temporarily reduces the flow's weight under weighted fair queueing (WFQ). We evaluate NOS-Gate under timing-controlled evasion using an executable 'worlds' benchmark that specifies benign device processes, auditable attacker budgets, contention structure, and…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInternet Traffic Analysis and Secure E-voting · Security and Verification in Computing · Software-Defined Networks and 5G
