High-speed links make full-fidelity security monitoring expensive. Uniform sampling reduces the load, but the rare, security-relevant traffic that analysts care about most tends to disappear along with the rest.
Approach
XNET uses Linux’s eXpress Data Path (XDP) to dynamically prioritize security-relevant traffic directly in the kernel’s fast path, on commodity hardware. Traffic that matters for detection is kept at higher fidelity, while bulk traffic is sampled down.
Early results
- In a real-world deployment, XNET reduced traffic volume by up to 84% while increasing the visibility of otherwise negligible traffic fivefold.
- Controlled tests scale to 100 Gbps.
This work is currently under review; more details will be shared after publication.