Membrane Systems (or P Systems) are a computational paradigm, inspired by the biological cell, that focuses on information processing through the use and formalization of distributed and parallel structures separated by membranes. Within these systems, a set of objects evolves through rules that modify and communicate them among regions. The work aims to formalize a Membrane System for the analysis of network traffic to detect volumetric anomalies within a packet-switched computer network, and classify them. We focus on two volumetric anomalies, i.e., Elephant Flow and DDoS, and on a high-cardinality anomaly, i.e., Super-Spreader, which is volumetric-by-effect. All these anomalies are typically related to well-known network attacks. After formalizing the model, an implementation on GPU using the CUDA platform is proposed, and compared to a CPU implementation. The reported results provide deep insights into the proposed model, highlighting its scalability and showing its ability in identifying and adapting to different scenarios of attacks, especially when they do not occur simultaneously, provided a correct tuning of the parameters. Experiments on a real trace show a very good detection performance for Elephant Flow and Super-Spreader anomalies (up to 0.95 F1 score), while the model struggles more in the detection of DDoS traffic (0.71 F1 score). The use of GPU for computation has proven to be well-suited for parallel processing tasks, such as those naturally enabled by Membrane Computing, strongly outperforming the use of CPU, with a time speedup of about 50 times versus the CPU. Understanding the characteristics and performance of this approach, as well as the alternatives proposed within the context of Membrane Computing, could open pathways to new strategies for networking system protection and guide future development of Network-based Intrusion Detection Systems based on P Systems.

Campanella, S., Ermini, I., Savi, M., Zandron, C. (2026). Membrane computing for the identification of network traffic anomalies in communication networks. INTEGRATED COMPUTER-AIDED ENGINEERING [10.1177/10692509261478419].

Membrane computing for the identification of network traffic anomalies in communication networks

Savi, Marco;Zandron, Claudio
2026

Abstract

Membrane Systems (or P Systems) are a computational paradigm, inspired by the biological cell, that focuses on information processing through the use and formalization of distributed and parallel structures separated by membranes. Within these systems, a set of objects evolves through rules that modify and communicate them among regions. The work aims to formalize a Membrane System for the analysis of network traffic to detect volumetric anomalies within a packet-switched computer network, and classify them. We focus on two volumetric anomalies, i.e., Elephant Flow and DDoS, and on a high-cardinality anomaly, i.e., Super-Spreader, which is volumetric-by-effect. All these anomalies are typically related to well-known network attacks. After formalizing the model, an implementation on GPU using the CUDA platform is proposed, and compared to a CPU implementation. The reported results provide deep insights into the proposed model, highlighting its scalability and showing its ability in identifying and adapting to different scenarios of attacks, especially when they do not occur simultaneously, provided a correct tuning of the parameters. Experiments on a real trace show a very good detection performance for Elephant Flow and Super-Spreader anomalies (up to 0.95 F1 score), while the model struggles more in the detection of DDoS traffic (0.71 F1 score). The use of GPU for computation has proven to be well-suited for parallel processing tasks, such as those naturally enabled by Membrane Computing, strongly outperforming the use of CPU, with a time speedup of about 50 times versus the CPU. Understanding the characteristics and performance of this approach, as well as the alternatives proposed within the context of Membrane Computing, could open pathways to new strategies for networking system protection and guide future development of Network-based Intrusion Detection Systems based on P Systems.
Articolo in rivista - Articolo scientifico
Membrane Computing, network Intrusion Detection Systems, distributed Denial-of-Service, GPU
English
3-set-2026
2026
none
Campanella, S., Ermini, I., Savi, M., Zandron, C. (2026). Membrane computing for the identification of network traffic anomalies in communication networks. INTEGRATED COMPUTER-AIDED ENGINEERING [10.1177/10692509261478419].
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/10281/625521
Citazioni
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
Social impact