Publication:

RustiFlow: Bridging the Gap Between Security Research and Practice using eBPF-based Network Flow Extraction

 
cris.virtual.department#PLACEHOLDER_PARENT_METADATA_VALUE#
cris.virtual.department#PLACEHOLDER_PARENT_METADATA_VALUE#
cris.virtual.department#PLACEHOLDER_PARENT_METADATA_VALUE#
cris.virtual.department#PLACEHOLDER_PARENT_METADATA_VALUE#
cris.virtual.department#PLACEHOLDER_PARENT_METADATA_VALUE#
cris.virtual.orcid0000-0003-2618-3311
cris.virtual.orcid0000-0003-4824-1199
cris.virtual.orcid0000-0003-0575-5894
cris.virtual.orcid0000-0002-1781-900X
cris.virtual.orcid0000-0001-5086-6361
cris.virtualsource.departmentcc837ec8-2eb7-46b6-90d8-480d745c3fcc
cris.virtualsource.department505a9fa2-2261-4859-8c77-73c2ba21244c
cris.virtualsource.departmentbe209fe9-cb8c-4c91-821b-9c93bd548ca7
cris.virtualsource.departmentf4004503-5b5c-4de1-b15e-4766bab29002
cris.virtualsource.department5063d8d4-e483-4a33-a1cc-4024ee18d9f0
cris.virtualsource.orcidcc837ec8-2eb7-46b6-90d8-480d745c3fcc
cris.virtualsource.orcid505a9fa2-2261-4859-8c77-73c2ba21244c
cris.virtualsource.orcidbe209fe9-cb8c-4c91-821b-9c93bd548ca7
cris.virtualsource.orcidf4004503-5b5c-4de1-b15e-4766bab29002
cris.virtualsource.orcid5063d8d4-e483-4a33-a1cc-4024ee18d9f0
dc.contributor.authorVerkerken, Miel
dc.contributor.authorCallewaert, Matisse
dc.contributor.authorD'hooge, Laurens
dc.contributor.authorWauters, Tim
dc.contributor.authorVolckaert, Bruno
dc.contributor.authorDe Turck, Filip
dc.date.accessioned2026-06-10T10:26:10Z
dc.date.available2026-06-10T10:26:10Z
dc.date.createdwos2025-11-25
dc.date.issued2025
dc.description.abstractLarge organizations generate billions of network flows daily, creating a high-velocity data challenge for modern security monitoring and threat detection. Researchers frequently develop custom flow extraction tools tailored for AI-driven security analyses, but these solutions often lack the performance, scalability, and interoperability required for real-world use. At the same time, existing production-ready flow extractors lack flexibility and customization, limiting their application for advanced security research. To bridge this gap, we introduce RustiFlow, an open-source, eBPF-based network flow feature extractor developed in Rust. Designed for both research and operational deployments, RustiFlow delivers high throughput, realtime processing, and modular feature extraction, ensuring adaptability across diverse security applications. Our performance evaluation demonstrates that RustiFlow outperforms established extractors such as NFStream, nProbe, and CICFlowMeter, offering the fastest offline PCAP processing and zero packet loss while monitoring a multi-gigabit interface under load, while maintaining minimal resource overhead. Real-world case studies in a university data center and a network security testbed validate RustiFlow's reliability, efficiency, and practical applicability. During a 24-hour test in a data center, RustiFlow processed over 1 billion packets and 5.8TB of traffic with zero packet loss, while maintaining stable resource usage. In an adversarial security scenario, it operated with negligible resource consumption, demonstrating its efficiency for constrained environments. RustiFlow has the potential to become an essential tool for AI-based network security analysis, empowering future research and closing the gap between research and practice.
dc.description.wosFundingTextThis work is supported by the Belgian Chancellery of the Prime Minister (Grant: AIDE-BOSA).
dc.identifier.doi10.1109/eurospw67616.2025.00030
dc.identifier.isbn979-8-3315-9547-0
dc.identifier.issn2768-0649
dc.identifier.urihttps://imec-publications.be/handle/20.500.12860/59656
dc.language.isoeng
dc.provenance.editstepusergreet.vanhoof@imec.be
dc.publisherIEEE COMPUTER SOC
dc.source.beginpage203
dc.source.conferenceIEEE European Symposium on Security and Privacy Workshops (EuroS&PW)
dc.source.conferencedate2025-06-30
dc.source.conferencelocationVenice
dc.source.endpage216
dc.source.journal2025 IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS, EUROS&PW
dc.source.numberofpages14
dc.title

RustiFlow: Bridging the Gap Between Security Research and Practice using eBPF-based Network Flow Extraction

dc.typeProceedings paper
dspace.entity.typePublication
imec.internal.crawledAt2026-04-07
imec.internal.sourcecrawler
imec.internal.wosCreatedAt2026-04-07
Files
Publication available in collections: