{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,2]],"date-time":"2026-02-02T10:47:20Z","timestamp":1770029240199,"version":"3.49.0"},"reference-count":38,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2026,2,2]],"date-time":"2026-02-02T00:00:00Z","timestamp":1769990400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,2,2]],"date-time":"2026-02-02T00:00:00Z","timestamp":1769990400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>Packet classification is a cornerstone of network security functions, such as firewalls, access control, and network metering. It involves taking different actions on packets based on security rules to implement these network security functions. As networks continue to evolve and the number of network instances rapidly increases, the complexity and size of network security rule sets are also expanding. Additionally, autonomous defense systems with artificial intelligence that can detect and block online attacks have become a new trend in network security. Packet classifiers need to not only achieve fast rule matching under large rule sets but also support rapid rule updates in order to deploy security rules issued by online defense systems in a timely manner. However, existing packet classification methods struggle to balance lookup speed with update performance. To achieve rapid rule matching and support fast rule updates in networks, we propose a novel approach called the Learned Index Updatable Tree (LIPT) to address this challenge. LIPT partitions the rule set into single-field non-overlapping subsets and constructs dynamic learned index trees for each subset using keys obtained by sampling. To implement rule updates directly within the learned index tree without reconstruction, LIPT employs a gap array layout in the data nodes, which reserves space for rule insertion. To enhance lookup and update performance, LIPT addresses the challenge of direct range validation in the data node through payload-assisted validation, which helps quickly identify lookup and insertion locations. Furthermore, LIPT employs a simple linear regression model to construct the learned index tree, enabling swift lookup based on the predictive results of the linear regression model; it also utilizes a cost model to simplify the construction process. We conduct a comprehensive evaluation of LIPT\u2019s performance, showing that both lookup and update speeds are significantly improved compared to existing algorithms that support rule updating. Compared to the benchmark algorithm PSTSS, LIPT\u2019s update speed increases by 25%, and its classification speed increases by 242%.<\/jats:p>","DOI":"10.1186\/s42400-025-00407-z","type":"journal-article","created":{"date-parts":[[2026,2,2]],"date-time":"2026-02-02T00:02:06Z","timestamp":1769990526000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Efficient packet classification with updatable learned index for online network defense"],"prefix":"10.1186","volume":"9","author":[{"given":"Yuqi","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4307-0896","authenticated-orcid":false,"given":"Chen","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zixuan","family":"Ma","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xuefei","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bibo","family":"Tu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,2,2]]},"reference":[{"key":"407_CR1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2020.107534","volume":"181","author":"H Alimohammadi","year":"2020","unstructured":"Alimohammadi H, Ahmadi M (2020) Common non-wildcard portion-based partitioning approach to sdn many-field packet classification. Comput Netw 181:107534","journal-title":"Comput Netw"},{"key":"407_CR2","doi-asserted-by":"crossref","unstructured":"Chen, X, Xiao Q, Liu H, Huang Q, Zhang D, Liu X, Hu L, Zhou H, Wu C, Ren K (2024) Eagle: Toward scalable and near-optimal network-wide sketch deployment in network measurement. In: Proceedings of the ACM SIGCOMM 2024 conference, ACM SIGCOMM \u201924, pp 291\u2013310, New York, NY, USA, Association for Computing Machinery","DOI":"10.1145\/3651890.3672244"},{"key":"407_CR3","doi-asserted-by":"crossref","unstructured":"Chen X, Liu H, Sun T, Huang Q, Zhang D, Liu X, Zhou B, Zhou H, Wu C (2023) Excalibur: a scalable and low-cost traffic testing framework for evaluating ddos defense solutions. In: IEEE INFOCOM 2023\u2014IEEE conference on computer communications, pp 1\u201310","DOI":"10.1109\/INFOCOM53939.2023.10229080"},{"issue":"4","key":"407_CR4","doi-asserted-by":"publisher","first-page":"1417","DOI":"10.1109\/TNET.2019.2920718","volume":"27","author":"J Daly","year":"2019","unstructured":"Daly J, Bruschi V, Linguaglossa L, Pontarelli S, Rossi D, Tollet J, Torng E, Yourtchenko A (2019) Tuplemerge: fast software packet processing for online packet classification. IEEE\/ACM Trans Network 27(4):1417\u20131431","journal-title":"IEEE\/ACM Trans Network"},{"key":"407_CR5","doi-asserted-by":"crossref","unstructured":"Daly J, Torng E (2018) Bytecuts: Fast packet classification by interior bit extraction. In: IEEE INFOCOM 2018\u2014IEEE conference on computer communications, pp 2654\u20132662","DOI":"10.1109\/INFOCOM.2018.8486215"},{"key":"407_CR6","doi-asserted-by":"crossref","unstructured":"Ding J, Minhas UF, Yu J, Wang C, Do J, Yinan Li, Zhang H, Chandramouli B, Gehrke J, Kossmann D, Lomet D, Kraska T (2020) Alex: An updatable adaptive learned index. In: Proceedings of the 2020 ACM SIGMOD international conference on management of data, SIGMOD \u201920, pp 969\u2013984, New York, NY, USA, Association for Computing Machinery","DOI":"10.1145\/3318464.3389711"},{"issue":"1","key":"407_CR7","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1109\/40.820051","volume":"20","author":"P Gupta","year":"2000","unstructured":"Gupta P, McKeown N (2000) Classifying packets with hierarchical intelligent cuttings. IEEE Micro 20(1):34\u201341","journal-title":"IEEE Micro"},{"key":"407_CR8","doi-asserted-by":"crossref","unstructured":"Jung C, Kim S, Jang R, Mohaisen D, Nyang D (2022) A scalable and dynamic acl system for in-network defense. In: Proceedings of the 2022 ACM SIGSAC conference on computer and communications security, CCS \u201922, pp 1679\u20131693, New York, NY, USA, Association for Computing Machinery","DOI":"10.1145\/3548606.3560606"},{"key":"407_CR9","doi-asserted-by":"crossref","unstructured":"Kraska T, Beutel A, Chi EH, Dean J, Polyzotis N (2018) The case for learned index structures. In: Proceedings of the 2018 international conference on management of data. SIGMOD \u201918, pp 489\u2013504, New York, NY, USA, Association for Computing Machinery","DOI":"10.1145\/3183713.3196909"},{"key":"407_CR10","doi-asserted-by":"crossref","unstructured":"Li, W, Li X (2013) Hybridcuts: A scheme combining decomposition and cutting for packet classification. In: 2013 IEEE 21st annual symposium on high-performance interconnects. pp 41\u201348","DOI":"10.1109\/HOTI.2013.12"},{"issue":"7","key":"407_CR11","doi-asserted-by":"publisher","first-page":"1555","DOI":"10.1109\/JSAC.2020.2986935","volume":"38","author":"W Li","year":"2020","unstructured":"Li W, Yang T, Rottenstreich O, Li X, Xie G, Li H, Vamanan B, Li D, Lin H (2020) Tuple space assisted packet classification with high performance on both search and update. IEEE J Sel Areas Commun 38(7):1555\u20131569","journal-title":"IEEE J Sel Areas Commun"},{"key":"407_CR12","doi-asserted-by":"crossref","unstructured":"Liang E, Zhu H, Jin X, Stoica I (2019) Neural packet classification. In: Proceedings of the ACM special interest group on data communication, SIGCOMM \u201919, pp 256-269, New York, NY, USA, Association for Computing Machinery","DOI":"10.1145\/3341302.3342221"},{"key":"407_CR13","doi-asserted-by":"crossref","unstructured":"Li W, Li X, Li H, Xie G (2018) Cutsplit: a decision-tree combining cutting and splitting for scalable packet classification. In: IEEE INFOCOM 2018\u2014IEEE conference on computer communications, pp 2645-2653. IEEE Press","DOI":"10.1109\/INFOCOM.2018.8485947"},{"issue":"3","key":"407_CR15","doi-asserted-by":"publisher","first-page":"1295","DOI":"10.1109\/TNET.2016.2533613","volume":"24","author":"AX Liu","year":"2016","unstructured":"Liu AX, Meiners CR, Torng E (2016) Packet classification using binary content addressable memory. IEEE\/ACM Trans Network 24(3):1295\u20131307","journal-title":"IEEE\/ACM Trans Network"},{"key":"407_CR16","unstructured":"Liu Z, Namkung H, Nikolaidis G, Lee J, Kim C, Jin X, Braverman V, Yu M, Sekar V (August 2021) Jaqen: a high-performance switch-native approach for detecting and mitigating volumetric DDoS attacks with programmable switches. In: 30th USENIX security symposium (USENIX Security 21), pp 3829\u20133846. USENIX Association"},{"key":"407_CR17","doi-asserted-by":"crossref","unstructured":"Liu Y, Xin Y, Li W, Song H, Rottenstreich O, Xie G, Li W, Wang Y (2022) Hybridtss: a recursive scheme combining coarse- and fine- grained tuples for packet classification. In: Proceedings of the 6th Asia-Pacific workshop on networking, APNet 2022, Fuzhou, China, July 1-2, 2022, pp 43\u201349. ACM","DOI":"10.1145\/3542637.3542644"},{"key":"407_CR18","doi-asserted-by":"crossref","unstructured":"Li W, Yang T, Chang Y-K, Li T, Li H (2019) Tabtree: a tss-assisted bit-selecting tree scheme for packet classification with balanced rule mapping. In: 2019 ACM\/IEEE symposium on architectures for networking and communications systems (ANCS), pp 1\u20138","DOI":"10.1109\/ANCS.2019.8901884"},{"key":"407_CR19","doi-asserted-by":"crossref","unstructured":"Narodytska N, Ryzhyk L, Ganichev I, Sevinc S (2019) Bdd-based algorithms for packet classification. In: 2019 Formal methods in computer aided design (FMCAD), pp 64\u201368","DOI":"10.23919\/FMCAD.2019.8894253"},{"issue":"2","key":"407_CR20","doi-asserted-by":"publisher","first-page":"657","DOI":"10.1109\/TNET.2018.2809583","volume":"26","author":"E Norige","year":"2018","unstructured":"Norige E, Liu AX, Torng E (2018) A ternary unification framework for optimizing tcam-based packet classification systems. IEEE\/ACM Trans Network 26(2):657\u2013670","journal-title":"IEEE\/ACM Trans Network"},{"key":"407_CR21","unstructured":"Pfaff B, Pettit J, Koponen T, Jackson E, Zhou A, Rajahalme J, Gross J, Wang A, Stringer J, Shelar P, Amidon K, Casado M (May 2015) The design and implementation of open vSwitch. In: 12th USENIX symposium on networked systems design and implementation (NSDI 15), pp 117\u2013130, Oakland, CA, USENIX Association"},{"key":"407_CR22","doi-asserted-by":"crossref","unstructured":"Qi S, Monis L, Zeng Z, Wang I-c, Ramakrishnan KK (2022) Spright: extracting the server from serverless computing! high-performance ebpf-based event-driven, shared-memory processing. In: Proceedings of the ACM SIGCOMM 2022 Conference, SIGCOMM \u201922, pp 780\u2013794, New York, NY, USA, Association for Computing Machinery","DOI":"10.1145\/3544216.3544259"},{"issue":"3","key":"407_CR23","doi-asserted-by":"publisher","first-page":"1230","DOI":"10.1109\/TNET.2022.3215143","volume":"31","author":"A Rashelbach","year":"2023","unstructured":"Rashelbach A, Rottenstreich O, Silberstein M (2023) Scaling by learning: accelerating open vswitch data path with neural networks. IEEE\/ACM Trans Netw 31(3):1230\u20131243","journal-title":"IEEE\/ACM Trans Netw"},{"key":"407_CR24","doi-asserted-by":"crossref","unstructured":"Rashelbach A, Rottenstreich O, Silberstein M (2020) A computational approach to packet classification. In: Proceedings of the annual conference of the ACM special interest group on data communication on the applications, technologies, architectures, and protocols for computer communication, SIGCOMM \u201920, pp 542\u2013556, New York, NY, USA, Association for Computing Machinery","DOI":"10.1145\/3387514.3405886"},{"key":"407_CR25","doi-asserted-by":"crossref","unstructured":"Singh S, Baboescu F, Varghese G, Wang J (2003) Packet classification using multidimensional cutting. In: Proceedings of the 2003 conference on applications, technologies, architectures, and protocols for computer communications, SIGCOMM \u201903, pp 213\u2013224, New York, NY, USA, Association for Computing Machinery","DOI":"10.1145\/863955.863980"},{"key":"407_CR26","doi-asserted-by":"crossref","unstructured":"Song E, Song Y, Lu C, Pan T, Zhang S, Lu J, Zhao J, Wang X, Wu X, Gao M, Li Z, Fang Z, Lyu B, Zhang P, Wen R, Yi L, Zong Z, Zhu S (2024) Canal mesh: A cloud-scale sidecar-free multi-tenant service mesh architecture. In: Proceedings of the ACM SIGCOMM 2024 Conference, ACM SIGCOMM \u201924, pp 860\u2013875, New York, NY, USA, Association for Computing Machinery","DOI":"10.1145\/3651890.3672221"},{"key":"407_CR27","doi-asserted-by":"crossref","unstructured":"Spitznagel E, Taylor D, Turner J (2003) Packet classification using extended tcams. In: 11th IEEE international conference on network protocols, 2003. Proceedings., p 120\u2013131","DOI":"10.1109\/ICNP.2003.1249762"},{"key":"407_CR28","doi-asserted-by":"crossref","unstructured":"Srinivasan V, Suri S, Varghese G (1999) Packet classification using tuple space search. In: Proceedings of the conference on applications, technologies, architectures, and protocols for computer communication, SIGCOMM \u201999, pp 135\u2013146, New York, NY, USA, Association for Computing Machinery","DOI":"10.1145\/316188.316216"},{"key":"407_CR29","doi-asserted-by":"crossref","unstructured":"Sun C, Xu K, Antichi G, Marina MK (November 2024) Netgsr: towards efficient and reliable network monitoring with generative super resolution. In: Proc. ACM Netw., 2(CoNEXT4)","DOI":"10.1145\/3696400"},{"issue":"3","key":"407_CR30","doi-asserted-by":"publisher","first-page":"238","DOI":"10.1145\/1108956.1108958","volume":"37","author":"DE Taylor","year":"2005","unstructured":"Taylor DE (2005) Survey and taxonomy of packet classification techniques. ACM Comput Surv 37(3):238\u2013275","journal-title":"ACM Comput Surv"},{"issue":"3","key":"407_CR31","doi-asserted-by":"publisher","first-page":"499","DOI":"10.1109\/TNET.2007.893156","volume":"15","author":"DE Taylor","year":"2007","unstructured":"Taylor DE, Turner JS (2007) Classbench: a packet classification benchmark. IEEE\/ACM Trans Netw 15(3):499\u2013511","journal-title":"IEEE\/ACM Trans Netw"},{"key":"407_CR32","unstructured":"Unger C, Jia Z, Wu W, Lin S, Baines M, Narvaez CEQ, Ramakrishnaiah V,Prajapati N, McCormick P, Mohd-Yusof J, Luo X, Mudigere D, Park J, Smelyanskiy M, Aiken A (July 2022) Unity: Accelerating DNN training through joint optimization of algebraic transformations and parallelization. In: 16th USENIX symposium on operating systems design and implementation (OSDI 22), pp 267\u2013284, Carlsbad, CA, USENIX Association"},{"key":"407_CR33","unstructured":"Vaughan-Nichols S (2023) Google cloud, aws, and cloudflare report largest ddos attacks ever. https:\/\/www.zdnet.com\/article\/microsoft-heres-how-we-stopped-the-biggest-ever-ddos-attack\/, Accessed on 10 Oct 2023"},{"key":"407_CR34","doi-asserted-by":"crossref","unstructured":"Wei C, Li X, Yang Y, Jiang X, Xu T, Yang B, Wu T, Xu C, Lv Y, Gao H, Zhang Z, Chen Z, Wang Z, Zhang Z, Zhu S, Chen W (2023) Achelous: Enabling programmability, elasticity, and reliability in hyperscale cloud networks. In: Proceedings of the ACM SIGCOMM 2023 Conference, ACM SIGCOMM \u201923, pp 769\u2013782, New York, NY, USA, Association for Computing Machinery","DOI":"10.1145\/3603269.3604859"},{"key":"407_CR35","doi-asserted-by":"crossref","unstructured":"Yingchareonthawornchai S, Daly J, Liu AX, Torng E (2016) A sorted partitioning approach to high-speed and fast-update openflow classification. In: 2016 IEEE 24th international conference on network protocols (ICNP), pp 1\u201310","DOI":"10.1109\/ICNP.2016.7784429"},{"key":"407_CR36","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2021.108630","volume":"202","author":"XWC Zhang","year":"2022","unstructured":"Zhang XWC, Xie G (2022) Dynamictuple: the dynamic adaptive tuple for high-performance packet classification. Comput Netw 202:108630","journal-title":"Comput Netw"},{"key":"407_CR37","doi-asserted-by":"crossref","unstructured":"Zhang H, Wu S, Pan J, Wang Z, Sun X (2024) A novel ddos detection model for sdn using single-class cluster oversampling and weighted ensemble method. In: 2024 IEEE 32nd international conference on network protocols (ICNP), pp 1\u20136","DOI":"10.1109\/ICNP61940.2024.10858549"},{"key":"407_CR38","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.comcom.2020.12.027","volume":"169","author":"J Zhong","year":"2021","unstructured":"Zhong J, Chen S (2021) Efficient multi-category packet classification using tcam. Comput Commun 169:1\u201310","journal-title":"Comput Commun"},{"issue":"5","key":"407_CR39","doi-asserted-by":"publisher","first-page":"2027","DOI":"10.1109\/TNET.2022.3227206","volume":"31","author":"J Zhong","year":"2023","unstructured":"Zhong J, Wei Z, Zhao S, Chen S (2023) Tupletree: a high-performance packet classification algorithm supporting fast rule-set updates. IEEE\/ACM Trans Netw 31(5):2027\u20132041","journal-title":"IEEE\/ACM Trans Netw"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00407-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-025-00407-z","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00407-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,2]],"date-time":"2026-02-02T00:02:15Z","timestamp":1769990535000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s42400-025-00407-z"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,2,2]]},"references-count":38,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,12]]}},"alternative-id":["407"],"URL":"https:\/\/doi.org\/10.1186\/s42400-025-00407-z","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,2,2]]},"assertion":[{"value":"11 February 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"2 April 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"2 February 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no Conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"22"}}