Sketch Acceleration on FPGA and its Applications in Network Anomaly Detection
Sketch Acceleration on FPGA and its Applications in Network Anomaly Detection
复制标题
基于FPGA的草图加速及其在网络异常检测中的应用
DOI:
10.1109/tpds.2017.2766633
复制
发表时间:
2018-04
影响因子:
5.3
通讯作者:
Da Tong;V. Prasanna
中科院分区:
文献类型:
--
作者:
Da Tong;V. Prasanna
Sketch, a highly accurate data stream summarization technique, has gained much interest in the research community in recent years. Because of its sub-linear memory complexity, Sketch-based techniques consume significantly less memory than the traditional per-item-state techniques for processing high throughput data streams. One of the major applications of Sketch is in network anomaly detection, which is critical for network management and security in both Internet and data centers. In these applications, throughput is a key performance metric. Due to the low memory complexity, Sketch-based techniques can be supported by the fast on-chip storage of the state-of-the-art computing platforms to achieve high throughput. In this work, we first propose a generic architecture on FPGA to accelerate Sketch and adopt it to 2 widely used Sketches: Count-min Sketch and K-ary Sketch. We propose online Sketch-based algorithms for 2 key network anomaly detection tasks: heavy hitter detection and heavy change detection. We adopt the proposed generic architecture for Sketch to accelerate these online algorithms. The post place-and-route results on a state-of-the-art FPGA show that our generic architecture can accelerate both Count-min Sketch and K-ary Sketch to over 150 Gbps, demonstrating significant throughput performance improvements compared with other Sketch acceleration techniques. Our architectures for online anomaly detection tasks sustain 100-150 Gbps throughput for various system configurations.