Scalable multigigabit pattern matching for packet inspection

Scalable multigigabit pattern matching for packet inspection
复制标题

DOI:
10.1109/tvlsi.2007.912036
复制
发表时间:
2008-02-01
影响因子:
2.8
通讯作者:
Vassiliadis, Stamatis
Vassiliadis, Stamatis
中科院分区:
工程技术2区
文献类型:
--
作者:
Sourdis, Ioannis;Pnevmatikatos, Dionisios N.;Vassiliadis, Stamatis

文献摘要

被引文献

相似文献

在本文中,我们考虑基于硬件的扫描和分析数据包有效载荷,以检测有害内容。我们提出两种模式匹配技术,以将传入数据包与入侵检测搜索模式进行比较。第一种方法是解码的部分凸轮(DPCAM),即传入的字符,将解码的数据对准并执行逻辑,并在它们上为每种模式产生匹配信号。第二种方法是完美的哈希内存(PHMEM),它使用完美的哈希来确定包含搜索模式的唯一内存位置以及传入的数据和内存输出之间的比较以确定匹配项。两种技术都非常适合可重构逻辑,并使用单个VirTex2现场可编程的栅极阵列设备匹配了大约2200个入侵检测模式。我们表明,DPCAM实现了每个搜索字符的2至8 Gb/s的吞吐量,需要0.58-2.57逻辑单元。另一方面,PHMEM设计可以使用几十个块RAM(630-1404 kb)和每个字符的逻辑单元仅0.28-0.65支持2-5.7 GB/s。我们在性能和区域成本方面评估了这两种方法,并分析了它们的效率,可扩展性和权衡。最后,我们表明,与以前的工作相比,我们的设计至少提高了30%的效率,以每个搜索字符所需的吞吐量测量。
In this paper, we consider hardware-based scanning and analyzing packets payload in order to detect hazardous contents. We present two pattern matching techniques to compare incoming packets against intrusion detection search patterns. The first approach, decoded partial CAM (DpCAM), predecodes incoming characters, aligns the decoded data, and performs logical AND on them to produce the match signal for each pattern. The second approach, perfect hashing memory (PHmem), uses perfect hashing to determine a unique memory location that contains the search pattern and a comparison between incoming data and memory output to determine the match. Both techniques are well suited for reconfigurable logic and match about 2200 intrusion detection patterns using a single Virtex2 field-programmable gate-array device. We show that DpCAM achieves a throughput between 2 and 8 Gb/s requiring 0.58-2.57 logic cells per search character. On the other hand, PHmem designs can support 2-5.7 Gb/s using a few tens of block RAMs (630-1404 kb) and only 0.28-0.65 logic cells per character. We evaluate both approaches in terms of performance and area cost and analyze their efficiency, scalability, and tradeoffs. Finally, we show that our designs achieve at least 30% higher efficiency compared to previous work, measured in throughput per area required per search character.