FLARE: An FPGA-Based Universal Large Flow Detection Engine
摘要
Detecting large flows in high-speed networks is a persistent challenge in network security, often hampered by processing speed, memory demands, and the need for versatile handling of a range of attack vectors. The emergence of FPGA-based solutions offers promising prospects for real-time, scalable network security. Yet, precise detection of diverse large flow attacks introduces significant complexity and calls for the coordination of multiple independent detection algorithms. This paper presents FLARE, a large flow detection framework designed to address these challenges by integrating multiple detection algorithms into a unified system. FLARE can monitor network flows in real-time, handling data rates of up to 200 Gbps, and employs a shared architecture that minimizes resource usage while enhancing detection accuracy and coordination. The proof-of-concept implementation on the Alveo U250 data center accelerator shows that FLARE can process an entire packet in every clock cycle, irrespective of the throughput of the employed detection algorithms. Beyond large flow detection, FLARE provides a versatile and scalable platform applicable to a broad spectrum of network security applications.