In this study, we propose a novel, hardware-efficient non-cryptographic (NC) hash function, developed using Cartesian Genetic Programming (CGP), to optimize the processing of network flows (e.g., 96-bit vectors in IPv4). With the advent of high-speed terabit Ethernet technologies such as 800G, cybercriminals are increasingly exploiting these networks to launch various attacks, including distributed denial-of-service (DDoS) attacks. To counter these threats, network security applications often employ probabilistic data structures (PDS), such as Bloom filters and Count Min sketches, to monitor network flows. These applications are often deployed on Field Programmable Gate Arrays (FPGAs) to meet real-time processing demands. The performance of PDS depends significantly on the efficiency of NC-hash functions. By utilizing avalanche metrics (avalanche dependence, avalanche weight, and entropy) as the fitness function, CGP-hash ensures robust performance without the need for dataset-specific training. While Genetic Programming (GP)-based NC-hash functions have demonstrated superior computational efficiency on FPGAs in terms of operating frequency, throughput, and latency, they are often less resource-efficient compared to state-of-the-art NC-hash functions. Thus, our hypothesis in this paper is that CGP, with its compact representation, leads to NC hashes with high computational efficiency and fewer resources on an FPGA. Our experimental results confirm that CGP-hash improves computational efficiency by at least 7.3% while improving area efficiency by 4.5 \(\times \) compared to state-of-the-art NC-hash functions. This makes CGP-hash more suitable for FPGA implementations than other bio-inspired and handcrafted hash functions. Moreover, the 48-bit hash output can be extended by evolving additional hash functions and concatenating their outputs, all while maintaining superior resource efficiency and computational speed.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Designing Hardware-Friendly Hash Functions for Network Security Using Cartesian Genetic Programming

  • Mujtaba Hassan,
  • Jo Vliegen,
  • Stjepan Picek,
  • Nele Mentens

摘要

In this study, we propose a novel, hardware-efficient non-cryptographic (NC) hash function, developed using Cartesian Genetic Programming (CGP), to optimize the processing of network flows (e.g., 96-bit vectors in IPv4). With the advent of high-speed terabit Ethernet technologies such as 800G, cybercriminals are increasingly exploiting these networks to launch various attacks, including distributed denial-of-service (DDoS) attacks. To counter these threats, network security applications often employ probabilistic data structures (PDS), such as Bloom filters and Count Min sketches, to monitor network flows. These applications are often deployed on Field Programmable Gate Arrays (FPGAs) to meet real-time processing demands. The performance of PDS depends significantly on the efficiency of NC-hash functions. By utilizing avalanche metrics (avalanche dependence, avalanche weight, and entropy) as the fitness function, CGP-hash ensures robust performance without the need for dataset-specific training. While Genetic Programming (GP)-based NC-hash functions have demonstrated superior computational efficiency on FPGAs in terms of operating frequency, throughput, and latency, they are often less resource-efficient compared to state-of-the-art NC-hash functions. Thus, our hypothesis in this paper is that CGP, with its compact representation, leads to NC hashes with high computational efficiency and fewer resources on an FPGA. Our experimental results confirm that CGP-hash improves computational efficiency by at least 7.3% while improving area efficiency by 4.5 \(\times \) compared to state-of-the-art NC-hash functions. This makes CGP-hash more suitable for FPGA implementations than other bio-inspired and handcrafted hash functions. Moreover, the 48-bit hash output can be extended by evolving additional hash functions and concatenating their outputs, all while maintaining superior resource efficiency and computational speed.