The analysis of the possible Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) is performed. The possible variants of the cyberincident are considered. The methods of detection are classified. The use of both signature method and anomaly detection method for such systems are considered. The possibility of acceleration and offloading of datacenters using SmartNIC is discussed. The existing solutions for intrusion detection with the use of SmartNIC based on of Field Programmable Gate Array (FPGA) are investigated. The possibility of the use of FPGA accelerator cards to improve the performance of the server for such systems is considered. The architecture of hardware-based implementation of the intrusion prevention system with use of FPGA is proposed. The sequence of steps for creation of FPGA-based implementation of intrusion prevention systems is proposed.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Analysis of Possibilities of Intrusion Prevention Systems Acceleration with Use of FPGA-Based SmartNIC

  • Artem Tetskyi,
  • Artem Perepelitsyn

摘要

The analysis of the possible Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) is performed. The possible variants of the cyberincident are considered. The methods of detection are classified. The use of both signature method and anomaly detection method for such systems are considered. The possibility of acceleration and offloading of datacenters using SmartNIC is discussed. The existing solutions for intrusion detection with the use of SmartNIC based on of Field Programmable Gate Array (FPGA) are investigated. The possibility of the use of FPGA accelerator cards to improve the performance of the server for such systems is considered. The architecture of hardware-based implementation of the intrusion prevention system with use of FPGA is proposed. The sequence of steps for creation of FPGA-based implementation of intrusion prevention systems is proposed.