|
Towards Accelerating Intrusion Detection
, q2 b j2 m& |- lOperations at the Edge Network using FPGAs
) y2 D) Z; y& `4 L( W8 k f+ E2 I4 b$ k
$ o8 m1 t* [3 G" B: G) w
. u5 v* Z* G9 D( ~: L0 | In the current paper, we present our work towards
6 {1 V' y8 }' x& \5 A5 Iaccelerating intrusion detection operations at the edge network 7 E- `5 U% C0 O4 e" J( h! b
using FPGAs. Cloud computing and network function 2 Z2 W# ^$ W( z" d* x9 @; R7 R
virtualization have led to a new appealing paradigm for service 6 K. J% v& P7 @3 c0 k9 v2 Z
delivery and management. Unfortunately, this paradigm fails 1 _- I5 A# H( L0 q
to correctly support IoT applications and services that seek
# [ z! a2 e+ G& n$ O9 V, [' a" B" zbetter communication platforms. Security as a Service can also % A: o) @' U: R- M% N
be seen as a cloud-based model that needs to be accommodated ) i! L; `" ]0 V" o6 P9 k
to fulfill these services requirements. Again, one of the main
' {8 j" w& d' f9 B' u5 C& Fissues to be addressed in this context is how to improve the
9 l- _! H" H) S; g1 Zperformance of such systems or services in order to make them
1 R$ T# j' e8 I6 bcapable of coping with the huge amount of data while
; ]: K/ k" o5 T5 b) p4 V4 jremaining reliable. A potential solution is the FPGA based
6 A9 e4 w1 z7 X, z# q' t9 Wedge computing, which is a powerful combination offering
! B: A" y) v2 ~) g: vFPGA acceleration capabilities together with edge and fog & O# h: w, w' p6 L& X! D
benefits. Indeed, our work focusses on devising an Intrusion ; t, k2 g8 D$ ]' A
Prevention architecture called FORTISEC (40SEC), that is 8 b8 I6 G; Z. W+ ?. r
meant to operate in a completely softwarized as well as in an
f `1 O; z: K5 C( HFPGA mode. Thereby, we present suitable algorithms, design
9 K1 ] s$ _) R; oprinciples and well defined components towards the
1 |- G; T6 b7 ~* c0 M% S* mimplementation of accelerated intrusion prevention on the
$ ?0 _7 }$ ?7 o$ ~: Dedge. We also present a testbed being utilized for the 3 f( p( i# k3 r$ b% v) F+ T
implementation of 40SEC and its performance testing.
4 A9 W) q3 a) h9 c* V# `) L- a6 D, ]& j8 v1 d5 U5 y# e
7 S( Z l1 G0 X* j6 g |