A Hardware-Accelerated L7-filter Method for 100Gbps Networks

Wen-liang FU,Ping GUO,Zhou ZHOU
DOI: https://doi.org/10.3969/j.issn.0372-2112.2016.11.001
2016-01-01
Abstract:L7-filter is a widely used traffic classification system which relies on regular expression matching based deep packet inspect method and can identify network traffic by inspecting string patterns hidden in the packet payload.How-ever,due to considerable computation and storage expenditures,existing L7-filter software and hardware solutions could not offer sufficient performance in the context of 40 Gbps and higher speed networks.Based on analysis of common features of the L7-filter protocol patterns,this paper proposes a hardware-accelerated method which is for achieving high performance and includes customized data structure,optimization and matching architecture.To validate the proposed method,a hardware prototype on Virtex 6 FPGA card is implemented and tested.Experimental results show that the prototype can scan network traffic at a typical rate of about 115Gbps.
What problem does this paper attempt to address?