Analysis of Possibilities of Intrusion Prevention Systems Acceleration with Use of FPGA-Based SmartNIC
摘要
The analysis of the possible Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) is performed. The possible variants of the cyberincident are considered. The methods of detection are classified. The use of both signature method and anomaly detection method for such systems are considered. The possibility of acceleration and offloading of datacenters using SmartNIC is discussed. The existing solutions for intrusion detection with the use of SmartNIC based on of Field Programmable Gate Array (FPGA) are investigated. The possibility of the use of FPGA accelerator cards to improve the performance of the server for such systems is considered. The architecture of hardware-based implementation of the intrusion prevention system with use of FPGA is proposed. The sequence of steps for creation of FPGA-based implementation of intrusion prevention systems is proposed.