arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

用于实时TCP-SYN扫描检测的高吞吐量FPGA架构

A High-Throughput FPGA Architecture for Real-Time TCP-SYN Scan Detection

Faisal Saeed, Mohammad Fahad, Ayesha Javaid, Christian Doerr, Muhammad Ali Siddiqi

arXiv 2609.14043首次发表:更新:

发表机构

Lahore University of Management Sciences; Hasso Plattner Institute(拉合尔管理科学大学; 哈索·普拉特纳研究所)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

提出一种轻量级FPGA架构,通过浅层布尔LUT树实现线速TCP-SYN扫描指纹检测,具有恒定两周期延迟和线性资源增长,在10 Gbps下仅用0.5% LUT,支持超2000个并发指纹,检测延迟10纳秒,零误报漏报。

AI 中文摘要

TCP-SYN端口扫描通常先于网络攻击发生,对嵌入在数据包头中的扫描器指纹进行早期检测可以提供及时的入侵警报。现有方法要么计算成本过高,无法满足线速运行要求,要么仅限于离线分析。本文提出了一种轻量级FPGA架构,用于可重构的线速指纹检测,其中每个指纹被编译成浅层布尔查找表(LUT)树,支持并行评估,无论指纹数量多少,均具有恒定的两周期延迟,而资源成本随指纹数量线性增长。该检测核心与MAC层前端解耦,前端执行流式字段提取,无需帧缓冲或更高层状态,从而只需修改前端即可在不同线速下部署。一个Python框架自动将布尔表达式编译为可综合的HDL,消除了手动RTL修改。对于TCP-SYN端口扫描指纹检测,在Versal VCK190上以10 Gbps速率部署18个指纹时,该架构使用约0.5%的LUT,支持超过2,000个并发指纹;在Virtex-6上以1 Gbps速率时,LUT使用率低于2.5%,两种速率下的检测延迟均为10纳秒,比软件入侵检测系统中典型的每包处理延迟低三到四个数量级。该系统在8小时生产数据包轨迹上针对软件重新实现进行了交叉验证,确认了检测正确性,零误报和零漏报。

英文摘要

TCP-SYN port scanning often precedes cyber-attacks, and early detection of scanner fingerprints embedded in packet headers can provide timely intrusion alerts. Existing approaches are either too computationally expensive for line-rate operation or limited to offline analysis. This brief presents a lightweight FPGA architecture for reconfigurable line-rate fingerprint detection, where each fingerprint is compiled into a shallow Boolean LUT tree, enabling parallel evaluation with constant two-cycle latency regardless of fingerprint count, while resource cost grows linearly with fingerprint count. This detection core is decoupled from a MAC-layer frontend that performs streaming field extraction with no frame buffering or higher-layer state, allowing deployment across different line rates by modifying only the frontend. A Python framework automatically compiles Boolean expressions into synthesizable HDL, eliminating manual RTL changes. For TCP-SYN port-scan fingerprint detection, the architecture uses approximately 0.5% LUTs at 10 Gbps on a Versal VCK190 for 18 deployed fingerprints, with capacity for over 2,000 concurrent fingerprints, and under 2.5% on a Virtex-6 at 1 Gbps, with a detection latency of 10 ns at both rates, three to four orders of magnitude below typical per-packet processing latency in software intrusion-detection systems. The system was cross-validated against a software re-implementation on an 8-hour production packet trace, confirming detection correctness with zero false positives/negatives.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑