100 Gbps Hash-Based Reconfigurable Pattern Matching
Paper i proceeding, 2026

High-Throughput pattern matching is crucial to applications such as network intrusion detection systems (NIDS). However, a pattern-matching engine typically cannot exceed a few Gbps unless it processes the input stream at a large stride, meaning multiple bytes per cycle. This requires searching for each pattern at multiple starting offsets in parallel, which increases hardware cost proportionally. This paper presents a new pattern-matching design that addresses this scalability challenge by efficiently scanning an input stream with a large stride while searching thousands of patterns. The proposed solution partitions the matching problem using a grouping heuristic, then employs a hash-based matcher for each partition. Each matcher searches a mutually exclusive set of patterns at specific offsets and produces at most one match at a time. To minimize the number of groups, our technique exploits the fact that most pattern-offset pairs (POPs) are mutually exclusive, enabling larger groups spanning multiple offsets, greatly reducing the resource cost. For a stride of N=64, our approach yields about 1/4 fewer groups and an order of magnitude less pattern memory compared to the conventional method of replicating resources N times. This enables a single FPGA, for the first time to our knowledge, to achieve 100 Gbps guaranteed throughput regardless of input data, while matching the entire SNORT NIDS ruleset.

Författare

Magnus Östgren

Göteborgs universitet

Chalmers, Data- och informationsteknik, Datorteknik

Anna-Maria Unterberger

Chalmers, Data- och informationsteknik, Datorteknik

Göteborgs universitet

Ioannis Sourdis

Chalmers, Data- och informationsteknik, Datorteknik

Göteborgs universitet

Proceedings 2026 IEEE International Parallel and Distributed Processing Symposium Workshops Ipdpsw 2026

353-360
9798319530899 (ISBN)

2026 IEEE International Parallel and Distributed Processing Symposium Workshops, IPDPSW 2026
New Orleans, USA,

Principer för beräknande minnesenheter (PRIDE)

Stiftelsen för Strategisk forskning (SSF) (DnrCHI19-0048), 2021-01-01 -- 2025-12-31.

Ämneskategorier (SSIF 2025)

Kommunikationssystem

Datavetenskap (datalogi)

DOI

10.1109/IPDPSW71298.2026.00051

Mer information

Senast uppdaterat

2026-09-09