Suricata With Rte_flow: Improving the Performance of IPS and IDS With Hardware Acceleration
DPDK Project via YouTube
Overview
Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Discover how to accelerate Intrusion Detection and Prevention Systems (IDS/IPS) in high-speed network environments in this conference talk by Adam Kiripolský and Eliška Červinková from Cesnet. Learn about enhancing Suricata's performance using DPDK's rte_flow API for hardware acceleration. Explore various optimization techniques including encapsulation stripping, filtering user-predefined traffic, and dynamic insertion of rte_flow rules to bypass undesired flows such as elephant or encrypted flows. See how adding a prefiltration step directly to the network card enhances Suricata's existing software filtering capabilities. Examine the evaluation process using Suricata-CI, an open-source toolset for testing Suricata with different traffic profiles, and review the performance improvements achieved through hardware acceleration in high-speed network analysis.
Syllabus
Suricata With Rte_flow: Improving the Performance of IPS an... - Adam Kiripolský & Eliška Červinková
Taught by
DPDK Project