NFA split architecture for fast regular expression matching

  • Authors:
  • Jan Kořenek;Vlastimil Košař

  • Affiliations:
  • Brno University of Technology, Brno, Czech Republic;Brno University of Technology, Brno, Czech Republic

  • Venue:
  • Proceedings of the 6th ACM/IEEE Symposium on Architectures for Networking and Communications Systems
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

Many hardware architectures have been designed to accelerate regular expression matching in network security devices, but most of them can achieve high throughput only for strings or small sets of regular expressions. We propose new NFA Split architecture which reduces the amount of consumed FPGA resources in order to match larger set of regular expressions. New algorithm is introduced to find non-collision sets of states and determine part of nondeter-ministic automaton which can be mapped to the memory based architecture. For all analysed sets of regular expressions, the algorithm was able to find non-collision sets with 67.8% of states in average and reduces the amount of consumed flip-flops to 37.6% and look-up tables to 63.9% in average.