A look under the hood: Revealing performance issues in the DPI engine

Wesley Melo, Stênio Fernandes, Rafael Antonello, Djamel Fawzi Hadj Sadok, Judith Kelner, Géza Szabó · 2013

Compressed Deterministic Finite Automata (DFA) promises same representation power as traditional DFAs while using less memory for representing Regular Expressions (RE). Experimental evaluations of DFA-based Deep Packet Inspection (DPI) systems focus mainly on memory consumption without observing other important related aspects, such as the matching speed. Proper design of DPI systems requires the assessment of several performance metrics at hardware level, in order to make sure that its implementation will not compromise the overall performance. This paper proposes a novel and systematic evaluation of DPIs and reveals the impact of DFA's data-structures and the correspondent memory layout implementation to hardware-level metrics. Experimental results show that some DFA model and memory layout combinations are almost 100 times faster than others. Results also show that choosing the incorrect model-layout pair can lead to significant performance issues. Our methodology and results will certainly help researchers and developers to design efficient DPI engines, through the selection of the best DFA model and memory layout combination to achieve the targeted overall performance.

Read the paper · More papers on PaperTik