PAMO: Pattern Matching Offload for Intrusion Detection Systems
Lukáš Šišmiš, Colin Evrard, Etienne Rivière, Tom Barbette · 2025
Intrusion Detection Systems (IDS) play a crucial role in network security. An IDS recognizes malicious activity in network traffic by matching it against patterns defined in a set of rules. The complexity and size of rule sets lead to substantial computational load. In a state-of-the-art IDS, such as Suricata, a single CPU core processes a few hundred MB to a few GB of network traffic per second, and rule evaluation accounts for over 60% of CPU consumption. Scaling IDS to today's high-speed networks is, therefore, a significant challenge.