Inline DPI and Blacklist Matching: Hardware-based Flow Classification Use Cases

Enable High Performance, Low Latency, Scalability and Precision

Implementing flow classification functions in an FPGA (as opposed to software) enables the highest performance, lowest latency, scalability and precision required in sophisticated, mission critical network monitoring and security applications.

Accolade Technology provides the most technologically advanced 1-100GE FPGA-based, lossless packet capture and acceleration adapters that help accelerate network/cyber security and monitoring applications.  Accolade’s advanced ANIC adapters are fully PCIe compliant and seamlessly integrate into standard servers offered by companies such as Cisco, Dell, HP, Super Micro and others.

The following are a few high-level flow classification characteristics offered with ANIC adapters:

  • Can track up to 32 million unique IP flows per adapter
  • Actions such as forward, drop or redirect can be requested on a per flow basis
  • Both directions of a flow are tracked and recorded
  • Information such as total packet count, byte count and the last time a packet was seen is maintained for every flow

Use Cases:

Inline Deep Packet Inspection (Inline DPI)

Flow classification can be used as a mechanism to selectively drop unwanted flows in live network traffic. The flows could be dropped for many reasons for instance if they are deemed malicious or if they violate some terms of service.

Blacklist Matching

Flow classification can be used to drop or block known bad IP addresses (IPv4 or IPv6). In this scenario, the host application provides the ANIC adapter (via the API) a list of IP addresses and if the source IP address of a flow matches one of the IP addresses in the blacklist, the flow is immediately dropped or blocked and the payload data is sent to the host application for analysis.

About Accolade

Accolade is the technology leader in FPGA-based Host CPU Offload and 100% Packet Capture PCIe NIC’s and Scalable 1U Platforms. Accolade’s line of 1-100GE products enable 100% packet capture, flow classification, flow shunting, deduplication, packet filtering and more. Our customers are global leaders in network monitoring & cybersecurity applications as well as in the network test and measurement, telecom and video stream monitoring markets.

FPGA Acceleration Features

100% Packet Capture | Flow Classification | Flow Shunting | Precise Time Stamping | Packet Merging | Packet Slicing | Packet Parsing | Packet Filtering | Deduplication | Host Packet Buffer | Packet Steering | Direct Memory Access (DMA) | Statistics (RMON1)

Free Product Evaluation

Resolve all your host CPU offload bottlenecks. Share Your Technical Requirements with our FPGA and software experts to tailor the optimal solution. Accolade offers a 60 day free product evaluation for qualified customers to fully test and evaluate our products.