System and method for high speed pattern matching in multi core environment
Patent Information
- Application Number
- KR1020260104393
- Authority / Receiving Office
- KR · KR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2026-06-09
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2046-06-09
Smart Images

Figure 112026069762192-PAT00001_ABST
Abstract
Description
Technology Field
[0001] The present invention relates to a high-speed packet pattern matching system and method in a multi-core environment, and more specifically, to a system and method that improves the speed of pattern matching and uses resources efficiently while maximizing processing performance by allowing multiple execution flows to simultaneously and directly reference the same pattern matching data structure mapped to a shared memory area without redundant duplication of the data structure for pattern matching in a multi-core environment. Background Technology
[0002] High-performance network security equipment adopts a multi-core architecture as a prerequisite for processing traffic of gigabit or higher.
[0003] In conventional methods that perform pattern matching using a multi-core architecture, there was a problem where memory usage increased exponentially in proportion to the number of cores due to the redundant loading of pattern matching data structures with identical execution flows into individual memories. This is because pattern matching data structures are generated based on dynamic pointers.
[0004] In addition, there is a problem where performance degradation and service interruptions frequently occur because large-scale data is replicated to all cores during pattern updates. Prior art literature
[0005] Republic of Korea Published Patent Application No. 10-2017-0044307 (Published April 25, 2017) The problem to be solved
[0006] The present invention aims to solve the problems described above by providing a system and method that improve the speed of pattern matching and use resources efficiently, while maximizing processing performance, by allowing multiple execution flows to simultaneously and directly reference the same pattern matching data structure mapped to a shared memory area without redundant duplication of the data structure for pattern matching in a multi-core processor environment. means of solving the problem
[0007] To solve the problem described above, the present invention provides a high-speed packet pattern matching system in a multi-core environment, comprising: a rule distribution unit that divides a plurality of pattern rules into a plurality of rule sets based on packet processing condition information; a state transition structure generation unit that generates a plurality of state transition structures for each of the plurality of rule sets; a pattern matching array generation unit that generates a pattern matching array including a rule set-specific matching array based on relative offsets based on the plurality of state transition structures; and a mapping unit that places the pattern matching array in a shared memory area. The present invention provides a packet pattern matching system comprising a plurality of search units that perform pattern matching for a received packet by referencing a rule set-specific pattern matching array corresponding to packet processing condition information of the received packet among the pattern matching arrays placed in the shared memory area, wherein the state transition structure includes state information, transition information, alternative link information, and detection list information representing an automaton of a trie structure generated for each of the plurality of pattern rules, wherein the relative offset-based rule set-specific pattern matching array is an array in which header information, state array information, transition array information, detection list array information, pattern table information, and string table information are sequentially arranged for each of the rule sets, wherein the pattern matching array unit generates a single pattern matching array by sequentially arranging the plurality of rule set-specific pattern matching arrays to correspond to each pattern processing condition, and wherein the plurality of search units perform pattern matching while continuously referencing the header information, state array information, transition array information, detection list array information, pattern table information, and string table information included in the rule set-specific pattern matching array corresponding to the packet processing condition information of the received packet.
[0008] Here, the packet processing condition information may include at least one of rule group conditions, protocol conditions, and port conditions.
[0009] Additionally, the state transition structure generation unit generates a root node and sequentially adds child nodes for the root node while sequentially making the characters constituting each pattern rule into edges, thereby generating a trie-structured automaton, and for the child node corresponding to the last character constituting the pattern rule, generates the corresponding character as detection list information, and at each child node, generates alternative link information which is path information indicating a node to move to for a character other than the character constituting the pattern rule, and the state information is node information indicating an identifier of each node corresponding to the characters constituting a plurality of pattern rules in the trie-structured automaton, and the transition information may be path information indicating a node to move to for a character corresponding to the pattern rule at each node corresponding to the state information.
[0010] Additionally, the header information includes offset information representing a relative address that is the starting position of each of the state array information, transition array information, detection list array information, pattern table information, and string table information placed after the header information, and the state array information includes, for each of the state information included in the state transition structure, offset information for the transition array information, alternative link information, detection list count information, and offset information for the detection list array information, and the transition array information includes an input character and state information to move according to the input character for each of the transition information included in the state transition structure, and the detection list array information includes pattern table index information which is index information of a pattern rule detected for each state having the detection list information included in the state transition structure, and the pattern table information includes identifier information for each of the pattern table index information, offset information for the string table information, and pattern addition information, and the string table information may include a string constituting a pattern rule for each of the identifier information of the pattern table information.
[0011] In addition, the pattern matching array generation unit may generate a plurality of rule set-specific matching arrays based on relative offsets based on the plurality of state transition structures, and generate a single pattern matching array by arranging the plurality of rule set-specific matching arrays in succession.
[0012] In addition, the plurality of search units can sequentially check the characters constituting the string included in the received packet from the beginning, refer to header information, state array information, and transition array information to move to the next state, check detection list array information, and if detection list array information exists, check pattern table information and string table information to output a pattern matching result for the received packet.
[0013] Additionally, the state transition structure generation unit generates a new state transition structure for a new rule set when an update request occurs, the pattern matching array generation unit generates a new shadow pattern matching array based on the new state transition structure, the mapping unit maps the shadow pattern matching array to an empty space in a shared memory area, and the update management unit can replace the pattern matching array previously referenced by the plurality of search units with the shadow pattern matching array.
[0014] Additionally, the search unit is coupled to a plurality of NUMA nodes, each consisting of a plurality of processors and a local memory allocated to each processor, and the mapping unit maps a plurality of rule set-specific pattern matching arrays to a local memory area of each node or a local memory area close to the corresponding NUMA node, and each of the search units can select a pattern matching array mapped to a local memory area corresponding to its own NUMA node and perform pattern matching using the pattern matching array.
[0015] According to another aspect of the present invention, a high-speed packet pattern matching method in a multi-core environment comprises: a first step of dividing a plurality of pattern rules into a plurality of rule sets based on packet processing condition information; a second step of generating a plurality of state transition structures for each of the divided plurality of rule sets; a third step of generating a rule set-specific matching array based on relative offsets based on each of the plurality of state transition structures and arranging them consecutively to generate a single pattern matching array; a fourth step of placing the pattern matching array in a shared memory area; and a fifth step of performing pattern matching for each of the received packets by referring to a rule set-specific pattern matching array corresponding to the packet processing condition information of the received packet among the pattern matching arrays placed in the shared memory area. Effects of the invention
[0016] According to the present invention, by allowing multiple execution flows to simultaneously and directly reference the same pattern matching data structure mapped to a shared memory area without redundant duplication of the data structure for pattern matching in a multi-core processor environment, a system and method can be provided that improve the speed of pattern matching and use resources efficiently, while maximizing processing performance. Brief explanation of the drawing
[0017] FIG. 1 is a diagram showing the configuration of a high-speed packet pattern matching system (100) in a multi-core environment according to an embodiment of the present invention. Figure 2 shows an example of an automaton for generating a state transition structure. Figure 3 shows the elements constituting the state transition structure generated by the automaton of Figure 2 in a table form. Figure 4 shows an example of a pattern matching array for each rule set based on relative offset. FIG. 5 is a diagram illustrating, by way of example, a method for generating a pattern matching array for each rule set shown in FIG. 4. Figure 6 is a diagram showing an example of a pattern matching array. FIG. 7 is a flowchart showing an example of a pattern matching method performed in a system (100) described with reference to FIG. 1 to 6. Specific details for implementing the invention
[0018] Hereinafter, embodiments according to the present invention will be described in detail with reference to the attached drawings.
[0019] FIG. 1 is a diagram showing the configuration of a high-speed packet pattern matching system (100) in a multi-core environment according to an embodiment of the present invention.
[0020] Referring to FIG. 1, a high-speed packet pattern matching system (100, hereinafter simply referred to as “system (100)”) in a multi-core environment includes a rule distribution unit (10), a state transition structure generation unit (20), a pattern matching array generation unit (30), a mapping unit (40), and a plurality of search units (50, 60).
[0021] The rule distribution unit (10) performs the function of dividing a plurality of pattern rules into a plurality of rule sets based on packet processing condition information.
[0022] Here, a pattern rule refers to a rule that defines a pattern that is detected, blocked, or allowed by the multiple search units (50, 60) described later.
[0023] For example, a pattern rule may be composed of a set of specific strings such as “he”, “she”, “her”, “his”, etc., and since such a pattern rule itself is well known in the prior art and is not the direct purpose of the present invention, a detailed description is omitted here.
[0024] Packet processing condition information may include at least one of rule group conditions, protocol conditions, and port conditions.
[0025] Rule group conditions refer to conditions in which pattern rules with similar characteristics or purposes are divided into groups, such as, for example, URI-based intrusion prevention rules, payload-based intrusion prevention rules, application identification rules, and user-defined rules.
[0026] Protocol conditions refer to protocol-specific conditions, such as TCP, UDP, ICMP, etc., and port conditions refer to port-specific conditions.
[0027] For example, as protocol conditions and port conditions, conditions may include maintaining any context and port-specific contexts from 0 to 65535 for TCP and UDP, and placing ICMP and IP family rules into any context without port concepts.
[0028] The rule distribution unit (10) divides multiple pattern rules into multiple rule sets based on this packet processing condition information.
[0029] The state transition structure generation unit (20) performs the function of generating multiple state transition structures for each of the multiple rule sets.
[0030] Here, a state transition structure refers to a set of data representing a model in which the pattern matching process for strings included in a plurality of rule sets is expressed as transitions between states in order to perform a pattern matching operation on a received packet.
[0031] For example, the state transition structure may be data representing a model in the form of an automaton known by conventional technology.
[0032] For example, the state transition structure generation unit (20) can generate automatons for a plurality of rule sets and generate a state transition structure based on state information, transition information, alternative link information, and detection list information representing each automaton.
[0033] Figure 2 shows an example of an automaton for generating a state transition structure.
[0034] Figure 2 shows an example of an automaton generated by an algorithm used for conventional multi-pattern detection, and shows an example of a trie-structured automaton for a rule set containing four pattern rules composed of strings P1='he', P2='she', P3='his', and P4='hers'.
[0035] The state transition structure generation unit (20) can generate a tri-structure automaton as shown in FIG. 2 for each of the plurality of pattern rules, and generate a state transition structure based on state information, transition information, alternative link information, and detection list information representing the generated tri-structure automaton.
[0036] A method for generating a tri-structured automaton for pattern matching is well known by prior art, and, for example, the following method can be used.
[0037] First, the state transition structure generation unit (20) generates a root node and sequentially adds child nodes for the root node while sequentially making the characters constituting each pattern rule into edges.
[0038] For example, in Fig. 2, the four pattern rules are a set of four strings P1='he', P2='she', P3='his', and P4='hers', and each character constituting these four strings is sequentially connected as an edge from the root node (S0), and child nodes for the root node are sequentially connected.
[0039] These root nodes and child nodes correspond to state information, and edges correspond to transition information.
[0040] That is, state information refers to node information representing the identifier of each node corresponding to the characters constituting multiple pattern rules in a trie-structured automaton, and transition information is path information representing the node to move to for the character corresponding to the pattern rule from each node corresponding to this state information.
[0041] Referring to Figure 2, the state information corresponds to the identification information of 9 nodes (S0~S9), S0~S9, and the root node is S0.
[0042] In addition, in Figure 2, it can be seen that when the input value at node S0 is h, it moves to node S1, and when the input value is s, it moves to node S3. In this way, the transition information can be represented as state information of the state (node) to move to for the character corresponding to the pattern rule for each node.
[0043] And, the state transition structure generation unit (20) generates the corresponding character as detection list information for the child node corresponding to the last character constituting the pattern rule.
[0044] In other words, the detection list information refers to information representing the pattern found when a specific state is reached, that is, the pattern rule detected at each node corresponding to the state information.
[0045] For example, in FIG. 2, the detection list information of node S9 is “hers”, and the detection list information of node S35 is “he”, “she”. In FIG. 2, it can be seen that nodes S2, S5, S7, and S9 each have {P1}, {P1, P2}, {P3}, and {P4} as detection list information.
[0046] Additionally, the state transition structure generation unit (20) generates alternative link information, which is path information indicating the node to move to for a character other than the character constituting the pattern rule, at each child node.
[0047] That is, alternative link information refers to path information indicating the node to move to when there is no input of a character constituting the pattern rule at each node corresponding to the state information.
[0048] In Figure 2, node (state) S4 is in a state where the input value is “sh”, and in this state, if the next input value is not “e”, it is not moved to the root node S0, but rather to node S1 because the alternative link information is directed toward S1.
[0049] In Figure 2, alternative link information is indicated by a dotted line.
[0050] According to the automaton generated in this way, input strings included in the received packet are read sequentially, and the next state is determined based on the current state and the input characters. When a state is reached in which a detection list exists, it can be determined that the corresponding pattern rule has been detected.
[0051] When reading an input string, the state transition structure moves to the next state (node) if transition information corresponding to the input character exists in the current state, and continues the search by moving to the state (node) pointed to by the alternative link information if no corresponding transition information exists.
[0052] In this way, while moving through states, if detection list information exists in a specific state, it is treated as if one or more pattern rules were detected at the position of the input string that reached that state.
[0053] The state transition structure generation unit (20) generates a state transition structure for pattern rules divided into multiple rule sets in this manner.
[0054] Figure 3 shows the elements constituting the state transition structure generated by the automaton of Figure 2 in a table form.
[0055] Referring to FIG. 3, it can be seen that the state transition structure can be represented by elements such as state information, transition information, alternative link information, and detection list information for a single rule set containing a plurality of pattern rules.
[0056] Although Figure 3 shows a state transition structure for a single rule set, as previously explained, the state transition structure generation unit (20) generates a state transition structure of the form shown in Figure 3 for each of the multiple rule sets divided by the rule distribution unit (10).
[0057] FIGS. 2 and 3 illustrate one method for generating a state transition structure, and it goes without saying that other methods can be used to generate a state transition structure in the form of an automaton based on states and transitions for pattern rules, in addition to the method described in FIGS. 2 and 3.
[0058] Next, referring again to FIG. 1, the pattern matching array generation unit (30) will be described.
[0059] The pattern matching array generation unit (30) performs the function of generating a pattern matching array including a matching array for each rule set based on a plurality of state transition structures.
[0060] Here, the pattern matching array per rule set refers to an array in which header information, state array information, transition array information, detection list array information, pattern table information, and string table information are sequentially arranged for each rule set.
[0061] Figure 4 shows an example of a pattern matching array for each rule set based on relative offset.
[0062] Figure 4 shows the structure of a pattern matching array per rule set generated based on a state transition structure generated for one rule set.
[0063] Referring to FIG. 4, it can be seen that the pattern matching array for each rule set has a structure in which header information, state array information, transition array information, detection list array information, pattern table information, and string table information are arranged sequentially in a continuous array form.
[0064] The header information includes offset information (section_offsets) representing relative addresses that are the starting positions of the state array information, transition array information, detection list array information, pattern table information, and string table information, respectively, which are placed after the header information.
[0065] This offset information includes state array offset information, transition array offset information, detection list array offset information, pattern table offset information, and string table offset information.
[0066] State array offset information is information indicating the relative address where the state array information is located when the address of the header information is used as the base address.
[0067] Similarly, the transition array offset information is information representing the relative address where the transition array information is located when the address of the header information is used as the base address, and the detection list offset information is information representing the relative address where the detection list array information is located from the header information.
[0068] In addition, the pattern table offset information is information representing the relative address where the pattern table array information is located when the address of the header information is used as the base address, and the string table offset information is information representing the relative address where the string table array information is located when the address of the header information is used as the base address.
[0069] Additionally, the header information may include count information and string size information (counts) for each of the state information, transition information, detection list information, and pattern list information, and may include other necessary additional information (version).
[0070] Meanwhile, the state array information (states[]) may include, for each state information included in the state transition structure described above, offset information (edge_off) for the transition array information, alternative link information (fail), detection list count information (match_count), and offset information (match_off) for the detection list array information.
[0071] In this case, the state array information may also include information on the number of transition information.
[0072] The transition array information (edges[]) includes, for each of the transition information included in the state transition structure described above, an input character (c) and state information (next_state_index) to move to based on the input character.
[0073] The detection list array information (matches[]) includes pattern table index information (pattern_index), which is index information of a pattern rule detected for each state having detection list information included in the state transition structure described above.
[0074] Pattern table information (patterns[]) may include identifier information (id) for each pattern table index information, offset information (msg_off) for string table information, and pattern additional information (category / risk).
[0075] Pattern supplementary information may be additional information such as the length, category, policy, risk level, etc. of the pattern.
[0076] The string table information (strtab[]) may include strings that constitute pattern rules for each identifier information (id) of the pattern table information.
[0077] FIG. 5 is a diagram illustrating, by way of example, a method for generating a pattern matching array for each rule set shown in FIG. 4.
[0078] First, the pattern matching array generation unit (30) calculates the number of states, number of transitions, number of detections, number of patterns, and string size of the state transition structure.
[0079] Next, the pattern matching array generation unit (30) arranges header information in a preset byte size, and then generates state array information, transition array information, detection list array information, pattern table information, and string table information in a preset size each after the header information, and arranges them sequentially to generate a pattern matching array for each rule set.
[0080] At this time, the pattern matching array generation unit (30) calculates the starting positions of the state array information, transition array information, detection list array information, pattern table information, and string table information based on preset bytes. For example, the starting positions of each area can be aligned in units of 8 bytes.
[0081] For example, the header information can be arranged with a size of 48 bytes, each entry constituting the state array information with a size of 20 bytes, each entry constituting the transition array information with a size of 8 bytes, and each entry constituting the detection list array information with a size of 4 bytes.
[0082] In addition, the entries constituting the pattern table information and the string table information, respectively, can be constructed by arranging variable-length strings consecutively.
[0083] The pattern matching array generation unit (30) records information such as the above-described information to be included in the state array information, transition array information, detection list array information, pattern table information, and string table information.
[0084] In the state array information (states[]), as described above, for each state information included in the state transition structure, offset information (edge_off) for the transition array information, alternative link information (fail), detection list count information (match_count), and offset information (match_off) for the detection list array information are recorded.
[0085] Additionally, the transition array information (edges[]) records the input character (c) and the state information to move to based on the input character (next_state_index) for each transition information included in the state transition structure.
[0086] Additionally, in the detection list array information (matches[]), pattern table index information (pattern_index) is recorded for each state having detection list information included in the state transition structure as described above, and in the pattern table information (patterns[]), offset information (msg_off) and pattern addition information (category / nsk) for the string table information corresponding to the identifier information (id) are recorded.
[0087] In addition, string table information (strtab[]) records strings that constitute pattern rules for each identifier information (id) of pattern table information.
[0088] In this way, the pattern matching array generation unit (30) generates a plurality of rule set-specific matching arrays based on relative offsets based on a plurality of state transition structures, and generates a single pattern matching array by arranging the plurality of rule set-specific matching arrays in succession.
[0089] Figure 6 is a diagram showing an example of a pattern matching array.
[0090] The pattern matching array generation unit (30) can generate a pattern matching array for each rule set as described above, and then sequentially arrange them as shown in FIG. 6 to correspond to each pattern processing condition to generate a single pattern matching array.
[0091] Generating a pattern matching array in this manner allows entries of the same type to be placed in adjacent memory locations, unlike the method of following pointer-based dynamic objects in conventional technology, where elements constituting the state transition structure are referenced by pointers or dynamic data structures. Therefore, internal pointer relocation is not required even if the same pattern matching array is mapped to a virtual address used by a core or process.
[0092] Therefore, by efficiently utilizing memory space and minimizing issues such as TLB misses (Translation Lookaside Buffer misses) in the cache, it enables high-speed pattern matching in a multi-core environment.
[0093] For example, based on a 64-byte cache line, each entry constituting the transition array information can contain up to 8 entries, and each entry constituting the detection list array information can contain up to 16 entries in a single cache line, so the search unit (50, 60) described later can significantly increase reference locality when sequentially checking the transition array information or detection list array information of the current state.
[0094] Next, the mapping section (40) and the search section (50, 60) of FIG. 1 will be described again.
[0095] The mapping unit (40) performs the function of placing the pattern matching array generated by the pattern matching array generation unit (30) as described above into a shared memory area.
[0096] The mapping unit (40) maps the entire pattern matching array generated in the manner described above directly into a shared memory area.
[0097] A plurality of search units (50, 60) perform pattern matching for a received packet by referring to a pattern matching array for each rule set corresponding to the packet processing condition information of the received packet among the pattern matching arrays placed in the shared memory area.
[0098] Multiple search units (50, 60) are composed of multiple units that are combined with multiple multi-cores, and each core performs pattern matching for the received packet.
[0099] In FIG. 1, for convenience of explanation, only two search units (50, 60) are shown, but it is obvious that there may be three or more.
[0100] After the pattern matching array is placed in the shared memory area by the mapping unit (40), each of the multiple search units (50, 60) checks packet processing condition information for the received packet and checks the pattern matching array for each rule set corresponding to the packet processing condition information.
[0101] For example, each of the multiple search units (50, 60) checks the protocol, source port, and destination port of the received packet and selects a pattern matching array for each rule set that corresponds to the corresponding packet processing condition information among the pattern matching arrays.
[0102] And, each of the multiple search units (50, 60) performs pattern matching by continuously referencing header information, state array information, transition array information, detection list array information, pattern table information, and string table information included in the pattern matching array for each rule set corresponding to the packet processing condition information of the received packet.
[0103] That is, each of the multiple search units (50, 60) sequentially checks the characters constituting the string included in the received packet from the very beginning and performs pattern matching for the received packet by referring to the pattern matching array for each rule set.
[0104] Each of the multiple search units (50, 60) can sequentially check the characters constituting the string included in the received packet from the beginning, refer to the header information, state array information, and transition array information to move to the next state, check the detection list array information, and if the detection list array information exists, check the pattern table information and string table information to output a pattern matching result for the received packet.
[0105] In this case, as previously explained, since the header information, state array information, and transition array information constituting the pattern matching array contain offset-based relative addresses rather than absolute addresses, pattern matching can be performed on an input character using the state array information (states[]), offset information for the transition array information (edge_off), alternative link information (fail), offset information for the detection list array information (match_off), and pattern table index information (pattern_index).
[0106] Therefore, since the search unit (50, 60) combined to each core in a multi-core environment can simultaneously share and reference the same pattern matching array and perform pattern matching simultaneously, high-speed pattern matching can be performed efficiently in a multi-core environment.
[0107] That is, by utilizing a single pattern matching array arranged in an array form, the multiple search units (50, 60) do not need to perform separate search structure reconstruction, internal pointer placement, or address relocation, unlike the prior art. In this case, when the mapping unit (40) utilizes virtual memory, for example, there is an advantage of being able to perform pattern matching at high speed while performing state transitions, alternative state movements, detection list lookups, and rule additional information references using only the mmap reference address, the relative offset of the pattern matching array, and the array index.
[0108] In addition, since it is sufficient to check only the pattern matching array for each rule set corresponding to the packet processing conditions of the received packet, the state space unrelated to the packet processing conditions can be excluded from the search path, thereby improving the search speed.
[0109] FIG. 7 is a flowchart showing an example of a pattern matching method performed in a system (100) described with reference to FIG. 1 to 6.
[0110] Referring to FIG. 7, first, the rule distribution unit (10) divides a plurality of pattern rules into a plurality of rule sets based on packet processing condition information, as previously explained (S100).
[0111] And, the state transition structure generation unit (20) generates a plurality of state transition structures for each of the divided plurality of rule sets in the manner described above (S110).
[0112] When a state transition structure is generated, the pattern matching array generation unit (30) generates a matching array based on a relative offset rule set based on each of the plurality of state transition structures as described above, and arranges them consecutively to generate a single pattern matching array (S120).
[0113] When the creation of the pattern matching array is complete, the mapping unit (40) places the pattern matching array in a shared memory area (S130).
[0114] Afterwards, each of the multiple search units (50, 60) performs pattern matching for each received packet by referring to a pattern matching array for each rule set corresponding to the packet processing condition information of the received packet among the pattern matching arrays placed in the shared memory area (S140).
[0115] This method can be implemented as a program that can be executed on a multi-core computer.
[0116] In this case, as described above, the multiple search units (50, 60) can be implemented as programs executed on each core by independently combining multiple multi-cores.
[0117] In addition, the method according to the present invention may be implemented in the form of program instructions that can be executed via a computer and recorded on a computer-readable medium. It goes without saying that such a computer-readable medium may include program instructions, data files, data structures, etc., either individually or in combination.
[0118] Meanwhile, in the aforementioned system (100), the update to the pattern matching array can be performed in the following way.
[0119] First, the state transition structure generation unit (20) generates a new state transition structure for the new rule set in the manner described above when an update request occurs.
[0120] And, the pattern matching array generation unit (30) generates a new shadow pattern matching array based on a new state transition structure in the manner described above.
[0121] Here, a shadow pattern matching array refers to a pattern matching array mapped to an empty space in the shared memory area. A pattern matching array currently mapped to the shared memory area is called an active pattern matching array.
[0122] The mapping unit (40) maps the shadow pattern matching array to an empty space in the shared memory area and verifies the header information.
[0123] When verification is complete, the update management unit (not shown) replaces the active pattern matching array that the search unit (50, 60) previously referenced with the shadow pattern matching array.
[0124] This is executed by a single atomic operation that replaces the memory address pointer of the active pattern matching array (active handle) that the search unit (50, 60) previously referenced with a pointer to the shadow pattern matching array.
[0125] As previously mentioned, since the pattern matching array does not contain an absolute address pointer internally, no internal pointer patching or address relocation is required even if the replaced pattern matching array is mapped to a virtual address different from the existing pattern matching array.
[0126] After replacement, pattern matching for newly incoming received packets can refer to the replaced pattern matching array, so updates can be performed simply and efficiently even when the pattern rules are changed.
[0127] Meanwhile, by using the pattern matching array described above, pattern matching can be efficiently performed even in a NUMA (Non-Uniform Memory Access) structure in which dedicated memory is allocated to each processor (CPU) in a multi-processor environment.
[0128] In this NUMA structure, multiple search units (50, 60) are combined with multiple NUMA nodes, each consisting of multiple processors (CPUs) and local memory allocated per processor.
[0129] Pattern matching in such NUMA structures can be performed, for example, in the following ways.
[0130] First, the mapping unit (40) maps a plurality of rule set-specific pattern matching arrays to a local memory area of each NUMA node or a local memory area close to the NUMA node.
[0131] And, each of the search units (50, 60) identifies its own NUMA node. This can be identified using CPU fixed information, current CPU information provided by the scheduler, or preset worker-node mapping information.
[0132] Next, the search unit (50, 60) selects a pattern matching array mapped to a local memory area corresponding to the identified NUMA node and performs pattern matching in the manner described above.
[0133] In this case, even if the base address of the selected pattern matching array differs from the base address of another node, the same search logic can be applied because the internal reference of the pattern matching array is based on relative offsets and array indices. In this case, if there is no local mapping for the corresponding node, it can be replaced with a public mapping or an adjacent node mapping.
[0134] Therefore, by reducing remote memory access between sockets and allowing them to reference pattern-matching arrays close to themselves, memory access latency can be mitigated.
[0135] In addition, the system (100) according to the present invention can suppress TLB misses by combining with a large-capacity page.
[0136] The pattern matching array generation unit (30) calculates the size of the pattern matching array based on relative offset and, if necessary, expands the size of the pattern matching array to match the boundaries of large pages, such as 2MB or 1GB pages.
[0137] The mapping unit (40) maps a pattern matching array to a memory area using a large page mapping function such as a hugetlbfs-based file provided by a large page support file system or operating system, a MAP_HUGETLB flag, or a request to use a Transparent Huge Page (MADV_HUGEPAGE), and the search unit (50, 60) performs pattern matching in the manner described above.
[0138] According to this, since a single TLB entry can use a wider memory area compared to the case where a conventional general 4KB page is used, there is an advantage in that it can reduce TLB misses and page table walks that may occur during state and transition array iteration references.
[0139] Meanwhile, in order to further improve the pattern matching speed in the aforementioned system (100), the search unit (50, 60) can directly read and use the payload of the received packet from the input buffer without copying the received packet payload to a separate search buffer.
[0140] That is, a packet processing unit (not shown) extracts the protocol, source port, destination port, payload pointer, and payload length from the received packet, and a search unit (50, 60) selects a pattern matching array for each rule set according to the packet processing conditions as described above.
[0141] And, the search unit (50, 60) sequentially reads the bytes pointed to by the payload pointer, performs pattern matching by referring to the pattern matching array as described above, and transmits the same payload pointer, pattern identifier, detection location, and rule additional information to the subsequent packet processing unit.
[0142] According to this method, packet payload copying, separate IPC forwarding, and the creation of temporary buffers for retrieval can be reduced, thereby mitigating latency and memory bandwidth usage in high-speed packet processing environments.
[0143] Although the present invention has been described above with reference to preferred embodiments, the present invention is not limited to the above embodiments, and it is understood that various modifications and variations are possible within the scope of the present invention as understood by referring to the appended claims and drawings. Explanation of the symbols
[0144] 100… High-speed packet pattern matching system in a multi-core environment 10… Rule Distribution Department 20… State transition structure generation part 30… Pattern matching array generation part 40… Mapping section 50, 60… Search Department
Claims
Claim 1 A high-speed packet pattern matching system in a multi-core environment comprises: a rule distribution unit that divides a plurality of pattern rules into a plurality of rule sets based on packet processing condition information; a state transition structure generation unit that generates a plurality of state transition structures for each of the plurality of rule sets; a pattern matching array generation unit that generates a pattern matching array including a rule set-specific matching array based on relative offsets based on the plurality of state transition structures; and a mapping unit that places the pattern matching array in a shared memory area. A packet pattern matching system comprising a plurality of search units that perform pattern matching for a received packet by referencing a rule set-specific pattern matching array corresponding to packet processing condition information of the received packet among the pattern matching arrays placed in the shared memory area, wherein the state transition structure includes state information, transition information, alternative link information, and detection list information representing an automaton of a trie structure generated for each of the plurality of pattern rules, wherein the relative offset-based rule set-specific pattern matching array is an array in which header information, state array information, transition array information, detection list array information, pattern table information, and string table information are sequentially arranged for each of the rule sets, wherein the pattern matching array generation unit generates a single pattern matching array by sequentially arranging the plurality of rule set-specific pattern matching arrays to correspond to each pattern processing condition, and wherein the plurality of search units perform pattern matching while continuously referencing the header information, state array information, transition array information, detection list array information, pattern table information, and string table information included in the rule set-specific pattern matching array corresponding to the packet processing condition information of the received packet. Claim 2 A packet pattern matching system according to claim 1, wherein the packet processing condition information comprises at least one of a rule group condition, a protocol condition, and a port condition. Claim 3 A packet pattern matching system according to claim 1, wherein the state transition structure generating unit generates a root node and generates a trie-structured automaton by sequentially adding child nodes for the root node while sequentially making the characters constituting each pattern rule into edges, generates the corresponding character as detection list information for the child node corresponding to the last character constituting the pattern rule, generates alternative link information which is path information indicating a node to move to for a character other than the character constituting the pattern rule at each child node, wherein the state information is node information indicating an identifier of each node corresponding to the characters constituting a plurality of pattern rules in the trie-structured automaton, and the transition information is path information indicating a node to move to for a character corresponding to the pattern rule at each node corresponding to the state information. Claim 4 A packet pattern matching system according to claim 1, wherein the header information includes offset information representing a relative address which is the starting position of each of the state array information, transition array information, detection list array information, pattern table information, and string table information disposed after the header information; the state array information includes, for each of the state information included in the state transition structure, offset information for the transition array information, alternative link information, detection list count information, and offset information for the detection list array information; the transition array information includes an input character and state information to move according to the input character for each of the transition information included in the state transition structure; the detection list array information includes pattern table index information which is index information of a pattern rule detected for each state having the detection list information included in the state transition structure; the pattern table information includes identifier information for each of the pattern table index information, offset information for the string table information, and pattern addition information; and the string table information includes a string constituting a pattern rule for each of the identifier information of the pattern table information. Claim 5 A packet pattern matching system according to claim 4, wherein the pattern matching array generating unit generates a plurality of rule set-specific matching arrays based on relative offsets based on the plurality of state transition structures, and generates a single pattern matching array by arranging the plurality of rule set-specific matching arrays in succession. Claim 6 A packet pattern matching system according to claim 1, wherein the plurality of search units sequentially check characters constituting a string included in a received packet from the beginning, check detection list array information while moving to the next state by referring to header information, state array information, and transition array information, and if detection list array information exists, check pattern table information and string table information to output a pattern matching result for the received packet. Claim 7 A packet pattern matching system according to claim 1, wherein the state transition structure generating unit generates a new state transition structure for a new rule set when an update request occurs, the pattern matching array generating unit generates a new shadow pattern matching array based on the new state transition structure, the mapping unit maps the shadow pattern matching array to an empty space in a shared memory area, and the update management unit replaces the pattern matching array previously referenced by the plurality of search units with the shadow pattern matching array. Claim 8 A packet pattern matching system according to claim 1, wherein the search unit is coupled to a plurality of NUMA nodes, each comprising a plurality of processors and a local memory allocated to each processor, and the mapping unit maps a plurality of rule set-specific pattern matching arrays to a local memory area of each node or a local memory area close to the corresponding NUMA node, and each of the search units selects a pattern matching array mapped to a local memory area corresponding to its own NUMA node and performs pattern matching using the pattern matching array. Claim 9 A high-speed packet pattern matching method in a multi-core environment comprises: a first step of dividing a plurality of pattern rules into a plurality of rule sets based on packet processing condition information; a second step of generating a plurality of state transition structures for each of the divided plurality of rule sets; a third step of generating a rule set-specific matching array based on relative offsets based on each of the plurality of state transition structures and arranging them consecutively to generate a single pattern matching array; and a fourth step of placing the pattern matching array in a shared memory area. A packet pattern matching method comprising: a fifth step of performing pattern matching for each received packet by referencing a rule set-specific pattern matching array corresponding to packet processing condition information of the received packet among pattern matching arrays placed in a shared memory area for each received packet; wherein the state transition structure includes state information, transition information, alternative link information, and detection list information representing an automaton of a trie structure generated for each of a plurality of pattern rules; wherein the relative offset-based rule set-specific pattern matching array is an array in which header information, state array information, transition array information, detection list array information, pattern table information, and string table information are sequentially arranged for each rule set; wherein the third step generates a single pattern matching array by sequentially arranging the plurality of rule set-specific pattern matching arrays to correspond to each pattern processing condition; and wherein the fifth step performs pattern matching while sequentially referencing the header information, state array information, transition array information, detection list array information, pattern table information, and string table information included in the rule set-specific pattern matching array corresponding to packet processing condition information of the received packet.
Citation Information
Patent Citations
Match engine for detection of multi-pattern rules
US20110029473A1