FPGA Implementation of Pattern Matching for Industrial Control Systems
Abstract
Network cybersecurity solutions, like Intrusion Detection Systems (IDS) or Intrusion Protection Systems (IPS), address the concern of industrial infrastructures cybersecurity through pattern matching engine to identify threats among network data. However they present vulnerabilities inherent to their software implementation. Furthermore, industrial networks have specific constraints that are not always covered by solutions coming from classical IT networks (such as low-latency or support of specific industrial protocols). To cope with it, hardware solutions are more and more investigated. Literature offers various approaches to perform pattern matching. In this article, various implementations of pattern matching on FPGA are discussed and experimental results are used to provide design guidelines.