Home InternationalAchieving 100Gbps intrusion prevention on a single...
International⭐ Featured

Achieving 100Gbps intrusion prevention on a single server

Achieving 100 Gbps intrusion prevention on a single server, Zhao et al., OSDI’20 Papers-we-love is hosting a mini-event this Wednesday (18th) where I’ll be leading a panel discussion including one of the authors of today’s paper choice: Justine Sherry. Please do join us if you can. We always want more! This stems from a combination of Jevon’s paradox … Continue reading Achieving 100Gbps intrusion prevention on a single server

6 April 2026 at 08:08 pm
1 views
Achieving 100Gbps intrusion prevention on a single server

Achieving 100 Gbps intrusion prevention on a single server is a remarkable feat that highlights the potential of modern hardware and innovative system design. This paper, authored by Zhao et al., was presented at OSDI’20 and is now being discussed in a mini-event hosted by Papers-we-love on Wednesday, the 18th. The event features a panel discussion led by the host, with one of the authors, Justine Sherry, participating. Attendees are encouraged to join this engaging discussion to delve deeper into the intricacies of this groundbreaking work.

The concept of achieving such high performance on a single server stems from a combination of Jevon’s paradox and the interconnectedness of systems. Jevon’s paradox, which states that technological progress in one area often leads to increased demand in another, is evident in the need for enhanced security measures as systems become more interconnected. As we improve our capabilities in one area, the demand for security and protection grows, necessitating innovative solutions.

There are three primary ways to increase capacity: increasing the number of units in a system, improving the efficiency of coordinating work across units, and increasing the work done on a single unit. Options 1 and 2 are typically referred to as "scale out," while option 3 is known as "scale up." While scale-out architectures have dominated the cloud era due to their flexibility and scalability, it is essential to periodically revisit the capabilities of a single server or even a single thread.

Pigasus, the Intrusion Detection/Prevention System (IDS/IPS) presented in this paper, exemplifies the potential of scale-up. Traditionally, CPUs have been surrounded by accelerators, with the CPU coordinating and calling out to these accelerators. However, Pigasus inverts this control flow, placing the FPGA at the helm and relegating the CPU to a supportive role. This innovative design allows for unprecedented performance, achieving 100 Gbps intrusion prevention on a single server.

IDS/IPS systems monitor network flows and match incoming packets against a set of rules known as signatures. These signatures can include patterns matching against headers, packet content, exact string matches, and regular expressions. Pigasus's architecture enables it to process these signatures at an astonishing speed, making it a powerful tool in the fight against cyber threats.

The paper's authors have demonstrated that by leveraging the capabilities of a single server and optimizing the interaction between the CPU and FPGA, it is possible to achieve remarkable performance in intrusion prevention. This work not only pushes the boundaries of what a single server can accomplish but also challenges the traditional scale-out approach to system design.

In conclusion, the achievement of 100 Gbps intrusion prevention on a single server is a testament to the potential of innovative hardware and system design. By inverting the control flow between the CPU and FPGA, Pigasus has set a new standard for IDS/IPS systems. This groundbreaking work serves as a reminder that scale-up solutions can offer significant advantages over traditional scale-out architectures, particularly in the context of high-performance security systems. As the demand for robust security continues to grow, solutions like Pigasus will play a crucial role in safeguarding networks and systems against evolving threats.

📰 Related News
Ollama 0.2.6 Released with Native Gemma 4 Support and Enhanced Performance
Ollama 0.2.6 Released with Native Gemma 4 Support and Enhanced Performance
Ollama 0.2.6 is now live, featuring native support for Google's Gemma 4 models and improved local inference performance for Windows, macOS, and Linux.
14 Apr
Weekly news roundup: Shortages spread to MLCCs; SK Hynix reportedly in talks with Microsoft and Google
Weekly news roundup: Shortages spread to MLCCs; SK Hynix reportedly in talks with Microsoft and Google
Below are the most-read DIGITIMES Asia stories from the week of April 6-April 13, 2026:
14 Apr
cutile-stencil 0.2.0
cutile-stencil 0.2.0
An xDSL-based stencil compiler that generates optimized GPU kernels via NVIDIA cuTile
14 Apr
merlin-llm added to PyPI
merlin-llm added to PyPI
Merlin — a fast local LLM for agentic coding on Apple Silicon
14 Apr
Fluent Cut - Craft and compose videos programmatically in PHP with an elegant fluent API
Fluent Cut - Craft and compose videos programmatically in PHP with an elegant fluent API
Craft and compose videos programmatically in PHP with an elegant fluent API - b7s/fluentcut
14 Apr
Crypto Investor at Center of Trump Corruption Allegations Now Sees Himself as ‘Victim’
Crypto Investor at Center of Trump Corruption Allegations Now Sees Himself as ‘Victim’
Justin Sun has accused Trump-affiliated World Liberty Financial of misconduct and a general lack of transparency.
14 Apr
nvidia-nat-weave 1.7.0a20260413
nvidia-nat-weave 1.7.0a20260413
Subpackage for Weave integration in NeMo Agent Toolkit
14 Apr
nvidia-nat-s3 1.7.0a20260413
nvidia-nat-s3 1.7.0a20260413
Subpackage for S3-compatible integration in NeMo Agent Toolkit
14 Apr
Social Security Trust Fund to Run Dry in 2032: Just 6 Years From Now
Social Security Trust Fund to Run Dry in 2032: Just 6 Years From Now
Six years. That is how much time separates retirees from a Social Security system that, by its own projections, runs out of money. If you are 56 years old...
14 Apr
cane-gpu-perf added to PyPI
cane-gpu-perf added to PyPI
GPU inference benchmarking with opinionated diagnostics
13 Apr