Ilmu Komputer & AI editorial
Open AccessOA2026
A High-Throughput FPGA Architecture for Real-Time TCP-SYN Scan Detection
Line-rate fingerprint detection with constant two-cycle latency and linear resource scaling
Faisal Saeed; Mohammad Fahad; Ayesha Javaid; Christian Doerr; Muhammad Ali Siddiqiยท 2026ยท DOI 10.48550/arXiv.2609.14043
The core problem
TCP-SYN port scanning is a common precursor to cyber-attacks. Detecting scanner fingerprints embedded in packet headers at line rate can provide timely intrusion alerts. However, existing detection approaches are either too computationally expensive for line-rate operation or limited to offline analysis. This work presents a lightweight FPGA architecture for reconfigurable line-rate fingerprint detection. The core idea is to compile each fingerprint into a shallow Boolean LUT tree, enabling parallel evaluation with constant two-cycle latency regardless of the number of fingerprints, while resource cost grows linearly with fingerprint count. The detection core is decoupled from a MAC-layer frontend that performs streaming field extraction with no frame buffering or higher-layer state, allowing deployment across different line rates by modifying only the frontend. A Python framework automatically compiles Boolean expressions into synthesizable HDL, eliminating manual RTL changes. The architecture is demonstrated for TCP-SYN port-scan fingerprint detection.
Innovation
For TCP-SYN port-scan fingerprint detection, the architecture uses approximately 0.5% of LUTs at 10 Gbps on a Versal VCK190 for 18 deployed fingerprints, with capacity for over 2,000 concurrent fingerprints. On a Virtex-6 at 1 Gbps, resource usage is under 2.5% LUTs. Detection latency is 10 ns at both line rates, which is three to four orders of magnitude below typical per-packet processing latency in software intrusion-detection systems. The system was cross-validated against a software re-implementation on an 8-hour production packet trace, confirming detection correctness with zero false positives and zero false negatives. The constant two-cycle latency and linear resource scaling are key performance characteristics.
TCP-SYN port scanning is a common precursor to cyber-attacks. Detecting scanner fingerprints embedded in packet headers at line rate can provide timely intrusion alerts. However, existing detection approaches are either too computationally expensive for line-rate operation or limited to offline analysis. This work presents a lightweight FPGA architecture for reconfigurable line-rate fingerprint detection. The core idea is to compile each fingerprint into a shallow Boolean LUT tree, enabling parallel evaluation with constant two-cycle latency regardless of the number of fingerprints, while resource cost grows linearly with fingerprint count. The detection core is decoupled from a MAC-layer frontend that performs streaming field extraction with no frame buffering or higher-layer state, allowing deployment across different line rates by modifying only the frontend. A Python framework automatically compiles Boolean expressions into synthesizable HDL, eliminating manual RTL changes. The architecture is demonstrated for TCP-SYN port-scan fingerprint detection.
The proposed architecture consists of two main components: a MAC-layer frontend and a fingerprint detection core. The frontend performs streaming extraction of relevant packet header fields (e.g., TCP flags, source/destination ports, IP addresses) without buffering entire frames or maintaining higher-layer state. The extracted fields are fed to the detection core, where each fingerprint is represented as a Boolean expression. These expressions are compiled into shallow LUT trees, allowing parallel evaluation. The latency through the detection core is constant at two cycles, independent of the number of fingerprints. Resource utilization scales linearly with the number of fingerprints. A Python-based framework automates the translation of Boolean expressions into synthesizable HDL, enabling rapid reconfiguration without manual RTL edits. The design was implemented and evaluated on two FPGA platforms: a Versal VCK190 at 10 Gbps and a Virtex-6 at 1 Gbps. Detection correctness was cross-validated against a software re-implementation using an 8-hour production packet trace.
Why it matters
The results demonstrate that the proposed FPGA architecture achieves high-throughput, low-latency TCP-SYN scan detection suitable for line-rate operation. The decoupling of the detection core from the MAC-layer frontend enables portability across different line rates by only modifying the frontend, making the design adaptable to various network speeds. The use of a Python framework to compile Boolean expressions into HDL significantly reduces development time and allows for dynamic reconfiguration as new fingerprints emerge. The linear resource scaling with fingerprint count ensures predictability and scalability. The constant two-cycle latency, independent of fingerprint count, provides deterministic performance, which is critical for real-time intrusion detection. The zero false positives/negatives on a production trace validate the correctness of the approach. Compared to software-based intrusion-detection systems, the FPGA implementation offers orders of magnitude lower latency, making it suitable for high-speed networks where timely detection is essential. The architecture is particularly effective for TCP-SYN port scanning, a common attack precursor, but the methodology could be extended to other packet-header-based fingerprints. Future work may explore integration with higher-layer stateful analysis and adaptation to even higher line rates.
Who should read this
CS practitioners and researchers
Opening member contentโฆ