1
Intrusion Detection and Prevention / AMD zen 5 Hyperscan AVX-512 Suricata Throughput
« on: April 15, 2024, 08:01:07 pm »
Hi there,
since Hyperscan 5.4.0 AVX-512 is supported. This Version is currently a part of OPNsense 24.1.5_3-amd64. The latest version is: Hyperscan 5.4.2 released in april 2023 (please update Hyperscan @opnsense devs).
Since AVX is used to speed up suricata. More avx performance should mean more throughput.
It is rumoured that AMDs zen 5 architrecture will double the avx-512 performance. In theory this could result in an extreme performance improvement.
The Deciso DEC4280 (EPYC 3451) is being marketed with ~7.5Gbps Threat Protection Throughput.
Using this information as a baseline and throwing in some benchmark numbers i try to estimate what a zen 5 Suricata IPS performance could look like:
CPU Benchmarkesult (cpubenchmark.net) IPS Throughput (gbps)
EPYC 3451 19532 7,5
Ryzen 7700x 36021 13,8 (estimated)
Ryzen 7950x 62950 24,1 (estimated)
Ryzen 9950x 94425 (estimated) 36,2 (estimated)
since Hyperscan 5.4.0 AVX-512 is supported. This Version is currently a part of OPNsense 24.1.5_3-amd64. The latest version is: Hyperscan 5.4.2 released in april 2023 (please update Hyperscan @opnsense devs).
Since AVX is used to speed up suricata. More avx performance should mean more throughput.
It is rumoured that AMDs zen 5 architrecture will double the avx-512 performance. In theory this could result in an extreme performance improvement.
The Deciso DEC4280 (EPYC 3451) is being marketed with ~7.5Gbps Threat Protection Throughput.
Using this information as a baseline and throwing in some benchmark numbers i try to estimate what a zen 5 Suricata IPS performance could look like:
CPU Benchmarkesult (cpubenchmark.net) IPS Throughput (gbps)
EPYC 3451 19532 7,5
Ryzen 7700x 36021 13,8 (estimated)
Ryzen 7950x 62950 24,1 (estimated)
Ryzen 9950x 94425 (estimated) 36,2 (estimated)