scieee AI-readable full text Open interactive document viewer

Programmable packet-optical network security and monitoring using DPUs with embedded GPUs [Invited]

Cugini, Filippo

Abstract

Data processing units (DPUs) with embedded graphics processing units (GPUs) have the potential to revolutionize optical network functionalities at the edge. These advanced units can significantly enhance the performance and capabilities of optical networks by integrating powerful processing capabilities directly at the network edge, where data is generated and consumed. We explore the use cases for DPUs in optical data monitoring with local artificial intelligence (AI) processing and embedded security. This paradigm shift aims to enable more efficient data handling, reduced latency, and improved overall network performance by leveraging local AI processing capabilities embedded within DPUs. In this paper, we show how DPUs can analyze vast amounts of optical data in real-time, implementing advanced data analysis algorithms and security protocols directly on the DPUs to provide robust monitoring and protection for the optical networks. Results indicate that DPUs with embedded GPUs can significantly improve the detection and response times to network anomalies, performance issues, and security threats.

Full text

Research Article 1 Programmable Packet-Optical Networks Security and Monitoring using DPUs with Embedded GPU (Invited) PIERO CASTOLDI1,*, RANA ABU BAKAR1, ANDREA SGAMBELLURI1, JUAN JOSE VEGAS OLMOS2, FRANCESCO PAOLUCCI3,AND FILIPPO CUGINI3 1Scuola Superiore Sant’Anna, Pisa, Italy 2NVIDIA, Denmark 3CNIT, Pisa, Italy *piero[email protected] Compiled December 18, 2025 Data Processing Unit (DPU) with embedded Graphics Processing Unit (GPU) have the potential to revolutionize optical network functionalities at the edge. These advanced units can significantly enhance the performance and capabilities of optical networks by integrating powerful processing capabilities directly at the network edge, where data is generated and consumed. We explore the use cases for DPUs in optical data monitoring with local AI processing and embedded security. This paradigm shift aims to enable more efficient data handling, reduced latency, and improved overall network performance by leveraging local AI processing capabilities embedded within DPUs. In this paper, we show how DPUs can analyze vast amounts of optical data in real-time, implementing advanced data analysis algorithms and security protocols directly on the DPUs to provide robust monitoring and protection for the optical networks. Results indicate that DPUs with embedded GPUs can significantly improve the detection and response times to network anomalies, performance issues, and security threats. http://dx.doi.org/10.1364/ao.XX.XXXXXX 1. INTRODUCTION Edge computing allows stakeholders to keep their IT infrastructures, Machine Learning (ML), Artificial Intelligence (AI) processing, and service management close to where data is generated and used. To accomplish this goal, edge computing resources must possess advanced networking capabilities, including ultra-high bandwidth connectivity. Edge nodes interact with each other and with the cloud through switches/routers served by high-speed optical transmission systems. Network Interface Card (NIC)s provide such connectivity to nearby routers. In just a few years, the capacity of NICs has significantly increased, advancing from 10 Gb/s to 400 Gb/s and beyond. Furthermore, they evolved to Data Processing Unit (DPU)s, i.e., powerful network computing systems encompassing hardware accelerators for advanced networking and embedded security [ 1 – 3 ]. DPUs, also known as SmartNICs, were initially developed for use within data centers. However, they are now being recognized as valuable candidate tools for enhancing the networking capabilities of edge computing infrastructures. DPUs, which are now commercially available with speeds of up to 400Gb/s, have recently been equipped with integrated Graphics Processing Unit (GPU)s, enabling new AI processing capabilities on networking data. In parallel with the evolution from NIC to DPU, also optical transmission systems have significantly evolved, enhancing from standalone legacy network equipment (i.e., transponders and muxponders) to small form-factor transceivers. In particular, transceivers adopting the coherent technology can nowadays be inserted directly within routers and switches and used to communicate across hundreds of km at an extremely high rate (i.e., 400Gb/s and beyond). In this paper, we propose the adoption of DPUs equipped with GPU and coherent pluggable transceivers, expanding upon the works which assume basic SmartNICs in the context of optical networks [ 1 – 3 ]. We present the benefits obtained through this converged system including computing, networking, and optical technologies specifically focusing on the case where basic smartNIC/DPUs are enhanced with embedded GPU to support secure packet-optical communication. Initially, we present an overview of the enabling technologies, specifically DPUs and coherent pluggable transceivers. Next, we explore the expected benefits in terms of security and monitoring in converged infrastructures that are ideal for cutting-edge, Research Article 2 energy-efficient, and fast solutions in the context of beyond 5G networks. Specifically, the contributions of this work are: • We propose and assess the use of DPUs with embedded GPUs for optical networks. This integration enhances the processing capabilities at the network edge, enabling more efficient and powerful network data handling. • We implement and integrate embedded AI-based monitoring and security features within the DPUs. We conducted a comprehensive performance evaluation to compare the inference times of setups using DPU with GPU versus setups using DPU with CPU only. • We develop an experimental testbed to validate proposed approaches for real-time measurements and comparisons of prediction inference times, demonstrating the practical applicability and effectiveness of the integrated DPU with GPU solution. 2. RELATED WORK A. Related work on AI/ML solutions for optical networks In this subsection we highlight several valuable works proposing and validating the use of AI processing applied to optical networks. The study [ 4 ] employed Remote Procedure Calls (gRPC) telemetry and a Convolutional Neural Network (CNN) to collect received signal data from whitebox transponders. Moreover, they have shown that it is feasible to classify field fibre bending in real-time using this approach. The study conducted by Tanimura et al. [ 5 ] utilises signal data acquired from digital coherent optical receivers as input data and employs a CNN for learning. Their study focuses on using this data for Optical Signal to Noise Ratio (OSNR) calculation and identifying the modulation format and symbol rate. The implementation of this methodology has led to exceptional categorization accuracy. Fan et al. [ 6 ] achieved successful identification of both the bitrate and modulation scheme for on-off keying signals by employing DNN-based multitask learning, which allows for the simultaneous identification of several parameters. Furthermore, they detected the OSNR, Cromatic Dispersion (CD), and differential group delay, alongside Optical Performance Monitoring (OPM). The CNN utilised asynchronous delay-tap sampling as an input parameter in this experiment. Jargon et al. [ 7 ] showed that training a neural network with properties derived from the geometry of a constellation can enable the estimation of unknown transmission characteristics, such as the CD and OSNR. Prior studies have investigated the use of neural networks to estimate the OSNR by eliminating nonlinear noise sources that impact the OSNR [ 8 ]. Machine learning can also be utilised for estimating parameters that are not limited to the OSNR. In their study, Fan et al. [ 6 ] demonstrated that the error vector magnitude can be accurately predicted for different modulation formats by feeding the decoded data of coherent signals into a CNN. A comprehensive analysis in [ 9 ] has extensively examined various machine learning approaches to estimate the OSNR, Qfactor, Bit Error Rate (BER), and other quality of transmission (QoT) metrics. These approaches have been applied in a wide range of applications, including optical communication lines, optical amplifiers, and networks. Recent research has focused on estimating the transmission properties associated with the distance direction of optical fibre transmission lines. The fiberlongitudinal optical power profile of a multi-span optical fibre transmission line is evaluated in representative research [ 10 ] by analysing the waveform data received by a digital coherent optical receiver and recreating the transmitted waveform. Until recently, these tasks were exclusively implemented using Optical Time Domain Reflectometer (OTDR). However, OTDRs have several drawbacks, such as their difficulty in being applied to multi-span optical fibre transmission lines. On the other hand, these techniques, which can calculate the location of optical power reduction without the need for specialised tools, show great potential for achieving extremely precise optical power measurements. Moreover, as a result of OPM, advancements in machine learning are transforming the methods and procedures of operations and maintenance. The conventional approach has been to employ reactive measures, such as altering routes, in response to failures. Nevertheless, the idea of utilising machine learning to identify indications of subtle malfunction and taking proactive measures to replace equipment before a genuine failure transpires has been introduced [ 11 ]. In order to comprehend this, it is imperative to scrutinise the data acquired by OPM, identify any instances of soft failure, and investigate the underlying causes of failure. Shahkarami et al. [ 12 ] utilized machine learning techniques to detect and identify soft failures in multispan optical fiber transmission lines, namely by analyzing the Bit Error Rate (BER). Mayer et al. [ 13 ] showed that real-time soft failure localization may be achieved using a neural network. This is done by collecting the OSNR and input/output power data from the complete network through streaming telemetry. The work in [ 14 ] proposes a multi-task CNN for advanced multiparameter monitoring. All these works show the potential and effective use of AI/ML solutions applied to optical networks. They typically rely on external processing resources implemented e.g. in centralized cloud systems. The introduction of DPUs equipped with embedded GPU and coherent optical transceivers, as proposed in this work, opens the way to the deployment of such solutions in a decentralized and possibly federated scenario, implemented where optical monitoring data are generated and where computed actions can be directly enforced with no communication delay. B. Related work on network security and traffic classification In this subsection we highlight relevant works proposing and validating the use of network programmability/accelerators and deep packet inspection (DPI) applied to cyber security and traffic classification. The work in [ 15 ] proposes anomaly-based methodologies for developing a unique pattern for detecting and identifying Distributed Denial of Services (DDoS) attacks. Signatures-based solutions are indeed preferred over anomaly detection due to their superior efficiency. An Access Control List (ACL) could be created based on the signature to automatically prevent future attacks that match the signature. Zhang et al. [ 16 ] conducted a study on enhancing the performance of the Snort 3.0 IDS by utilizing the Data Plane Development Kit (DPDK). The researchers determined that employing DPDK to enhance and augment the detection rate of Snort effectively resolves the performance concerns. This is accomplished through the implementation of an alternative packet polling technique, reduced CPU interruptions, and a decrease in memory operations. Qinwen et al. [ 17 ] conducted a comparative analysis of the effectiveness of three IDS Snort, Bro, and Suricata. In [ 17 ], crucial parameters are Research Article 3 examined, such as the utilization of system resources, the processing of packets, and the rate at which packets are dropped, that restrict the effectiveness of network intrusion detection system (NIDS) in handling high volumes of traffic in large-scale networks. The limits were determined by the implementation of the following experiments: the default setup, optimizations of the detection method, and modifications to the DAQ configuration to enhance capture performance. The results suggest that specific pattern-matching algorithms will reduce a substantial volume of traffic. Utilizing Suricata, the CPU use is significantly elevated when employing pattern-matching methods, while the NIDSs consume a small number of memory resources. Qinwen et al. [ 18 ] addressed the challenges associated with open-source intrusion detection systems in high-speed networks in their publication. A data transfer rate of 60Gbs is achieved by utilizing a transparent Intrusion Detection System (IDS) in conjunction with eXpress Data Path (XDP). Suricata would initiate and discard packets when the data rate reaches 60 Gb/s. In addition, they attempted to identify malevolent behavior using a solitary rule. At this juncture, they see that employing a solitary rule is inadequate for identifying malevolent behavior. Their research suggests utilizing hardware acceleration techniques to collect traffic on 100Gb/s networks. In 2018, Yang et al. introduced an architecture for regular expression (RE) matching that processes several bytes simultaneously. The architecture incorporates the benefits of three Field-Programmable Gate Array (FPGA)-based algorithms, namely Simple State Merge Tree (SSMT), Distribute Data in Round-Robin (DDRR), and Multipath Speculation, to enhance the speed of matching. Despite being memory frugal, they achieved a processing speed of 140Gbps on a FPGA. Many DPI methods are proposed to classify network traffic. Libprotoident [ 19 ] is a DPI library that identifies application layer protocols for network flows. Unlike other methods that require capturing the entire packet payload, Libprotoident only uses the first four bytes of payload sent in each direction, the size of the first payload-bearing packet in each direction, and the TCP or UDP port numbers for the flow. The nDPI library, cited as [ 20 ], provides application-layer detection of protocols that is independent of the port being used. This allows for the identification of known protocols on non-standard ports, as well as the detection of unknown protocols. Both ntop and nProbe utilize nDPI for this purpose. OpenDPI [ 21 ] is a software library that is built upon the commercial PACE product from Ipoque. It uses a combination of behavioral and statistical analysis techniques to identify transmission types of applications in monitored traffic. Behavioral analysis involves searching for known behavioral patterns of an application in the monitored traffic, while statistical analysis calculates statistical indicators that can be used to identify transmission types. DPI faces a major limitation with encrypted traffic. The reason is that it obstructs access to the underlying data, which makes it difficult to perform DPI effectively [ 22 ]. Chen et al. [ 23 ] proposed an FPGA-based approach for intrusion detection in cloud systems, which offloads detection tasks to FPGA-based SmartNICs for improved efficiency and reduced overhead. This model achieves high throughput, low latency, and high detection accuracy while providing benefits such as improved scalability and reduced power consumption. Although the paper has limitations, such as limited evaluation and lack of comparison with other FPGAbased approaches, it presents an innovative solution to the limitations of software-based intrusion detection in cloud systems. Further research and development could significantly enhance cloud systems and datacenter security. Wang et al. [ 24 ] presented an interesting approach to intrusion detection using extended Berkeley Packet Filter (eBPF) technology in the Linux kernel, but some potential limitations should be considered. Firstly, the effectiveness is decreased on larger networks with higher traffic volumes, which could limit its scalability. Secondly, false positives and negatives are not addressed. Finally, the paper does not evaluate the potential overhead of the system on system resources, such as CPU and memory usage. These limitations should be considered when considering the feasibility and applicability of the proposed system in real-world scenarios. Kim et al. [ 25 ] proposed a real-time network intrusion detection system that uses a deferred decision and hybrid classifier approach to improve detection accuracy and reduce false alarms. The authors provide a comprehensive overview of the system architecture and implementation details, and the experimental results show promising results on a publicly available dataset. 3. ENABLING TECHNOLOGIES A. DPU A DPU is a dedicated hardware component engineered to provide rapid data processing capabilities. DPUs are commonly used in data centers, server configurations, and supercomputers. However, there is increasing interest in exploring their potential use in Telco and edge networking applications. DPUs provide the ability to handle data transport, storage, and processing for huge datasets. This allows for fast computations and supports real-time analysis and acceleration of data-intensive applications. Unlike typical NICs that primarily prioritize low-level protocol acceleration, such as Ethernet, and depend on the server’s CPUs for other networking activities, DPUs have the benefit of programmability at higher layers. They have the ability to directly perform complex activities within the network, thereby releasing processing resources for tenant and application services. The latest DPU iteration has a maximum of four connections functioning at rates of up to 400 Gb/s. These DPUs also possess timing and synchronization capabilities, hardware encryption, and integrated security measures. In addition, they are equipped with a maximum of 16 ARM CPUs to manage embedded computer tasks. The most recent iteration also incorporates integrated GPU capabilities. DPUs often utilize flat-top connections such as OSFP and QSFP112/56/28 form factors rather than the QSFP-DD form factor found in packet-optical switches that support coherent pluggable modules. Nevertheless, the next iteration of coherent transceivers designed to meet these specific dimensions has already been declared for a speed of 100Gbps. Additionally, future generations of SmartNICs are anticipated to also be compatible with QSFP-DD, enabling speeds of 400Gbps and beyond. B. DOCA SDK NVIDIA’s DOCA (Data Center-on-a-Chip Architecture) is a software development framework designed for the BlueField DPUs. It includes libraries, service agents, and reference applications and supports C programming and DPDK for efficient packet processing. DOCA provides dedicated APIs for implementing IPsec, encryption, and decryption, making it easier for developers to integrate these functionalities into their applications. A key component of DOCA is the DOCA Flow library, which enables the customization of packet processing by defining matching criteria and actions. These match-action units are organized in pipes and can be chained together for flexibility. DOCA leverages rte_flow to transmit rules to the embedded switch Research Article 4 (NIC switch) using NVIDIA’s proprietary ASAP2 technology, offloading hardware traffic efficiently. An example DOCA application for URL filtering involves creating OvS bridges and connecting scalable functions (SF). SFs are lightweight functions with dedicated queues for packet transmission and reception, similar to virtual functions (VFs) used in SR-IOV. The OvS bridges are hardware offloaded, with one connecting the physical port to the application (OvS-BR2) and another connecting the application to the host (OvS-BR1). Incoming packets on the physical port are forwarded to the application running on the CPU cores. URL filtering entails parsing the application layer to locate the URL in the HTTP header. The SmartNIC utilizes a regular expression (RegEx) hardware accelerator to scan for the URL, significantly faster than CPU scanning. A third bridge can be created to enable user management of the application, with BlueField providing gRPC interfaces for runtime configuration. C. Optical Transceiver Technology For more than ten years, the rise in capacity in optical networks has mostly been achieved by developing successive generations of coherent optical transceivers that have better capacity and improved spectral efficiency (SE). In the past, coherent optical transceivers were typically integrated onto line cards, with the goal of optimizing both capacity and reach [ 26 ]. The boxes served as a physical barrier between the transport layer and the Ethernet/IP layer. They connected to switches and routers using grey short-reach transceivers, as depicted in Figure 1. The demarcation aligns with the internal structure of the majority of network operators, who typically maintain distinct teams responsible for managing the transport and IP network domains [ 27 ]. A significant advancement in coherent optical transceivers is their availability in pluggable form factors rather than being integrated into line cards. The OpenZR+ MSA [ 28 ] has expanded the range of uses for coherent pluggable optical transceivers by enabling the support of Ethernet client signals over extended distances in mesh optical networks that utilize reconfigurable optical add/drop multiplexer (ROADM) nodes. This development follows the 400ZR standard [ 29 ]. In addition, the OpenROADM MSA [ 30 ] has expanded the range of clients that can be transferred to include the optical transport network (OTN). There are two primary network designs that can be used to make use of coherent pluggable transceivers. The initial configuration maintains the specialised line cards, which currently support coherent pluggable transceivers such as C form-factor pluggable (CFP2) [ 31 ] or Quad small form-factor pluggable double density (QSFP-DD) [ 32 ]. This architecture preserves the distinct separation between transport and IP networks, making it well-suited for network operators who handle a variety of client traffic types. The second architecture takes advantage of the fact that highcapacity routers can naturally accommodate coherent pluggable transceivers in the QSFP-DD form factor. This eliminates the need for dedicated line cards and reduces the number of grey transceivers required. This allows for the efficient implementation of the IP-over-dense wavelength division multiplexing (DWDM) architecture that has been planned for a long time but has not yet been realized [33]. In this work, we assume coherent optical transceiver will be encompassed within SmartNICs/DPUs, overcoming current technological limitations (mainly due to power consumption and dissipation) that today prevent the effective deployment of such converged solution. Fig. 1. The traditional optical network setup (top) involves aggregation routers and standalone transponders. In the evolved scenario (center), white box and coherent transceivers are utilized. The innovative optical metro network scenario incorporates edge computing nodes and DPUs with coherent transceivers (bottom). 4. INNOVATIVE EDGE-CLOUD SCENARIO In this section, we present the innovative edge scenario potentially enabled by the introduction of DPUs with embedded GPU and coherent transceivers. The delivery of 5G/6G services is indeed driving Telco Central Offices (COs) to host not only networking equipment such as routers but also edge computing resources. The separation of networking and computing resources comes at a cost: it is power-hungry, expensive (both in terms of CAPEX and OPEX), and inefficient with respect to latency, as multiple OEO conversions must be experienced in the computing continuum between 5G/6G services and edge and cloud resources. Figure 1(top) shows a traditional network scenario where an edge computing node receives connectivity from a legacy router. The router, equipped with gray interfaces, rely on standalone transponders to communicate across the optical metro network to the Cloud. Thanks to the introduction of coherent pluggable transceivers, of type point-to-point or point-to-multipoint, transponders and aggregation routers can be eliminated as standalone elements, enabling a direct connection from the router to the optical metro infrastructure to towards the Cloud. This way, IP routers equipped with coherent pluggable modules (i.e., IPoDWDM) are driving the design and implementation of low-cost converged packet optical transport solutions, effectively removing boundaries between different IP and optical network domains, as shown in Figure 1(center). Edge computing nodes encompassing DPUs equipped with coherent transceivers have the potential to further improve the edge-to-cloud continuum by removing the barriers between computing and networking resources, as shown in Figure 1(bottom). One benefit is the reduction of active standalone nodes and the necessity for intermediate Optical-Electrical-Optical (OEO) Research Article 5 conversions between the edge computing node and the cloud. The second advantage pertains to reducing delay. This is accomplished by consolidating computational and optical network resources into a unified platform, resulting in a decrease in overall latency. Incorporating high-speed transceivers directly into DPUs will greatly improve the provision of ultra-low latency services for access. This will also allow for the utilization of hardware-accelerated network operations within DPUs, such as encryption. Furthermore, the presence of embedded DPU has the potential to significantly improve networking capabilities and performance by introducing AI processing at DPU. These advantages can result in enhanced performance for both low-latency consumer apps and Telco infrastructure components. For instance, they can enable the implementation of 5G capabilities in proximity to cellular sites. Functions such as UPF-DU-CU could be relocated in close proximity to the cell site and consolidated on robust edge nodes, utilizing (i) hardware-accelerated networking solutions offered by DPUs (e.g., deep packet inspection, cyber security, encryption) and (ii) direct peer-to-peer optical connections to cloud services and point-to-multipoint connections to multiple RUs. In addition, embedded GPUs provide efficient and rapid AI-driven predictive and proactive capabilities [34] 5. PROPOSED SYSTEM MODEL FOR EMBEDDED SECURITY AND MONITORING In this section, we introduce our comprehensive edge network system architecture, depicted in Figure 2, designed for optical failure monitoring and DDoS attack detection using a combination of DPI and deep learning techniques. The system, specifically designed for DPU execution, is structured into two use cases, optical failure monitoring and DDoS detection. Each use case consists of two modules that utilize DPI and deep learning, as shown in Figure 3. Figure 3 illustrates the workflows of our proposed system model. This setup uses Deep Packet Inspection (DPI) using DOCS SDK API (DOCA flow) to inspect packets in real-time, at line rates, for potential threats in high-speed optical networks. The optical use case utilized DPI and deep learning for optical failure monitoring. Security use case demonstrates for detection of DDoS attacks utilizing DPI and deep learning. DPI Module handles packet inspection at wire speed, identifying optical parameters for failure detection and tracing suspicious DDoS packets based on predefined threat signatures and thresholds. Only packets flagged by the DPI are forwarded to the CNN model for further analysis. Once flagged by DPI, packets are processed by CNN models on the DPU/GPU, which perform a detailed investigation for optical failure or DDoS attack detection. The combination of DPI for real-time filtering and CNN for selective deeper analysis ensures that packet processing at line rates (up to 100 Gbps) is not compromised, allowing the network to operate efficiently without latency issues. This approach ensures that the AI models, while powerful for detecting complex attack patterns, do not bottleneck network traffic, as they only analyze a small fraction of the total packet flow. A. Optical Monitoring Using DPI Traditionally, optical monitoring data are retrieved from the optical components, processed by the CPU of the host system, encapsulated in network packets, and delivered to remote nodes or telemetry collectors. Here, those network packets are first retrieved from the network interface, then processed by the host CPU and stored in external time-series databases where NetworkComponents Network Switch Gateway Router EdgeNetwork DPU with Embedded GPU Pluggable Transceiver Optical Data Monitoring Embedded Security Client Device 1Client Device 2 Processes data Applies Transfers optical data Ensures protection CPU GPU Central Data Storage CNN Model Fig. 2. Proposed Edge Network Architecture. AI processing can take place. The introduction of DPU with embedded GPU and coherent transceivers has the potential to significantly improve the efficiency of this procedure. Indeed, optical monitoring data can be locally retrieved by the DPU from the plugged transceiver. Then, hardware-offloaded DPI can be used to extract packet network information avoiding the interaction with the CPU of the host system. Finally, the local GPU can directly perform AI processing, overall guaranteeing fast reaction time and forecasting capabilities. In this work, a specific innovative DPI component has been developed for extracting optical monitoring data from custombuilt UDP packets containing payload information about selected monitoring parameters, such as BER and power levels of optical fiber devices. Then, the hardware-accelerated DPI system continuously inspects these payloads, comparing against predefined thresholds directly configured within the DPU pipes. If the monitored parameters exceed these thresholds, indicating a potential failure, the system is able to react efficiently, performing further elaborations (e.g., exploiting the embedded GPU, see next subsection) and/or sending automated warning/alarm messages possibly leading to traffic reroute even before the link fails. This proactive approach ensures continuous network reliability and operational efficiency also in case of soft-failures. B. Optical Failure Monitoring Using Deep Learning To enhance live detection capabilities, the results of the DPI inspections for optical monitoring are fed into the deep learning models. For optical monitoring, the metrics extracted from DPI, such as BER and power levels, are provided as input features to the CNN. This enables the CNN to make real-time predictions about potential optical failures based on the latest network conditions. We use standard CNNs to analyze data collected from optical networks. The CNN model is trained to detect both gradual and sudden degradations of critical parameters (e.g. pre-FEC BER and power levels), which are indicative of potential failures Research Article 6 AI for DDoS Training Modules Optical Transceiver DPI for Optical Data Extraction CNN for Optical Failure Detection Optical Failure Forecasting Incoming Network Traffic Traffic Rate Threshold Check Drop or Rate-Limit Stateful Flow Tracking DPI Signature Matching Forward Traffic Block and Log Attack Deployed CNN for DDoS Detection DDoS Attack Mitigation Historical Optical Data Storage Historical Network Data Storage Below Threshold No Attack DDoS Signature Detected Dataset 1....Dataset5 Train CNN for Optical Monitoring CICDDoS2019 Dataset Train CNN for DDoS Detection Optical Data DDoS Data Optical Use Case Security Use Case Fig. 3. Proposed System Model and Components in the optical fiber network. The system utilizes both historical data and latest monitoring metrics to predict soft-failures and the remaining useful life (RUL) of the optical components. By forecasting potential failures, the system can trigger preventive recovery and maintenance actions before actual failures occur, thus enhancing network reliability and minimizing downtime. C. DDoS Detection Using DPI Conventional approaches use distinct systems for cybersecurity, leading to integration challenges and higher latency. Traditional monitoring tools often lack the ability to process data in real-time, which is a key requirement for prompt detection and response. Ensuring high accuracy in detecting anomalies requires significant computational resources, which can be a bottleneck in high-speed networks. Conventional DDoS detection systems are often reactive, addressing issues only after they have occurred, leading to potential network downtime and reduced reliability. To address these challenges, we present an integrated system that leverages DPI combined with deep learning models, specifically CNNs, running on DPUs with embedded GPUs. The use of DPUs with embedded GPUs allows for the real-time processing of vast amounts of data, ensuring timely detection and response. The DPU-based DPI system is designed and implemented to continuously monitor incoming network traffic to detect potential DDoS attacks. The system, shown in Figure4, begins by checking if the traffic rate exceeds predefined thresholds, dropping or rate-limiting packets to mitigate immediate threats. Packets that pass this initial threshold check are sent to the Stateful Flow Tracking (SFT) module, which maintains stateful information about network flows, enabling the recognition and tracking of individual flow behaviors over time. The DPI engine inspects packet payloads in detail, comparing attributes against a database of known DDoS attack signatures. If a match is found, the system drops the packet and logs the attack information. This layered approach ensures comprehensive protection against DDoS attacks, leveraging both threshold-based and signature-based detection mechanisms. C.1. Packet Monitoring and Threshold Detection The DPI system continuously monitors incoming network traffic to detect potential DDoS attacks. When the traffic rate exceeds predefined thresholds, packets are either dropped or rate-limited to mitigate the immediate threat. This initial step ensures that the system can handle surges in traffic volume without overwhelming the network infrastructure. C.2. Stateful Flow Tracking (SFT) Packets that pass the initial threshold checks are sent to the Stateful Flow Tracking (SFT) module using the sft_process_packet() function. SFT maintains stateful information about network flows, enabling the system to recognize and track the behavior of individual flows over time. If a packet is not marked with a zone ID by the hardware, the SFT is informed about the packet’s zone using the sft_process_packet_with_zone() function. For packets not marked with a flow ID, a new flow is created using the sft_activate() function, followed by invoking doca_dpi_flow_create() if a new flow ID is assigned. C.3. DPI Processing and Signature Matching Packets are then enqueued for DPI processing using the doca_dpi_enqueue() function. The DPI engine inspects the packet payloads in detail, extracting attributes such as source and destination addresses, protocol information, and payload content. The extracted attributes are compared against a database of predefined signatures representing known DDoS attack patterns. The results of the DPI processing are dequeued using the doca_dpi_dequeue() function. If a match is found, the system checks if it corresponds to a DDoS signature. If so, the packet is dropped. Otherwise, match statistics are printed, and the flow is offloaded to the host for further processing. The detected threat information is retrieved using doca_dpi_signature_get() , and the flow is terminated using doca_dpi_flow_destroy(). D. DDoS Detection Using Deep Learning In traditional network security approaches, Deep Packet Inspection (DPI) is commonly implemented on edge devices using the CPU. This setup can introduce significant performance bottlenecks, particularly when handling high volumes of network traffic. The CPU, responsible for both DPI operations and other system tasks, can become overloaded, leading to slower processing speeds and reduced efficiency. Furthermore, integrating deep learning models for real-time analysis alongside DPI is challenging with conventional CPU-based systems due to their high computational demands and limited parallel processing Research Article 7 Fig. 4. Flowchart of the DPI Packet Processing for Optical Monitoring and DDoS detection and integration with Deep Learning capabilities. This limitation hampers the ability to perform simultaneous DPI and deep learning analyses, thereby affecting the responsiveness and accuracy of DDoS attack detection. To address these challenges and enhance the real-time detection of DDoS attacks, we integrate DPI results with deep learning models. DPI provides critical packet attributes and detected signatures, which are continuously updated and fed into a CNN. This dynamic integration allows the CNN to refine its understanding of both normal and malicious traffic patterns, thereby improving its accuracy in real-time DDoS attack detection. By leveraging DPI inspection outcomes, the system adopts a more adaptive and responsive approach to network security and monitoring. We utilize CNNs to analyze network traffic data and detect patterns indicative of DDoS attacks. The CNN model is trained on features such as packet rate, size, and distribution to differentiate between normal and malicious traffic. This continuous learning process enables the CNN-based detection system to identify and respond to emerging DDoS threats in real time. The integration of deep learning with DPI inspection results provides a robust defense mechanism, enhancing network security and resilience against sophisticated DDoS attacks. 6. IMPLEMENTATION In this section, we report on the implementation of the proposed system model based on the aforementioned four main components. The implementation of optical failure monitoring and DDoS attack detection using DPI and deep learning involves several steps, as outlined in Algorithm 1, Algorithm 2and Algorithm 3. These algorithms detail the process of monitoring incoming traffic, processing packets, and taking action based on detected optical transmission metrics or detected DDoS attack signatures, respectively, including deep learning classification where applicable. A. Fiber Optical network Monitoring using DPI We employ DPI to monitor Bit Error Rate (BER) and fiber power in optical networks, enabling proactive maintenance and failure prediction. In BlueField-2 with DOCA, DPI operations are tightly integrated with hardware offload mechanisms to ensure efficient and high-performance packet processing. We leverage specialized hardware components, such as BlueField-2 SmartNICs, to offload DPI tasks from the host CPU. These SmartNICs are equipped with dedicated processing units optimized for packet inspection and analysis, allowing for parallelized and accelerated DPI operations. When an incoming packet arrives at the SmartNIC, it undergoes deep inspection to extract key attributes, including BER and fiber power values embedded in the payload. After identifying the flow and ensuring it meets certain criteria, such as not exceeding predefined rate thresholds, packets are enqueued for DPI processing. Upon successful processing of the packet by the DPI engine, the result is dequeued for further analysis. If a match is found during DPI processing, it prints and counts match statistics related to the detected metrics. If the BER and fiber power values exceed predefined thresholds, indicating potential link failure, a rerouting request is sent to the edge node to reroute traffic before a failure occurs. Otherwise, the flow is hardware offloaded to the host for further processing. Informa- Research Article 8 80km A1 A2 A3 80km B 80km WSS WSS PinA1 PinA2 PinA3 L1 PowerEdge 1 PowerEdge 2 400ZR+ Edgecore DCS240 NVIDIA BF2 DPU NVIDIA BF2 DPU+GPU MultiFailure Telemetry Dataset Streamer 400ZR+ PinAx PoutAx OSNRLx Fig. 5. Network testbed. tion about the detected metrics is retrieved from the DPI engine for logging or further action. Once the packet processing is complete, the flow is terminated. These statistics about the packet processing, DPI results, and flow termination are retrieved for deep learning training. This inspection is performed at wire speed, ensuring minimal latency and maximum throughput. The DPI engine compares the extracted packet attributes against a database of predefined signatures representing known thresholds and patterns for BER and fiber power. DPI maintains stateful flow tracking information to contextualize packet inspection results. By associating packets with specific network connections or flows, DPI can detect anomalous behavior and identify patterns indicative of potential failures. Upon detecting a match between packet attributes and a threshold in the database, DPI can trigger enforcement actions to mitigate the risk. These actions include sending rerouting requests, packet dropping, rate limiting, and redirection towards another port, depending on the severity and nature of the detected metrics. DPI operations are seamlessly integrated into the broader DOCA framework, allowing for centralized management and orchestration of network performance and security policies. DOCA provides a unified interface for configuring DPI settings, monitoring traffic patterns, and responding to events in realtime. To stay current with network conditions, the DPI regularly updates its signature database. These updates are automatically distributed and applied across BlueField-2 SmartNICs, ensuring that the network remains optimized and protected against evolving risks. DPI signature creation involves a combination of manual analysis, network intelligence gathering, and automated tooling provided by DOCA API. B. Implementation of Optical Monitoring using Deep Learning Model The presence of DPUs equipped with coherent transceivers allows for efficient monitoring and correlation capabilities to be directly integrated into the network card. The received packet and optical data can be processed locally, utilizing high-performance GPU resources. For instance, the in-band telemetry can provide detailed information about the latency performance of each packet. This information can be analysed by embedded P4/DOCA libraries using AI-based algorithms, which are more effective than traditional threshold-based mechanisms. Unlike these mechanisms, which simply send telemetry data to remote management systems, the AI-based algorithms can achieve better results. In addition, the DPU has the ability to process optical parameters received by the local transceivers on-site. As a demonstration of its feasibility, we present the empirical verification of an artificial intelligence (AI) algorithm initially developed for identifying minor malfunctions, which is controlled by a centralised Software-Defined Networking (SDN) Controller [ 35 ]. In this case, the algorithm is being used to evaluate local conditions within the DPU. Figure 5depicts the network testbed under consideration. Two DELL PowerEdge Servers are outfitted with NVIDIA Bluefield2 DPUs that include integrated Graphics Processing Units (GPUs). Due to the lack of support for coherent transceivers in these DPUs, we depend on Edgecore switches that are equipped with 400ZR+ coherent transceivers. Nevertheless, the DPU manages the transceivers using a Rest interface rather than relying on an SDN Controller. This allows the transceivers to be controlled as if they were physically integrated into the DPU. Subsequently, the two transceivers are joined by three optically amplified spans, each spanning a distance of 80 km. The implementation of optical failure monitoring using deep learning involves collecting optical parameters, training a deep learning model offline using CSV files, and deploying the model for real-time predictions, as detailed in Algorithm 2. This algorithm describes the process of data collection, offline training, real-time prediction, and preventive actions. Initially, data is collected from optical devices, including Bit Error Rate (BER) values and power levels, and stored in CSV files for offline training. The collected data is preprocessed to prepare it for training, which includes normalization and handling missing values. The preprocessed data is then used to train a CNN model offline. The CNN architecture, as described in Table 1, is used for this purpose. The training process involves splitting the data into training and validation sets, defining the CNN architecture, and tuning hyperparameters. The model is trained using five datasets of optical failure, ensuring a robust understanding of various failure scenarios. Once the model is trained, it is saved for deployment in the production stage. In real-time, the trained CNN model is deployed, and BER and power level data are collected from optical devices. The deployed CNN model uses this real-time data to predict potential failures by comparing current metrics against learned patterns of normal operation and failure scenarios. The system maintains a feedback loop where detected anomalies and predictions are validated against actual outcomes. This feedback is used to periodically retrain and fine-tune the CNN model using new data collected and stored in CSV files. By updating the training dataset with confirmed failures and normal operation data, Research Article 9 Algorithm 1. DPI Packet Processing for BER and Fiber Power Monitoring with Reroute Request Require: Incoming packet Ensure: Processing results, statistics, and reroute requests if thresholds are exceeded Monitor incoming traffic to identify potential data of interest if Incoming traffic rate exceeds predefined threshold then Drop or rate-limit incoming packets Return Send packet to Stateful Flow Tracking (SFT) for processing with sft_process_packet() if Hardware recognizes the flow then if Packet is not marked with zone ID by HW then Inform SFT about zone of packet with sft_process_packet_with_zone() if Packet is not marked with flow ID by HW or SW then Create new flow with sft_activate() if New flow ID is assigned by SFT then Invoke doca_dpi_flow_create() before enqueuing packet Enforce rate limits for incoming packets if Rate limits exceeded then Drop or rate-limit incoming packets Return Enqueue packet for DPI processing with doca_dpi_enqueue() if Packet is accepted by DPI for processing then Dequeue result with doca_dpi_dequeue() if Match is found then if Matched with BER and Fiber Power signature then Extract BER and Fiber Power values Print and count match statistics Store BER and Fiber Power data for further analysis if BER or Fiber Power is different from predefined thresholds then Send reroute the request to the edge node Return Offload flow to host Retrieve match from DPI engine with doca_dpi_signature_get() Terminate flow with doca_dpi_flow_destroy() Retrieve additional statistics with doca_dpi_stat_get() the model’s accuracy improves over time. Upon predicting a potential failure, the system triggers preventive actions, such as rerouting traffic or scheduling maintenance, to avoid downtime. The CNN model and training process involve several steps. Data preprocessing includes loading data from CSV files, normalizing it to ensure all features have a similar scale, and handling missing values by either imputing them or discarding incomplete records. The model architecture, as outlined in Table 1, consists of an input layer that accepts BER and power level data, convolutional layers to extract features from the input data, pooling layers to reduce the dimensionality of the feature maps, fully connected layers to combine features to predict potential failures, and an output layer that produces the final prediction (failure or no failure). The training process involves splitting the data into training and validation sets, defining the CNN architecture, and compiling the model with an appropriate loss function and optimizer. The model is then trained using the training set and validated using the validation set, with hyperparameters Algorithm 2. Optical Failure Monitoring using Deep Learning Require: Collected BER and power level data in CSV files Ensure: Real-time predictions and preventive actions Collect and store BER and power level data in CSV files Preprocess the collected data (normalization, handling missing values) Train CNN model offline using preprocessed data and the architecture in Table 1 Save the trained CNN model Deploy the trained CNN model to production Collect real-time BER and power level data from optical devices Use the CNN model to predict potential failures if Potential failure predicted then Trigger preventive actions (rerouting traffic, scheduling maintenance) Maintain feedback loop to validate predictions and update training dataset Periodically retrain and fine-tune the CNN model using new data tuned to optimize performance. C. Implementation of DDoS attack detection using DPI We employ DPI to detect and block DDoS traffic effectively. In BlueField-2 with DOCA, DPI (Deep Packet Inspection) operations are tightly integrated with hardware offload mechanisms to ensure efficient and high-performance packet processing. Here’s how DPI works and its connection with hardware offload: We leverage specialized hardware components, such as BlueField-2 SmartNiC, to offload DPI tasks from the host CPU. These SmartNICs are equipped with dedicated processing units optimized for packet inspection and analysis, allowing for parallelized and accelerated DPI operations. When an incoming packet arrives at the SmartNIC, it undergoes deep inspection to extract key attributes such as source and destination addresses, protocol information, and payload content. After identifying the flow and ensuring it meets certain criteria, such as not exceeding predefined rate thresholds, packets are enqueued for DPI processing. Upon successful processing of the packet by the DPI engine, the result is dequeued for further analysis. If a match is found during DPI processing, it prints and counts match statistics related to the detected threat. If the match corresponds to a known DDoS signature, the packet is dropped. Otherwise, the flow is hardware offloaded to the host for further processing. Information about the detected threat is retrieved from the DPI engine for logging or further action. Once the packet processing is complete, the flow is terminated. These statistics about the packet processing, DPI results, and flow termination are retrieved for deep learning training. This inspection is performed at wire speed, ensuring minimal latency and maximum throughput. The DPI engine compares the extracted packet attributes against a database of predefined signatures representing known threats and attack patterns. These signatures are meticulously crafted based on the characteristics of common DDoS attack patterns and we can also utilize these for other malicious activities detection. DPI maintains stateful flow tracking information to contextualize packet inspection results. By associating packets with specific network connections or flows, DPI can detect anomalous behavior and identify patterns indicative of security threats. Upon detecting a match between packet attributes and a Research Article 16 Table 6. Comparison of DPUs with Embedded GPUs and P4-based In-Network Solutions Metric DPU with Embedded GPU P4-based In-Network Switch (Software) In-Network Switch (Hardware) Price (USD) $2,000 - $4,000 per unit $1500 - $10,500 per unit $8,000 - $15,000 per switch Throughput Up to 400 Gbps Up to 20 Gbps Up to 6.4 Tbps Operational Costs Lower due to reduced data transfer Moderate due to reliance on external AI Higher due to large hardware infrastructure AI Processing Capability Embedded AI processing with GPUs Not supported natively Limited to rule-based processing, not suitable for AI Memory Availability Large, supports AI model storage Moderate, supports packet processing Limited, insufficient for large AI models Scalability High due to integration of multiple functions Moderate, requires separate AI infrastructure Low due to reliance on external scaling ALU Processing Power Suitable for complex AI tasks Moderate for basic packet processing Poor for AI workloads, optimized for simple operations Power Consumption Moderate ( 100W per unit) Low ( 50W per unit) High ( 300-500W per switch) narios, where terabytes of data flow through the network per second, hardware-based switches cannot efficiently execute AI algorithms due to their constrained architecture. Consequently, while they offer high throughput regarding packet forwarding, their inability to handle complex AI workloads limits their utility in advanced optical monitoring and security use cases. • In-network switches have limited memory and ALU power, making them unsuitable for large-scale AI tasks, particularly in scenarios with high data rates, such as fiber ISP-level or 5G/6G networks. • P4-based in-network solutions are generally more costeffective from a hardware standpoint, but they lack the embedded AI capabilities that DPUs offer. • In terms of pure network throughput, hardware-based innetwork switches outperform both DPUs and P4-based software switches, making them ideal for large-scale data centers requiring ultra-high-speed networking. • DPUs excel in integrating AI capabilities directly into the network edge, making them more suitable for environments requiring advanced data analysis, such as real-time optical monitoring and security. • By offloading data processing to the edge, DPUs reduce operational costs and improve response times for AI workloads. P4-based solutions, on the other hand, may require additional AI infrastructure, thus increasing the overall cost of deployment in AI-heavy applications. Table 6 compares DPUs with embedded GPUs and P4based in-network solutions with different metrics such as price, throughput, operational costs, and AI processing capability. In-network switches optimized for packet forwarding at wire speeds have limited memory and ALU processing, making them unsuitable for AI tasks, especially in high-data-rate environments like ISP-level fiber networks or 5G/6G use cases. DPUs with embedded GPUs provide a more scalable and efficient solution for edge computing tasks that require high throughput and AI capabilities. 9. CONCLUSION The latest generation of DPUs with embedded GPUs, once equipped with coherent pluggable transceivers, has the potential to enable high-performance packet and optical networking within compact and power-efficient edge computing solutions. In this paper, we present a comprehensive system for monitoring optical failures and detecting DDoS attacks using a DPU with an embedded GPU. Our approach leverages both Deep Packet Inspection (DPI) and deep learning models to provide a robust and efficient solution. The CNN model integration allowed for real-time failure predictions, enabling timely preventive actions. Our results demonstrated a significant reduction in inference time when using DPI. In the case of DDoS attack detection, we utilized both the DPI custom dataset and the CICDDoS2019 dataset to train our deep learning models. The results indicated that the use of DPI improved the detection system’s accuracy, recall, F1 score, and precision. Additionally, the comparison of average inference times between the DPU solution and the DPU with embedded GPU solution underscored the advantages of leveraging hardware acceleration for enhanced performance. The combination of DPI and deep learning models offers a powerful toolset for maintaining the security and reliability of networks. Future work will focus on further optimizing the models and exploring additional use cases for DPI in supporting 5G/6G infrastructures. Research Article 17 ACKNOWLEDGMENTS. This work has been partially supported by the EU SNS SEASON Project (101096120) and by the EU under the Italian National Recovery and Resilience Plan (NRRP) of NextGenerationEU, partnership on “Telecommunications of the Future” (PE00000001 - program “RESTART”). Work is carried out within the Department of Excellence in AI and Robotics 2023-2027. REFERENCES 1. Y. Yan, A. F. Beldachi, R. Nejabati, and D. Simeonidou, “P4-enabled smart nic: Enabling sliceable and service-driven optical data centres,” J. Light. Technol. 38, 2688–2694 (2020). 2. L. Barsellotti, F. Alhamed, J. J. V. Olmos, F. Paolucci, P. Castoldi, and F. Cugini, “Introducing data processing units (DPU) at the edge,” in International Conference on Computer Communications and Networks (ICCCN), (2022). 3. F. Cugini, M. Agus, M. Quagliotti, E. Riccardi, C. Castro, B. Spinnler, and A. Napoli, “Point-to-multi-point coherent optics on data processing units (DPUs) for beyond-5G low-latency applications,” in ICTON, (2023). 4. T. Tanaka, S. Kuwabara, H. Nishizawa, T. Inui, S. Kobayashi, and A. Hirano, “Field demonstration of real-time optical network diagnosis using deep neural network and telemetry,” in 2019 Optical Fiber Communications Conference and Exhibition (OFC), (IEEE, 2019), pp. 1–3. 5. T. Tanimura, T. Hoshida, T. Kato, S. Watanabe, and H. Morikawa, “Data-analytics-based optical performance monitoring technique for optical transport networks,” in Optical Fiber Communication Conference, (Optica Publishing Group, 2018), pp. Tu3E–3. 6. X. Fan, Y. Xie, F. Ren, Y. Zhang, X. Huang, W. Chen, T. Zhangsun, and J. Wang, “Joint optical performance monitoring and modulation format/bit-rate identification by cnn-based multi-task learning,” IEEE Photonics J. 10, 1–12 (2018). 7. J. A. Jargon, X. Wu, H. Y. Choi, Y. C. Chung, and A. E. Willner, “Optical performance monitoring of qpsk data channels by use of neural networks trained with parameters derived from asynchronous constellation diagrams,” Opt. Express 18, 4931–4938 (2010). 8. A. D. Shiner, M. E. Mousa-Pasandi, M. Qiu, M. A. Reimer, E. Y. Park, M. Hubbard, Q. Zhuge, F. J. V. Caballero, and M. O’Sullivan, “Neural network training for osnr estimation from prototype to product,” in Optical Fiber Communication Conference, (Optica Publishing Group, 2020), pp. M4E–2. 9. Y. Pointurier, “Machine learning techniques for quality of transmission estimation in optical networks,” J. Opt. Commun. Netw. 13, B60–B71 (2021). 10. T. Sasai, M. Nakamura, S. Okamoto, F. Hamaoka, S. Yamamoto, E. Yamazaki, A. M. H. Nishizawa, and Y. Kisaka, “Simultaneous detection of anomaly points and fiber types in multi-span transmission links only by receiver-side digital signal processing,” in Optical Fiber Communication Conference, (Optica Publishing Group, 2020), pp. Th1F–1. 11. D. Rafique and L. Velasco, “Machine learning for network automation: overview, architecture, and applications [invited tutorial],” J. Opt. Commun. Netw. 10, D126–D143 (2018). 12. S. Shahkarami, F. Musumeci, F. Cugini, and M. Tornatore, “Machinelearning-based soft-failure detection and identification in optical networks,” in 2018 Optical Fiber Communications Conference and Exposition (OFC), (IEEE, 2018), pp. 1–3. 13. K. S. Mayer, J. A. Soares, R. P. Pinto, C. E. Rothenberg, D. S. Arantes, and D. A. Mello, “Soft failure localization using machine learning with sdn-based network-wide telemetry,” in 2020 European Conference on Optical Communications (ECOC), (IEEE, 2020), pp. 1–4. 14. S. Kulandaivel and R. Jeyachitra, “Combined image hough transform based simultaneous multi-parameter optical performance monitoring for intelligent optical networks,” Opt. Fiber Technol. 79 (2023). 15. B. Molina-Coronado, U. Mori, A. Mendiburu, and J. Miguel-Alonso, “Survey of network intrusion detection methods from the perspective of the knowledge discovery in databases process,” IEEE Transactions on Netw. Serv. Manag. 17, 2451–2479 (2020). 16. D. Zhang and S. Wang, “Optimization of traditional snort intrusion detection system,” in IOP Conference Series: Materials Science and Engineering, vol. 569 (IOP Publishing, 2019), p. 042041. 17. Q. Hu, M. R. Asghar, and N. Brownlee, “Evaluating network intrusion detection systems for high-speed networks,” in 2017 27th International Telecommunication Networks and Applications Conference (ITNAC), (IEEE, 2017), pp. 1–6. 18. Q. Hu, S.-Y. Yu, and M. R. Asghar, “Analysing performance issues of open-source intrusion detection systems in high-speed networks,” J. Inf. Secur. Appl. 51, 102426 (2020). 19. S. Alcock and R. Nelson, “Libprotoident: traffic classification using lightweight packet inspection,” Tech. rep., Technical report, University of Waikato (2012). 20. L. Deri, M. Martinelli, T. Bujlow, and A. Cardigliano, “ndpi: Open-source high-speed deep packet inspection,” in 2014 International Wireless Communications and Mobile Computing Conference (IWCMC), (IEEE, 2014), pp. 617–622. 21. T. Bujlow, V. Carela-Español, and P. Barlet-Ros, “Independent comparison of popular dpi tools for traffic classification,” Comput. Networks 76, 75–89 (2015). 22. M. Çelebi, A. Özbilen, and U. Yavano˘ glu, “A comprehensive survey on deep packet inspection for advanced network traffic analysis: issues and challenges,” Nigde 12, 1–29 (2023). 23. J. Chen, X. Zhang, T. Wang, Y. Zhang, T. Chen, J. Chen, M. Xie, and Q. Liu, “Fidas: Fortifying the cloud via comprehensive fpga-based offloading for intrusion detection: industrial product,” in Proceedings of the 49th Annual International Symposium on Computer Architecture, (2022), pp. 1029–1041. 24. S.-Y. Wang and J.-C. Chang, “Design and implementation of an intrusion detection system by using extended bpf in the linux kernel,” J. Netw. Comput. Appl. 198, 103283 (2022). 25. T. Kim and W. Pak, “Real-time network intrusion detection using deferred decision and hybrid classifier,” Futur. Gener. Comput. Syst. 132, 51–66 (2022). 26. D. Welch, A. Napoli, J. Bäck, W. Sande, J. Pedro, F. Masoud, C. Fludger, T. Duthel, H. Sun, S. J. Hand et al., “Point-to-multipoint optical networks using coherent digital subcarriers,” J. Light. Technol. 39, 5232–5247 (2021). 27. P. A. Robles, Ó. G. de Dios, J. P. F.-P. Giménez, L. M. Contreras, L. Roelens, A. M. Da Costa, J. V. Martínez, and D. D. L. O. Mostazo, “Transport sdn architecture for multi-layer transport slicing,” J. Opt. Commun. Netw. 16, D76–D85 (2024). 28. C. Xie and B. Zhang, “Scaling optical interconnects for hyperscale data center networks,” Proc. IEEE 110, 1699–1713 (2022). 29. OIF, “Oif 400zr ia,” https://www.oiforum.com/technical-work/hottopics/ 400zr-2/. Accessed: 2024-07-17. 30. Open ROADM MSA, “Open roadm msa,” http://openroadm.org/. Accessed: 2024-07-17. 31. CFP MSA, “Cfp msa,” https://cfp-msa.org/documents/. Accessed: 2024-07-17. 32. QSFP-DD MSA, “Qsfp-dd msa,” http://www.qsfp-dd.com/specification/. Accessed: 2024-07-17. 33. A. Klekamp, U. Gebhard, and F. Ilchmann, “Efficiency of adaptive and mixed-line-rate ip over dwdm networks regarding capex and power consumption,” J. Opt. Commun. Netw. 4, B11–B16 (2012). 34. Q. Liang, W. A. Hanafy, A. Ali-Eldin, and P. Shenoy, “Model-driven cluster resource management for ai workloads in edge clouds,” ACM Transactions on Auton. Adapt. Syst. 18, 1–26 (2023). 35. M. F. Silva et al., “Confidentiality-preserving machine learning algorithms for soft-failure detection in optical communication networks,” J. Opt. Commun. Netw. 15, C212–C222 (2023). 36. S. ur Rehman, M. Khaliq, S. I. Imtiaz, A. Rasool, M. Shafiq, A. R. Javed, Z. Jalil, and A. K. Bashir, “Diddos: An approach for detection and identification of distributed denial of service (ddos) cyberattacks using gated recurrent units (gru),” Futur. Gener. Comput. Syst. 118, 453–466 (2021). Research Article 18 37. R. Doriguzzi-Corin, S. Millar, S. Scott-Hayward, J. Martinez-del Rincon, and D. Siracusa, “Lucid: A practical, lightweight deep learning solution for ddos attack detection,” IEEE Transactions on Netw. Serv. Manag. 17, 876–889 (2020). 38. M. Wang, Y. Lu, and J. Qin, “A dynamic mlp-based ddos attack detection method using feature selection and feedback,” Comput. & Secur. 88, 101645 (2020). 39. S. Ahmed, Z. A. Khan, S. M. Mohsin, S. Latif, S. Aslam, H. Mujlid, M. Adil, and Z. Najam, “Effective and efficient ddos attack detection using deep learning algorithm, multi-layer perceptron,” Futur. Internet 15, 76 (2023). 40. H. Lun, M. Fu, X. Liu, Y. Wu, L. Yi, W. Hu, and Q. Zhuge, “Soft failure identification for long-haul optical communication systems based on one-dimensional convolutional neural network,” J. Light. Technol. 38, 2992–2999 (2020). 41. A. A. Najar and S. M. Naik, “Cyber-secure sdn: A cnn-based approach for efficient detection and mitigation of ddos attacks,” Comput. & Secur. 139, 103716 (2024).