Comment They keep trying... (Score 1) 30
They've been trying to create a problem for the solution of Bluefield to apply to, but with limited success.
Here runs into the same sort of problem they have had on other applications they have tried: The visibility of the NIC into the stack is too limited to make especially valuable decisions on.
Unless you get the instrumented stack to cooperate with the DPU to provide more insight, which quickly gets to the question of why bother to have the DPU do the work when it is now subject to the assessment of the host anyway, the host could feed 'bad' data if the host was compromised.
You should reasonably be able to tell the host is trying to reach an IP address. We are at basic firewall. If the host is using good old fashioned DNS with no caching, you might be able to discern with high confidence what the Host header in that TLS stream would be based on spying on the DNS activity (but caching and lots of activity could confuse things), so fancier than a firewall by applying a convoluted correlation. Of course you have *zero* insight into what URL and what method and what payload, because it's just such an awkward position.