发明名称 MATCHING WITH A LARGE VULNERABILITY SIGNATURE RULESET FOR HIGH PERFORMANCE NETWORK DEFENSE
摘要 Systems, methods, and apparatus are provided for vulnerability signature based Network Intrusion Detection and/or Prevention which achieves high throughput comparable to that of the state-of-the-art regex-based systems while offering improved accuracy. A candidate selection algorithm efficiently matches thousands of vulnerability signatures simultaneously using a small amount of memory. A parsing transition state machine achieves fast protocol parsing. Certain examples provide a computer-implemented method for network intrusion detection. The method includes capturing a data message and invoking a protocol parser to parse the data message. The method also includes matching the parsed data message against a plurality of vulnerability signatures in parallel using a candidate selection algorithm and detecting an unwanted network intrusion based on an outcome of the matching.
申请公布号 US2011030057(A1) 申请公布日期 2011.02.03
申请号 US20100846541 申请日期 2010.07.29
申请人 NORTHWESTERN UNIVERSITY 发明人 CHEN YAN;LI ZHICHUN;XIA GAO;LIU BIN
分类号 G06F21/00;H04L9/32 主分类号 G06F21/00
代理机构 代理人
主权项
地址