发明名称 IPS DETECTION PROCESSING METHOD, NETWORK SECURITY DEVICE AND SYSTEM
摘要 An IPS detection processing method, a network security device and system. The method includes: determining whether an intranet device is a client or a server; if it is a client, then simplifying an IPS signature rule library as an IPS signature rule library corresponding to the client, or if it is a server, then simplifying the IPS signature rule library as an IPS signature rule library corresponding to the server; and generating a state machine according to the signature rules in the simplified IPS signature rule library, and applying the state machine to perform IPS detection on the traffic flowing therethrough. In the embodiments of the present invention, a network security device can determine whether an intranet device is a client or a server, simplify the IPS signature rule library according to the determination result, and generate a state machine according to the simplified IPS signature rule library, and therefore the IPS detection can be performed by a state machine with the redundancy state being removed when performing IPS detection, thus being able to improve the IPS detection efficiency.
申请公布号 WO2013097493(A1) 申请公布日期 2013.07.04
申请号 WO2012CN81547 申请日期 2012.09.18
申请人 HUAWEI DIGITAL TECHNOLOGIES (CHENG DU) CO., LIMITED;XUE, ZHIHUI;JIANG, WU;LI, SHIGUANG;WAN, SHIGUANG 发明人 XUE, ZHIHUI;JIANG, WU;LI, SHIGUANG;WAN, SHIGUANG
分类号 H04L12/26 主分类号 H04L12/26
代理机构 代理人
主权项
地址