发明名称 |
Methods and systems for full pattern matching in hardware |
摘要 |
Methods and systems are provided for hardware-based pattern matching. In an embodiment, an intrusion-prevention system (IPS) identifies a full match between a subject data word comprising subject-data blocks and a signature data pattern comprising signature-data blocks. The IPS receives the subject data word via a network interface, and thereafter makes a partial-match determination that two or more but less than all of the subject-data blocks respectively match the same number of the signature-data blocks stored in partial-match hardware with respect to both value and position. Thereafter, the IPS makes a full-match determination that all of the subject-data blocks respectively match all of the signature-data blocks stored in the IPS's full-match hardware with respect to both value and position. The IPS then stores an indicator that the full-match determination has been made, and may carry out one or more additional intrusion-prevention responses as well.
|
申请公布号 |
US8458796(B2) |
申请公布日期 |
2013.06.04 |
申请号 |
US201113043287 |
申请日期 |
2011.03.08 |
申请人 |
STITES RONALD S.;BOTKIN CRAIG D.;CAMPBELL BRIAN K.;HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P. |
发明人 |
STITES RONALD S.;BOTKIN CRAIG D.;CAMPBELL BRIAN K. |
分类号 |
G06F11/00;G06F11/30;G06F17/00 |
主分类号 |
G06F11/00 |
代理机构 |
|
代理人 |
|
主权项 |
|
地址 |
|