发明名称 INTRUSION DETECTION SYSTEM (IDS) AND INTRUSION PREVENTION SYSTEM (IPS) RULE PROCESSING
摘要 <p>In an intrusion detection/prevention system, network traffic is received and checked for a matching pattern. Upon identifying the matching pattern, the network traffic with the matching pattern is evaluated against rules that are represented by a rule tree (101). References to rule options (131) are represented in the rule tree (101) and are stored separately from the rule tree. The rule tree represents unique rules by unique paths from a root of the tree (103) to the leaf nodes (111, 115, 121, 127), and represents rule options (133) as non-leaf nodes (103) of the rule tree. Evaluating the network traffic includes processing, against the network traffic, the rule options in the rule tree beginning at the root (103). Processing of the rules represented by subtrees of nodes with rule options that do not match is eliminated. The network traffic is evaluated against rules terminating in leaf nodes (111, 115, 121, 127) only for combinations of rule options that match the network traffic.</p>
申请公布号 WO2009128881(A1) 申请公布日期 2009.10.22
申请号 WO2009US02210 申请日期 2009.04.09
申请人 SOURCEFIRE, INC.;STURGES, STEVEN;NORTON, MARC 发明人 STURGES, STEVEN;NORTON, MARC
分类号 G06F11/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址