- Patent Title: Safe code for signature updates in an intrusion prevention system
-
Application No.: US15199866Application Date: 2016-06-30
-
Publication No.: US10250620B2Publication Date: 2019-04-02
- Inventor: Vladimir Lifliand , Evgeney Ryzhyk , Yifat Sagiv , Maxim Uritsky
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Agency: Workman Nydegger
- Main IPC: G06F8/41
- IPC: G06F8/41 ; H04L29/06

Abstract:
Described is a technology by which a signature used by network traffic intrusion prevention/detection systems includes logic that helps a prevention/detection engine detect that signature. A signature to detect is compiled into executable logic that is executed to communicate with an engine that evaluates network traffic. The signature logic provides an expression set (such as group of regular expressions) for the engine to match against a token corresponding to the network traffic. When matched, the engine notifies the logic and receives a further expression set to match, or a communication indicative that that the signature was detected. The signature thus directs the analysis, facilitating a lightweight, generic engine. Safety of the signature logic is described as being accomplished through layers, including by publisher signing, and by compilation and execution (e.g., interpretation) in safe environments.
Public/Granted literature
- US20160315957A1 SAFE CODE FOR SIGNATURE UPDATES IN AN INTRUSION PREVENTION SYSTEM Public/Granted day:2016-10-27
Information query