Invention Grant
US08166536B1 Transformation of network filter expressions to a content addressable memory format 有权
将网络过滤器表达式转换为内容可寻址内存格式

Transformation of network filter expressions to a content addressable memory format
Abstract:
A network device, such as a firewall, may be configured to filter network traffic. The filter may include regular expressions that are converted by the firewall into a format that can be stored in a ternary content addressable memory. In one exemplary implementation, the filter definition may include one or more input regular expressions that include variables that are compared to a result based on an equality/inequality relationship, where multiple variables are combined using logical operations selected from a set of logical operations including (but not limited to) logical AND and logical OR operations. The firewall may convert the input regular expressions into a format in which the equality/inequality relationships are converted to a pure equality relationship and the multiple variables are combined using only logical OR operations. The firewall may program the ternary content-addressable memory to implement the filter based on the converted one or more input regular expressions.
Public/Granted literature
Information query
Patent Agency Ranking
0/0