Invention Grant
- Patent Title: Speed and memory optimization of intrusion detection system (IDS) and intrusion prevention system (IPS) rule processing
-
Application No.: US12230338Application Date: 2008-08-28
-
Publication No.: US08474043B2Publication Date: 2013-06-25
- Inventor: Steven Sturges , Marc Norton
- Applicant: Steven Sturges , Marc Norton
- Applicant Address: US MD Columbia
- Assignee: Sourcefire, Inc.
- Current Assignee: Sourcefire, Inc.
- Current Assignee Address: US MD Columbia
- Agency: Posz Law Group, PLC
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
In an intrusion detection/prevention system, network traffic is received and checked for a matching pattern. Upon identifying the matching pattern, the network traffic with the matching pattern is evaluated against rules that are represented by a rule tree. References to rule options are represented in the rule tree and are stored separately from the rule tree. The rule tree represents unique rules by unique paths from a root of the tree to the leaf nodes, and represents rule options as non-leaf nodes of the rule tree. Evaluating the network traffic includes processing, against the network traffic, the rule options in the rule tree beginning at the root. Processing of the rules represented by subtrees of nodes with rule options that do not match is eliminated. The network traffic is evaluated against rules terminating in leaf nodes only for combinations of rule options that match the network traffic.
Public/Granted literature
Information query