Invention Grant
- Patent Title: Matching with a large vulnerability signature ruleset for high performance network defense
- Patent Title (中): 与高性能网络防御的大型漏洞签名规则集相匹配
-
Application No.: US12846541Application Date: 2010-07-29
-
Publication No.: US08522348B2Publication Date: 2013-08-27
- Inventor: Yan Chen , Zhichun Li , Gao Xia , Bin Liu
- Applicant: Yan Chen , Zhichun Li , Gao Xia , Bin Liu
- Applicant Address: US IL Evanston
- Assignee: Northwestern University
- Current Assignee: Northwestern University
- Current Assignee Address: US IL Evanston
- Agency: Hanley, Flight and Zimmerman, LLC
- Main IPC: G06F11/00
- IPC: G06F11/00

Abstract:
Systems, methods, and apparatus are provided for vulnerability signature based Network Intrusion Detection and/or Prevention which achieves high throughput comparable to that of the state-of-the-art regex-based systems while offering improved accuracy. A candidate selection algorithm efficiently matches thousands of vulnerability signatures simultaneously using a small amount of memory. A parsing transition state machine achieves fast protocol parsing. Certain examples provide a computer-implemented method for network intrusion detection. The method includes capturing a data message and invoking a protocol parser to parse the data message. The method also includes matching the parsed data message against a plurality of vulnerability signatures in parallel using a candidate selection algorithm and detecting an unwanted network intrusion based on an outcome of the matching.
Public/Granted literature
- US20110030057A1 MATCHING WITH A LARGE VULNERABILITY SIGNATURE RULESET FOR HIGH PERFORMANCE NETWORK DEFENSE Public/Granted day:2011-02-03
Information query