Invention Grant
- Patent Title: Method and device for optimizing and configuring detection rule
- Patent Title (中): 优化和配置检测规则的方法和设备
-
Application No.: US14300409Application Date: 2014-06-10
-
Publication No.: US09411957B2Publication Date: 2016-08-09
- Inventor: Wu Jiang , Tao Wang
- Applicant: Huawei Technologies Co., Ltd.
- Applicant Address: CN Shenzhen
- Assignee: Huawei Technologies Co., Ltd.
- Current Assignee: Huawei Technologies Co., Ltd.
- Current Assignee Address: CN Shenzhen
- Agency: Conley Rose, P.C.
- Agent Grant Rodolph
- Priority: CN201110459531 20111231
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/55 ; H04L12/26

Abstract:
A method and a device for optimizing and configuring a detection rule, where the method includes: a network entity receives network traffic; extracts a packet from the network traffic, and identifies, according to a feature of the packet, protocol related information used in the network; saves the protocol related information and correspondence between pieces of information in the protocol related information to a first learning association table; and matches a corresponding rule from a vulnerability rule base according to the protocol related information to generate a first compact rule set. Through the generated compact rule set in the present invention, subsequent protocol detection is performed only for a protocol threat that may occur in a live network; therefore, content that needs to be detected subsequently is reduced, the detection efficiency is improved, and unnecessary performance consumption is avoided at the same time.
Public/Granted literature
- US20140289856A1 Method and Device for Optimizing and Configuring Detection Rule Public/Granted day:2014-09-25
Information query