NETWORK INTRUSION DETECTION APPARATUS AND METHOD USING PERL COMPATIBLE REGULAR EXPRESSIONS-BASED PATTERN MATCHING TECHNIQUE
    1.
    发明申请
    NETWORK INTRUSION DETECTION APPARATUS AND METHOD USING PERL COMPATIBLE REGULAR EXPRESSIONS-BASED PATTERN MATCHING TECHNIQUE 有权
    网络侵入检测装置和使用PERL兼容的基于正则表达式的图案匹配技术的方法

    公开(公告)号:US20140123288A1

    公开(公告)日:2014-05-01

    申请号:US14023635

    申请日:2013-09-11

    CPC classification number: H04L63/1416

    Abstract: A network intrusion detection apparatus and method that perform Perl Compatible Regular Expressions (PCRE)-based pattern matching on the payloads of packets using a network processor equipped with a Deterministic Finite Automata (DFA) engine. The network intrusion detection apparatus includes a network processor core for receiving packets from a network, and transmitting payloads of the received packets to a Deterministic Finite Automata (DFA) engine. A detection rule converter converts a PCRE-based detection rule, preset to detect an attack packet, into a detection rule including a pattern to which only PCRE grammar corresponding to the DFA engine is applied. The DFA engine performs PCRE pattern matching on the payloads of the packets based on the detection rule converted by the detection rule converter.

    Abstract translation: 一种网络入侵检测装置和方法,其使用配备有确定性有限自动机(DFA)引擎的网络处理器,对分组的有效载荷执行基于Perl兼容正则表达式(PCRE)的模式匹配。 网络入侵检测装置包括用于从网络接收分组并将接收的分组的有效载荷发送到确定性有限自动机(DFA)引擎的网络处理器核心。 检测规则转换器将基于PCRE的检测规则转换为包含仅对应于DFA引擎的PCRE语法的模式的检测规则,以检测攻击包。 DFA引擎根据检测规则转换器转换的检测规则对报文的有效载荷进行PCRE模式匹配。

Patent Agency Ranking