Firewall policy inspection apparatus and method
    1.
    发明授权
    Firewall policy inspection apparatus and method 有权
    防火墙策略检查装置及方法

    公开(公告)号:US09083678B2

    公开(公告)日:2015-07-14

    申请号:US13946852

    申请日:2013-07-19

    CPC classification number: H04L63/0263 H04L63/0227 H04L63/1433 H04L63/1466

    Abstract: A firewall policy inspection apparatus and method is provided. The firewall policy inspection apparatus includes an intrusion prevention rule obtainment unit for obtaining intrusion prevention rules from a target firewall policy. An anomaly rule detection unit detects an anomaly rule in a relationship between the intrusion prevention rules. A screen display unit displays an anomaly rule graph on a screen using results of the detection.

    Abstract translation: 提供了防火墙策略检查装置和方法。 防火墙策略检查装置包括从目标防火墙策略获取入侵防御规则的入侵防御规则获取单元。 异常规则检测单元检测入侵防范规则之间的关系中的异常规则。 屏幕显示单元使用检测结果在屏幕上显示异常规则图。

    Network intrusion detection apparatus and method using Perl compatible regular expressions-based pattern matching technique
    3.
    发明授权
    Network intrusion detection apparatus and method using Perl compatible regular expressions-based pattern matching technique 有权
    网络入侵检测装置和方法采用Perl兼容的基于正则表达式的模式匹配技术

    公开(公告)号:US09444828B2

    公开(公告)日:2016-09-13

    申请号:US14023635

    申请日:2013-09-11

    CPC classification number: H04L63/1416

    Abstract: A network intrusion detection apparatus and method that perform Perl Compatible Regular Expressions (PCRE)-based pattern matching on the payloads of packets using a network processor equipped with a Deterministic Finite Automata (DFA) engine. The network intrusion detection apparatus includes a network processor core for receiving packets from a network, and transmitting payloads of the received packets to a Deterministic Finite Automata (DFA) engine. A detection rule converter converts a PCRE-based detection rule, preset to detect an attack packet, into a detection rule including a pattern to which only PCRE grammar corresponding to the DFA engine is applied. The DFA engine performs PCRE pattern matching on the payloads of the packets based on the detection rule converted by the detection rule converter.

    Abstract translation: 一种网络入侵检测装置和方法,其使用配备有确定性有限自动机(DFA)引擎的网络处理器,对分组的有效载荷执行基于Perl兼容正则表达式(PCRE)的模式匹配。 网络入侵检测装置包括用于从网络接收分组并将接收的分组的有效载荷发送到确定性有限自动机(DFA)引擎的网络处理器核心。 检测规则转换器将基于PCRE的检测规则转换为包含仅对应于DFA引擎的PCRE语法的模式的检测规则,以检测攻击包。 DFA引擎根据检测规则转换器转换的检测规则对报文的有效载荷进行PCRE模式匹配。

Patent Agency Ranking