Trie search engines and ternary CAM used as pre-classifier
    2.
    发明授权
    Trie search engines and ternary CAM used as pre-classifier 失效
    Trie搜索引擎和三进制CAM用作预分类器

    公开(公告)号:US07707217B2

    公开(公告)日:2010-04-27

    申请号:US11041629

    申请日:2005-01-24

    IPC分类号: G06F17/30

    摘要: A method performs a lookup on a search key word, employing a trie database including multiple trie blocks that include pointers to other trie blocks. Each trie is accessible by means of a segment of the search key. A selected section of the search key word is applied to a content addressable memory. In the event of an absence of a match of the selected section with an entry in the content addressable memory, a trie search is performed on the whole search key word. In the event of a match of the selected section with an entry in the content addressable memory, a partial trie search is performed, commencing with a first segment of the search key word after the selected section that has been matched in the content addressable memory.

    摘要翻译: 一种方法对搜索关键字执行查找,采用包括多个trie块的特里数据库,其中包括指向其他​​特里区块的指针。 每个线索都可以通过搜索键的一段进行访问。 搜索关键字的选定部分被应用于内容可寻址存储器。 在所选择的部分与内容可寻址存储器中的条目没有匹配的情况下,对整个搜索关键字执行特里搜索。 在所选择的部分与内容可寻址存储器中的条目匹配的情况下,执行部分特里搜索,从在内容可寻址存储器中匹配的所选择的部分之后的搜索关键字字的第一片段开始。

    Reduction of false positive detection of signature matches in intrusion detection systems
    3.
    发明授权
    Reduction of false positive detection of signature matches in intrusion detection systems 有权
    减少入侵检测系统中签名匹配的假阳性检测

    公开(公告)号:US07802094B2

    公开(公告)日:2010-09-21

    申请号:US11064225

    申请日:2005-02-22

    IPC分类号: H04L9/00

    CPC分类号: H04L63/1408 H04L47/2441

    摘要: Detection of a signature in a data packet comprises performing a pre-classification of the packet, using header information and particularly a 5-tuple access control list, into one of a multiplicity of flows and directing the payload of the packet to a respective one of a multiplicity of deterministic finite state machines each of which stores a plurality of signatures as a sequence of states and acts only on the respective flow.

    摘要翻译: 数据分组中的签名的检测包括使用头信息,特别是5元组访问控制列表来执行分组的预分类到多个流中的一个,并将分组的有效载荷指向相应的一个 多个确定性有限状态机,其各自存储多个签名作为状态序列,并且仅作用于相应的流。