Quick rule matching method
By merging ACL rules for the same action, using rule hierarchy and dichotomy matching, the problem of linear matching performance bottleneck when the ACL entries are large is solved, and the efficiency of the rule matching system is significantly improved.
Patent Information
- Application Number
- CN202510261562.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-06-03
AI Technical Summary
In the prior art, when the ACL entries are large, linear matching methods become a performance bottleneck, and the hash table and matching option methods have shortcomings in improving matching performance.
By combining a single rule that performs the same action, the rule size is reduced; rule hierarchy and dichotomy matching are adopted to further reduce the scale of the rule set that needs to be matched and improve matching performance.
It effectively narrows the overall scale of rules and the matching performance bottleneck of a single rule, and improves the matching efficiency of the entire rule matching system.
Smart Images

Figure CN120090849A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and particularly to a method for rapid rule matching. Background Art
[0002] Currently, in various levels of networks, ACL (Access Control List) is mainly used as the basis for packet filtering function. Therefore, the matching performance of ACL is directly related to network performance. A slight improvement in ACL matching performance will cause a butterfly effect in the entire network topology, thereby shortening the information delay of the entire network topology.
[0003] In the case of a small number of ACL entries, most systems choose linear matching, which is the most direct and easiest matching method to implement. However, as the scale of ACL entries increases, the linear matching method gradually becomes a performance bottleneck, so a higher-performance matching method is needed.
[0004] In the prior art, the methods for quickly searching, locating, and matching ACL mainly include: serializing all matching domain information strings of the ACL rules to be configured to improve the matching efficiency; determining the final matching rule according to the packet matching option to improve the packet matching efficiency. These methods can improve the packet filtering performance to a certain extent, but have the following deficiencies:
[0005] (1) The search for the matching domain information after string serialization depends on the hash algorithm. By hashing the ACL entries into the hash table, the scale of the rules that finally need to be matched is reduced. If the selected hash algorithm cannot effectively hash the ACL entries, the matching performance cannot be significantly improved; and the way of using the hash table is to exchange space for time, which is inconvenient to implement when the memory space is tight.
[0006] (2) Determining the rule set that needs to be matched through the matching option reduces the scale of the rules that need to be matched to a certain extent, which is similar to the core idea of the above-mentioned way of using the hash table for hashing. However, if the overall scale of the ACL entries is huge, the scale set that finally needs to be matched may still be large, and this method does not improve the matching performance of a single rule itself. Summary of the Invention
[0007] In view of the deficiencies of the prior art, the present disclosure provides a method and system for rapid rule matching, which can merge single rules that perform the same action to reduce the rule scale from the very beginning; then through rule layering, further reduce the scale of the rule set that needs to be matched when performing rule matching on packets; at the same time, introduce the dichotomy method when matching a single rule to further improve the matching performance, thereby improving the matching efficiency of the entire rule matching system.
[0008] The rule quick matching method provided by the present disclosure mainly includes the following steps:
[0009] S1. For multiple rules issued through configuration, according to the categories of matching resources, the matching items of the same category of matching resources are regarded as one layer, and there are as many layers as there are categories of matching items; each matching item merged in the same layer is regarded as a range, so the matching items in the same layer are an unordered set of several ranges;
[0010] S2. Arrange the ranges in the same category of matching items in an orderly manner according to their upper and lower boundaries to form multiple intervals. A single rule before merging is only associated with the intervals within the range of its matching item.
[0011] S3. For complex rules that reference more than one category of matching resources, merge the matching items of each category of matching resources of it with other single rules that only contain the same category of matching resources to the same level;
[0012] S4. Divide the packets to be filtered according to the levels formed in steps S1 - S3, and successively take the specific values of each category of items to be matched. Match the taken values in the range intervals of their corresponding levels in turn, and filter out the unmatched rules layer by layer; thereby finally determining the specific rule corresponding to the packet to execute the predetermined action of the rule.
[0013] Further, the types of the matching resources include one or more of source address, destination address, security domain, protocol, and / or port.
[0014] Further, in step S4, in the step of successively matching the taken values in the range intervals of their corresponding levels, the binary method is used to determine whether it belongs to a certain interval of a certain level.
[0015] Further, before step S1, the following steps are further included:
[0016] S0. For multiple single rules that reference the same category of matching items, if their execution actions are the same, then merge the matching items of these rules as a single rule, thereby reducing the scale of the overall rules.
[0017] Further, the rule is an ACL rule.
[0018] Compared with the prior art, the beneficial effects of the present disclosure are as follows: ① By integrating the original configuration rules, the overall scale of the rules is reduced; ② By defining the range and dividing the intervals of the same-type matching items in the rules, and adding the hierarchical representation between different matching items, the binary search method can be introduced into the range matching, and the scale of the rules to be finally matched is reduced layer by layer; ③ By defining the range and dividing the intervals of the matching resources such as addresses, the binary search method can also be introduced during the matching of a single rule, improving the matching performance of a single rule (from O(n) to O(lg(n))). BRIEF DESCRIPTION OF THE DRAWINGS
[0019] By describing the exemplary embodiments of the present disclosure in more detail with reference to the accompanying drawings, the above and other objects, features, and advantages of the present disclosure will become more apparent. Among them, in the exemplary embodiment mode of the present disclosure, the same reference numerals generally represent the same components.
[0020] Figure 1 FIG. is a flowchart of rule matching according to the present disclosure;
[0021] Figure 2 and Figure 3 FIG. is an example of range division at two levels;
[0022] Figure 4 FIG. is an example of the constructed rule matching hierarchy;
[0023] Figure 5 FIG. is an example of the construction process, where (a) represents the hierarchy when only R1 exists, and (b) represents the hierarchy after inserting R2. The structure marked as NIL indicates that it is empty here. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0024] The preferred embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although the preferred embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided to make the present disclosure more thorough and complete, and to fully convey the scope of the present disclosure to those skilled in the art.
[0025] The present disclosure provides a method for fast rule matching.
[0026] In an exemplary embodiment, all rules are: each rule is a single rule that only involves one type of matching resource. Then, the fast matching method according to the present disclosure mainly includes the following steps:
[0027] A. For multiple rules issued through configuration, if their execution actions are the same, merge the source address matching items in the rules as a single rule, and the source address matching item of the single rule is the union of the source address matching items of the multiple rules;
[0028] B. Consider each matching item in the rule as a range (interval), and the range itself is a closed set. The rule itself includes a matching part and an action part, and the matching part is an unordered set of the ranges;
[0029] C. For the same type of matching items in all rules, sort them in ascending order according to all upper and lower boundaries of their ranges, thus generating multiple intervals. A single rule is only associated with the intervals included within the range of its matching item; continue the same operation for the next same type of matching item, so that the interval arrangement of each same type of matching item forms a level. There are as many levels as there are types of matching items;
[0030] D. For the packets to be filtered, take the values according to the matching item values, and the obtained values form a point set. For each point in the point set, determine the truly matching rule set according to the above-mentioned matching item levels and interval arrangements (determine the interval in the interval arrangement, and use an algorithm similar to the binary search method to accelerate the positioning). After traversing all points in this way, the remaining rule set is the truly matching rule, and further more detailed matching can be performed;
[0031] For single rule matching, the performance bottleneck lies in resources with large amounts of information such as addresses. By using a method similar to the above, organize resources such as addresses in the form of interval arrangements, and when matching, an algorithm similar to the binary search method can be used to accelerate the resource matching of a single rule. This method can effectively improve the performance of the rule matching system.
[0032] In another exemplary embodiment, in addition to a single rule where each rule only involves a single type of matching resource, there are also single rules that simultaneously reference two or more complex matching resources. The types of complex matching resources include: address resources (source, destination), security domain resources (network interfaces), service resources (protocols and ports), etc. This embodiment takes the example of referencing two types of matching resources, namely source address and destination address. The fast matching method is as shown in the appendix Figure 2 and the main steps are as follows:
[0033] (1) Configure N ACL rules with the same action, each of which references different source address matching resources, that is, [addr1, addr2,..., addrN];
[0034] (2) Merge N ACL rules into a single rule. The source address matching resource of the rule is "addr1|addr2|...|addrN"; that is, merge single rules with the same predetermined action to reduce the overall scale of the rules.
[0035] (3) Additionally, configure M ACL rules, which randomly reference different matching resources.
[0036] (4) Perform hierarchical partitioning on different matching items in all rules: In the same layer, regard the matching items as ranges and perform interval partitioning according to their upper and lower boundaries. Take the following two rules as examples:
[0037] Source Address Destination Address
[0038] R1:=(
[020]
[1020] )
[0039] R2:=(
[1030]
[2040] )
[0040] Both R1 and R2 reference two types of matching resources, source address and destination address. Their generated first layer and second layer are respectively as Figure 2 (R1) and Figure 3 (R2) shown;
[0041] (5) Perform interval partitioning on complex matching items of a single rule:
[0042] For rules that reference complex matching resources as described in (1) above, perform range interval partitioning on their matching resources; for R1 and R2 above, the final structure is as Figure 4 shown, Figure 5 showing an example of the range construction process for two layers;
[0043] Figure 5 In it, part (a) is the hierarchical structure diagram when only R1 exists. It can be seen that for data packets with the source address falling within the
[020] interval, they can point to the second layer for further destination address matching. If the destination address is within the interval
[1020] , then R1 is matched, and other intervals do not match; while for data with the source address falling outside the
[020] interval, it points to NIL in the second layer, that is, it will not match any policy and there is no need to perform destination address matching anymore;
[0044] (b) part is the hierarchical structure diagram after adding R2. The part related to R2 is highlighted, and the matching method is the same as described in part (a).
[0045] In this embodiment, within a single rule that references the above complex matching resources, the complex matching resources are hierarchically partitioned, and then a range interval is partitioned within each layer to improve the matching performance of the complex matching resources during single-rule matching.
[0046] (6) For the received data packet, according to the hierarchical partitioning in (4), sequentially obtain the specific values of its items to be matched.
[0047] (7) Perform binary matching on the values obtained in (6) within the range intervals of their corresponding layers in sequence, and layer by layer filter out the unmatched rules; thus, use the hierarchical structure to reduce the scale of the rules that ultimately need to be matched.
[0048] (8) The remaining rules are matched one by one with the items to be matched in the data packet. For complex matching resources, binary matching is also used within their range intervals (the construction process is similar to the above method, a single layer, and small intervals are marked with 0 / 1 to indicate whether they are included), and finally determine the specific rule corresponding to this data packet, so as to execute its predetermined action.
[0049] The single-layer range processing of complex matching resources, and marking whether small intervals are included with 0 / 1.
[0050] The above technical solutions are only exemplary embodiments of the present invention. For those skilled in the art, based on the application methods and principles disclosed in the present invention, it is very easy to make various types of improvements or deformations, not limited to the methods described in the above specific embodiments of the present invention. Therefore, the above-described manner is only preferred and does not have a restrictive meaning.
Claims
1. A rule fast matching method, characterized in that: The following steps are involved: S1: For multiple rules issued through configuration, the matching items of the same matching resources are regarded as a layer according to the category of matching resources. There are as many layers as there are matching items of different categories. Each matching item merged in the same layer is regarded as a range, and the matching items in the same layer are an unordered set of several ranges. S2, arrange the ranges in the same type of matching items in order according to their upper and lower boundaries to form multiple intervals. A single rule before merging is only associated with the intervals within the range containing its matching items; S3, for complex rules that reference more than one type of matching resources, merge the matching items of each type of matching resources with other single rules that only contain matching resources of the same type into the same level; S4, divide the message to be filtered into the hierarchy formed by steps S1-S3, take the specific values of each type of item to be matched in turn, match the obtained values in the range interval of the corresponding level in turn, and filter out unmatched rules layer by layer; thereby finally determining the specific rule corresponding to the message to execute the predetermined action of the rule.
2. The method according to claim 1, characterized in that The types of matching resources include: one or more of source address, destination address, security zone, protocol and / or port.
3. The method according to claim 1, characterized in that In step S4, in the step of matching the obtained value in the range interval of its corresponding level in turn, a binary search method is used to determine whether it belongs to a certain interval of a certain level.
4. The method according to any one of claims 1 to 3, characterized in that: Before step S1, the method further includes the following steps: S0, for multiple single rules that reference the same category of matches, if their execution actions are consistent, the matches of these rules are merged as a single rule to reduce the size of the overall rules.
5. The method according to claim 1, characterized in that The rule is an ACL rule.