Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

54 results about "Packet filtering" patented technology

Performance detection method and device for AI infrastructure and storage medium

The invention discloses an AI infrastructure performance detection method and device and a storage medium, and belongs to the technical field of data processing. The method comprises the steps that according to chip information of container nodes, dynamic instrumentation is conducted on a kernel layer and a calculation layer by expanding a Burkley packet filter, first performance indexes of the kernel layer and the calculation layer are collected, a hardware management library function is called, second performance indexes of a chip hardware layer are collected, and on the basis of a control group mechanism, the kernel layer and the calculation layer are subjected to dynamic instrumentation; and obtaining meta-information of the business process group in the container node, constructing an association relationship between the first performance index and the business process group and between the second performance index and the business process group through association marking according to the meta-information, and performing association analysis on the first performance index and the second performance index based on the association relationship to obtain a performance detection result of the business process group. According to the method, the performance parameters are collected through a non-intrusive scheme, the performance indexes of different service processes are determined through a service association mode, and the accuracy of AI performance problem positioning is improved.
Owner:CHINA MERCHANTS BANK

Token injection in packet headers to support high volume packet filtering

A class of network packets can be labeled by inserting a token into a packet header field. Preferably the header field is available to intermediary devices in cleartext. A packet filter examines the packets, allowing packets with the token to pass while dropping others. For example, the token can indicate that the packet is part of a “trusted” class. The token can be calculated from a secret, shared between the sender and receiver, and a rotating value. In some embodiments, the token may be placed in all packets associated with a trusted sender or for some time before trust must be re-established. Alternatively, the token can be placed in an initial one or more packets of a particular flow, and the packet filter can look for such packet(s), deciding whether to allow or block them. The packet filter then treats subsequent packets in the same flow in the same way.
Owner:AKAMAI TECHNOLOGIES INC

Edge computing and distributed zero-trust architecture system and data processing method

The invention discloses an edge computing and distributed zero-trust architecture system and a data processing method. The system comprises an edge computing device cluster, a distributed zero-trust control center, an edge security gateway and a block chain identity infrastructure. The edge computing node collects hardware state, vulnerability and behavior data through the terminal security agent module; the block chain identity infrastructure provides distributed identity identification and verifiable credential service; the edge security gateway executes data packet filtering and single packet authentication; and the distributed zero-trust control center calculates a real-time security coefficient and generates a differentiation strategy, and the log is synchronized to the alliance chain for evidence storage. According to the data processing method, security access is realized through access request initiation, single packet authentication, data acquisition, trust evaluation, strategy execution and log evidence storage. According to the method, the edge device state and distributed zero trust are deeply fused, the problems of incomplete identity authentication and static permission control in an edge scene are solved, and the security and traceability of an edge computing network are improved.
Owner:BEIJING ANCHEN INFORMATION TECHNOLOGY CO LTD

Network-packet filtering system and method

A network-packet filtering system is provided. The system includes one or more end hosts and a network-packet filtering device communicable with the end hosts and an external network. Each end host obtains its host-performance vector by executing a first neural network model based on its system-performance information. The network-packet filtering device determines whether to drop a packet from the external network or to pass the packet by executing a second neural network model based on the host-performance vectors and the packet.
Owner:NUVOTON

Semantic monitoring and causal delimiting method for affairs of electricity consumption information acquisition terminal

PendingCN121880064AAchieve non-intrusive depth observationIncrease the level of automationFault responseTimestampPower usage
The invention discloses an electricity consumption information acquisition terminal transaction semantic monitoring and causal delimiting method, which comprises the following steps: acquiring an application protocol data unit by utilizing an eBPF probe, generating a cross-layer unique transaction fingerprint based on extracted sessions, objects, businesses and calling identifiers, and generating a transaction event record by utilizing a pairing state machine; constructing a transaction observation window containing front and back extensions by taking a transaction observation timestamp as a reference, and screening and aggregating kernel events associated with the transaction fingerprint to obtain a transaction evidence set; and constructing a directed evidence graph based on the set, and calculating the confidence coefficient of each root cause category by using a scoring rule and an index normalization algorithm. According to the invention, non-intrusive deep observation of power acquisition business affairs is realized, and the automation level and fault diagnosis precision of power terminal operation and maintenance are improved.
Owner:NANJING XINLIAN ELECTRONICS CO LTD

Method for monitoring and enforcing secure policies in a device

A method for monitoring and enforcing secure policies in a device includes collecting kernel data from a kernel space by a packet filtering module operating in a user space. The kernel data is processed into events that are transmitted to a data bus, where the events are stored and provided to a policy enforcement module. The policy enforcement module evaluates the events with an algorithm to detect potential threat events. When a threat event is identified, one or more secure policies are selected and executed in the device as corresponding actions or commands. The method enables real-time monitoring of kernel activity and enforcement of security policies while maintaining the architecture in user space.
Owner:EXEIN SPA

Systems and methods for cyber threat detection based on new and / or updated cyber threat intelligence

Systems, methods, and apparatuses are described for detection and / or analysis of cyber threats based on updated cyber threat intelligence associated with cyber threats. Packet filtering output data such as logs of packet communications and / or copies of packets may be generated based on first cyber threat intelligence associated with a cyber threat. Updated criteria based on subsequent updated cyber threat intelligence may then be applied to the packet filtering output data.
Owner:CENTRIPETAL NETWORKS INC

Data packet filtering method and device, storage medium and electronic equipment

The invention relates to a data packet filtering method and device, a storage medium and electronic equipment. The method comprises the following steps: acquiring mobile data of equipment and signal data of the equipment; determining a data filtering rule of the equipment according to the mobile data and the signal data; and filtering the transmission data packet of the equipment according to the data filtering rule. The technical problem that the data packet is not safely filtered is solved.
Owner:FIBOCOM AUTO INC

Methods and Systems for Efficient Encrypted SNI Filtering for Cybersecurity Applications

A packet-filtering system described herein may be configured to filter packets with encrypted hostnames in accordance with one or packet-filtering rules. The packet-filtering system may resolve a plaintext hostname from ciphertext comprising an encrypted Server Name Indication (eSNI) value. The packet-filtering system may resolve the plaintext hostname using a plurality of techniques. Once the plaintext hostname is resolved, the packet-filtering system may then use the plaintext hostname to determine whether the packets are associated with one or more threat indicators. If the packet-filtering system determines that the packets are associated with one or more threat indicators, the packet-filtering system may apply a packet filtering operation associated with the packet-filtering rules to the packets.
Owner:CENTRIPETAL NETWORKS INC

Network control method, device, equipment, medium and program product

The embodiment of the invention provides a network control method and device, equipment, a medium and a program product, and relates to the technical field of terminal intelligent control. The method comprises the steps of obtaining a unique identifier of a target application program; constructing a network access control list containing the target application program; and configuring a network filtering rule for the target application program based on the network access control list and the unique identifier. Based on the method, the accuracy of network filtering rule configuration can be improved through the uniqueness of the unique identifier of the target application program, and misjudgment caused by factors such as address or port overlapping is avoided. And the network filtering rule is configured for the target application program based on the network access control list and the unique identifier, so that data packet filtering can be forcibly processed, and the forcibility and uniformity of the rule are ensured. Therefore, through the method, the accuracy, uniformity and mandatory of network control can be improved.
Owner:SHENZHEN TAILIWEI INTELLIGENT TECHNOLOGY CO LTD

Duplicate message filtering system for industrial wireless networks

This invention relates to the technical field of industrial wireless communication. Specifically, it provides a duplicate packet filtering system for industrial wireless networks. The system includes: a packet feature extraction module, a hash value calculation module, a dynamic filter module, and a filtering decision and execution module. The packet feature extraction module extracts features from the current wireless packet. The hash value calculation module calculates the corresponding hash value based on the source MAC address of a first terminal. The dynamic filter module queries the hash RAM table based on the hash value to obtain the SA RAM index. The dynamic filter module retrieves the current entry corresponding to the SA RAM based on the SA RAM index. The dynamic filter module determines whether the current wireless packet is a duplicate packet based on the current entry corresponding to the SA RAM. The filtering decision and execution module filters out the current wireless packet when it is a duplicate packet. This invention reduces network resource waste, significantly reduces terminal processing load, and ensures real-time and reliable communication.
Owner:SHENYANG BONCHREE TECHNOLOGY CO LTD +1

User login auditing method, device and equipment, medium and product

The invention discloses a user login auditing method, device and equipment, a medium and a product. The method comprises the following steps: mounting an extension packet filter program to a target trigger point related to user login; under the condition that the target trigger point is triggered, acquiring a system call event of the target trigger point through the extension packet filter program, and transmitting to-be-audited event data associated with the system call event to a login audit daemon process of a user space; and performing user login auditing based on the to-be-audited event data through the login auditing daemon process, and generating a user login auditing result. According to the scheme, the system call event is acquired through the extension packet filter program mounting to perform user login auditing, so that the event call can be monitored in real time, and the real-time performance is high; the auditing process does not depend on log files, and the log tampering risk is avoided; kernel source codes, system configuration and the like do not need to be modified, the original authentication process and system stability are not influenced, the invasiveness is low, and the compatibility is high.
Owner:SHANGHAI JIACHE INFORMATION TECH CO LTD

Methods and systems for efficient adaptive logging of cyber threat incidents

ActiveUS12603862B2Securing communicationData packCyber threat intelligence
A packet-filtering network appliance such as a threat intelligence gateway (TIG) protects TCP / IP networks from Internet threats by enforcing certain policies on in-transit packets that are crossing network boundaries. The policies are composed of packet filtering rules derived from cyber threat intelligence (CTI). Logs of rule-matching packets and their associated flows are sent to cyberanalysis applications located at security operations centers (SOCs) and operated by cyberanalysts. Some cyber threats / attacks, or incidents, are composed of many different flows occurring at a very high rate, which generates a flood of logs that may overwhelm computer, storage, network, and cyberanalysis resources, thereby compromising cyber defenses. The present disclosure describes incident logging, in which a single incident log efficiently incorporates the logs of the many flows that comprise the incident, thereby potentially reducing resource consumption while improving the informational / cyberanalytical value of the incident log for cyberanalysis when compared to the component flow logs. Incident logging vs. flow logging can be automatically and adaptively switched on or off depending on the combination of resource consumption and informational / cyberanalytical value.
Owner:CENTRIPETAL NETWORKS INC

System and method for granting intermediary access to a data flow between non-kernel applications

Methods and apparatus for emerging use case support in user space networking architectures. In one embodiment, an apparatus configured to segregate packet data based on a packet type is disclosed. The exemplary embodiment provides a custom data type registry that enables the definition, addition, removal, modification, and / or prioritization of custom packet processing rules. Variants of the registry may support custom ethertype packets, network packets, and / or transport packets. In another embodiment, mechanisms for enabling an intermediary packet processing stage are described. Intermediary packet processing may enable user space system extensions that support e.g., packet filtering, packet modification, and / or other forms of packet processing.
Owner:APPLE INC

A data packet filtering method and device, a communication device, a chip and a storage medium

The present disclosure provides a data packet filtering method and device, a communication device, a chip and a storage medium. A modification instruction is received from a control console, the modification instruction being used to modify a first filter in first filtering information, the first filtering information including at least one first filter. A target filter list is determined according to the modification instruction, the target filter list including a first operation code, the first operation code being used to instruct a network device to replace the at least one first filter with a filter in the target filter list. Target filtering information is determined, the target filtering information being used to filter uplink data packets. The uplink data packets of a terminal can be filtered, the network device can be instructed through the first operation code, the complexity of terminal code can be reduced, and the processing efficiency, stability and reliability of the terminal can be improved.
Owner:BEIJING X RING TECHNOLOGY CO LTD

Methods and systems for the efficient enforcement of cybersecurity policies in network communication

Methods, devices, systems, and machine-readable media are disclosed that serve to improve the efficiency of packet filtering by reducing processing time and / or memory requirements. Any type of data structure, such as flat hash tables and / or rule trees, can be used by a packet filtering device to search for packet filtering rules for cybersecurity policies that should be applied to transmitted packets. The packet filtering device can search the index data structures for matches of search objects in the form of values ​​that the packet filtering device extracts from the transmitted packets to match them against the compliance criteria of the policy rules for threat indicators. Each of the index data structures can map rule identifiers (rule IDs) of policy rules to keys that are based on (or include) the compliance criteria of those rules.
Owner:CENTRIPETAL NETWORKS INC

Efficient rule matching method for high-complexity conditional expression rule body

The invention discloses an efficient rule matching method for a high-complexity condition expression rule body, and belongs to the technical field of network flow data packet filtering. And defining priorities among the operators and defining processing callback functions of the operators and the operands. Then, the rule body condition expression is scanned, analyzed and compiled, so that the rule body condition expression is converted into a similar executable binary program which can be executed by a plurality of users, and a result is calculated. Rule body matching: executing the binary programs which can be executed by the rule body type according to the compiled assembly instruction sequence; each calculation result of the expression is stored at the top of the stack, and a final result is stored at the bottom of the stack. According to the method, a lexical analysis method in a compiling principle is taken as a guiding policy, pre-compiling of an expression calculation process is completed, and expression matching calculation is accelerated; and meanwhile, the locality of the matching calculation process is enhanced, and the CPU processing capacity is fully utilized.
Owner:BEIJING SCISTOR TECH

Application protocol identification control method based on AI learning and FPGA rapid matching

The invention discloses an application protocol identification control method based on AI learning and FPGA rapid matching, and the method comprises the steps: firstly carrying out the preliminary shunting of a data package entering a gatekeeper according to a destination port, and distinguishing the data streams of different application protocols; secondly, application layer data recombination is carried out, data packets of the same data stream are recombined and converged, and application layer data content is recovered; the recombined data are sent to an FPGA module, and identification and compliance judgment are carried out on an application protocol in a regular expression matching mode; if the protocol identification is passed and a white list strategy is met, the data stream enters a subsequent state detection and packet filtering module; if the identification is not passed, directly discarding all messages of the data stream; fine-grained access control is carried out through a state detection and packet filtering module, and finally legal data packets are forwarded out. And the protocol feature library performs application protocol feature information extraction and construction based on an AI learning algorithm. According to the invention, efficient application protocol white list control can be realized, and a solution with high-speed processing capability is provided.
Owner:WUYUAN NETWORK TECHNOLOGY (WUXI) CO LTD

Message filtering device, message filtering method, protocol controller and computing equipment

The invention discloses a message filtering device, a message filtering method, a protocol controller and computing equipment, and belongs to the technical field of chips. The message filtering device is integrated in a protocol controller and comprises a filtering unit, a triggering unit and a storage unit, the filtering unit is used for filtering a protocol layer message based on a filtering condition in response to the starting signal, and the protocol layer message is a message processed by the protocol controller in a protocol layer format; the triggering unit is used for receiving the protocol layer message filtered by the filtering unit, responding to a detected target protocol layer message meeting a triggering condition, and controlling the filtering unit to stop filtering the protocol layer message according to a time point when the target protocol layer message is detected; and the storage unit is used for storing the protocol layer message filtered by the filtering unit. According to the message filtering device, the central processing unit at least can capture the target protocol layer message and the text of the target protocol layer message from the storage unit, so that the target protocol layer message is comprehensively and accurately analyzed.
Owner:HYGON INFORMATION TECH CO LTD

Artificial intelligence-driven cybersecurity system and cybersecurity method with dynamic reverse authentication

An AI-driven network security system that proactively detects and mitigates threats in enterprise environments is provided. The system integrates AI-based behavioral analysis to model normal activity and identify anomalies. It implements a Reverse Authentication Algorithm (RAA) to generate a unique 32-hex-character (128-bit) authentication (“au”) string formed from random hexadecimal values, a complement-masked timestamp, and a search string dynamically derived from an ASCII random string table. Incoming requests are validated by reconstructing and verifying the timestamp and by recomputing the search string extracted from the au string. Upon anomaly detection or authentication failure, the system triggers layered defenses including packet filtering, IP blocking via a blocklist, execution of custom threat-neutralization scripts, and integration with content delivery networks (CDNs) to mitigate volumetric attacks. The modular architecture enables real-time detection and response while integrating with existing infrastructure.
Owner:LIN CHAO HUNG +1

Communication method and apparatus

PCT designated stageWO2026091876A1Wireless communicationData packRadio access network
The present application provides a communication method and apparatus, which allow a radio access network (RAN) to have a data packet filtering function, so as to improve the transmission performance of data packets. The method comprises: a centralized unit receives first information from a terminal device, wherein the first information indicates a service type of a RAN local service requested by the terminal device, and the service type comprises at least one of sensing, positioning, artificial intelligence prediction, or artificial intelligence computation; the centralized unit sends second information to a session management function, wherein the second information instructs an access network device to provide, for the terminal device, the RAN local service of the service type; and the centralized unit receives third information and / or fourth information from the session management function, wherein the third information indicates a data packet detection rule, the data packet detection rule is obtained by the session management function on the basis of the second information, and the fourth information indicates transport network layer information of a service unit used for establishing a data plane tunnel with the service unit.
Owner:HUAWEI TECH CO LTD

Methods and Systems for Efficient Enforcement of Cybersecurity Policies in Network Communications

This document discloses methods, apparatus, systems, and computer-readable media for improving packet filtering efficiency by reducing processing time and / or memory usage. The packet filtering appliance uses one of various types of data structures, such as flat hash maps and / or rule trees, to look up packet filtering rules of a cybersecurity policy that should be applied to packets in transit. The packet filtering appliance searches an index data structure for matches of the search object against the matching criteria of the policy rule's threat indicators, in the form of values ​​that the packet filtering appliance extracts from packets in transit. Each of the index data structures maps the rule identifiers (rule IDs) of the policy rules to keys based on (or containing) the matching criteria of those rules.
Owner:CENTRIPETAL NETWORKS INC

Ten million-level rule matching method and system based on classification preprocessing

The invention provides a ten-million-level rule matching method and system based on classification preprocessing. Belongs to the field of data stream processing packet filtering. The method comprises the following steps: firstly, preprocessing a rule set, and carrying out classified statistics according to protocol information carried by a rule; the method comprises the following steps of: introducing a concept of identification degree, determining a main protocol category of each rule according to a protocol level priority (an application layer gt, a transmission layer gt and a network layer) and the number of association rules, and constructing rule subsets of multiple protocol dimensions according to the main protocol category; when real-time flow matching is carried out, a message protocol is analyzed and labeled, a rule subset corresponding to a protocol category is dynamically selected and only matched according to a message label, and finally a universal rule set only containing a quintuple is matched. According to the method, static rule statistics and dynamic message features are combined, a heuristic decision-making mechanism is established, and the number of rules needing to be traversed in single matching is effectively reduced, so that efficient multi-rule hit matching is realized under the ten-million-level rule capacity, and the overall performance is optimized.
Owner:CHINA ACADEMY OF INFORMATION & COMM

Message filtering method and device, equipment, storage medium and program product

The invention discloses a message filtering method and device, equipment, a storage medium and a product, a protocol to which a message belongs is identified, and a handshake stage of the message is analyzed only when the message belongs to a user datagram protocol UDP-based fast UDP Internet connection QUIC protocol, so that accurate identification and processing of HTTP / 3 traffic are realized, and the message filtering efficiency is improved. And the problem that HTTP / 3 traffic is difficult to intercept due to message structure difference is solved. Moreover, according to the message filtering method, the encrypted protocol control information is decrypted, and the encryption barrier of the QUIC protocol can be broken through, so that the feature information for identifying the communication target can be extracted from the decrypted protocol control information, the feature which is originally encrypted and hidden is converted into an effective interception voucher, and the security of the communication target is improved. The problem that the features cannot be extracted due to encryption is solved. And finally, the message is filtered based on the extracted feature information, such a filtering strategy based on an accurate identifier realizes accurate identification of the traffic selected to be intercepted by the user, and the error interception rate can be reduced.
Owner:SHANGHAI LIANHONG TECH CO LTD

Ebpf and xdp based ipv6 fragmentation bypass threat detection method and system

The application relates to the technical field of network security, in particular to an IPv6 fragmentation bypass threat detection method and system based on eBPF and XDP, which sets a data packet observation point at a network driver layer, the data packet observation point is used for mounting an extended Berkeley packet filter (eBPF) program on a data packet processing path by using a fast data path (XDP) technology; for a data packet received on the network driver layer, the data packet observation point calls the eBPF program on an XDP network hook, the eBPF program is used for identifying and filtering a data packet with potential threats by using a feature matching strategy, the feature matching strategy is used for extracting key features of the data packet, matching the extracted key features of the data packet with target threat features, and judging whether an upper layer header of the data packet is complete; the application realizes efficient detection of specific threats by combining the dynamic programmability of the eBPF and the high-performance data packet processing capability of the XDP, meets the task requirements of an IPv6 network security threat high-performance solution, and has a smaller influence on system stability even under serious threats.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

Intelligent agent communication cross-domain service quality assurance method, equipment and medium

The invention discloses an agent communication cross-domain service quality guarantee method, equipment and a medium, belongs to the technical field of intelligent communication, and aims to solve the technical problem that the existing agent communication protocol uses HTTP / HTTPS in an application layer, and the existing packet filtering and mapping mechanism based on IP quintuple cannot be distinguished. In order to guarantee the service quality of an end-side agent and a virtual agent in a mobile communication network and provide differentiated QoS for different AI services in a 5G-A / 6G network, the adopted technical scheme is as follows: the network issues a cross-domain QoS mapping rule to the end-side agent in an agent session establishment process and issues an N4 mapping rule to a UPF; an inter-domain mapping relation between the 5QI and the DSCP, namely a 5G domain and an IP domain, is embodied; when the QoS flow is mapped in the uplink and downlink directions, if it is detected that an application layer uses an HTTP / HTTPS protocol and indicates an AI service, the DSCP is mapped to 5QI according to a cross-domain QoS mapping rule / N4 mapping rule, and QFI information corresponding to the 5QI is carried in an uplink SDAP packet header and a downlink GTP-U packet header for flow identification.
Owner:INSPUR COMM TECH CO LTD

Method for obtaining operation information of application program and related equipment

PendingCN121646764AHardware monitoringComputer hardwareCode injection
The embodiment of the invention provides a method for obtaining operation information and related equipment. The invention provides an efficient scheme for obtaining the operation information of the application program. The method includes: when a stream conversion method in a performance analysis application is triggered, an extended Berkeley packet filter (eBPF) virtual machine (VM) running in a kernel space obtains thread data, the first thread data comprises N table entries, each table entry in the N table entries corresponds to one method in the performance analysis application, and the first thread data comprises a first thread data and a second thread data, each table entry in the N table entries corresponds to one method in the performance analysis application, and each table entry in the N table entries corresponds to one method in the performance analysis application. The N table items comprise a first table item, and the first table item corresponds to the triggered stream conversion method; the eBPF VM determines a target method according to the thread data, and the target method is called by the triggered stream conversion method; the eBPF VM performs performance analysis on the performance analysis application program to obtain a stack tracking result, the stack tracking result comprises a plurality of table entries, the table entries are in one-to-one correspondence with a plurality of methods, the table entries comprise a second table entry, and the second table entry corresponds to the target method; a collector running in a user space obtains the thread data and the stack tracking result from the eBPF VM; and the collector determines operation information of the performance analysis application program according to the thread data and the stack tracking result. According to the technical scheme, the eBPF VM can perform performance analysis on the performance analysis application program in the kernel space. In addition to the performance analysis application, the eBPF VM may obtain thread data and stack tracking results for other applications. No code is injected into the performance analysis application and / or the user space of the performance analysis application so that no damage is caused by code injection.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

A method and apparatus for processing a packet

The embodiment of the application provides a message processing method and device, which are applied to the technical field of network and include the following steps: calling a first extended Berkeley packet filter to analyze a first data message; when it is found that a first data message is provided with a custom optional field, if the custom optional field carries a target message modification value, mapping relationship between identification information of the first data message and the target message modification value is added in a mapping table; calling the first extended Berkeley packet filter to analyze a second data message; when it is found that the second data message is provided with the custom optional field, if the custom optional field only carries a specified code, it is determined that the target message modification value mapped by identification information of the second data message; and the value of a target field in the second data message is modified by using the target message modification value, so that the Berkeley packet filter is used to modify an undefined field in a standard protocol, and the customized requirement of message processing is met.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Method and system for efficiently and mandatorily executing network security policy in network communication

Methods, devices, systems, and machine-readable media are disclosed for improving packet filtering efficiency by reducing processing time and / or reducing memory usage. A packet filtering device may use any of various types of data structures, such as a flat hash map and / or rule tree, to search for network security policy packet filtering rules that should be applied to packets in transmission. The packet filtering device may search for an index data structure to find a match of a search object (in the form of a value extracted by the packet filtering device from a transmitted packet) to a threat indicator matching criterion of the policy rule. Each of the index data structures may map rule identifiers (rule IDs) for policy rules to keys that are based on (or include) matching criteria for the rules.
Owner:CENTRIPETAL NETWORKS INC

Communication method and device

The invention provides a communication method and device, which can realize that an RAN (Radio Access Network) has a data packet filtering function, so that the transmission performance of a data packet can be improved. The method comprises: a centralized unit receiving first information from a terminal device, the first information indicating a service type of a wireless access network local service requested by the terminal device, the service type comprising at least one of perception, positioning, artificial intelligence prediction, or artificial intelligence calculation; the centralized unit sends second information to the session management function, wherein the second information indicates the access network equipment to provide the wireless access network local service of the service type for the terminal equipment; and the centralized unit receives third information and / or fourth information from the session management function, the third information indicates a data packet detection rule, the data packet detection rule is acquired by the session management function according to the second information, and the fourth information indicates transmission network layer information of the service unit for establishing a data plane tunnel with the service unit.
Owner:HUAWEI TECH CO LTD