Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

101 results about "Packet filtering" patented technology

Neuro-Generative Adversarial System for real-time detection and combating of malware morphing in high-density edge networks

ActiveDE202025106911U1Platform integrity maintainanceData packEmbedded security
A system for real-time detection and mitigation of morphing malware in high-density edge networks, consisting of: a data acquisition unit configured to receive, normalize, and encode multimodal telemetry data streams originating from at least one of the following domains: network traffic, process behavior, system call sequences, binary instruction traces, and control flow graphs; the data acquisition unit is further configured to compute feature embeddings over sliding time windows and apply privacy-preserving redactions prior to storage; a generative neural processor that is operationally coupled to the data acquisition unit and configured to generate synthetic morphing malware variants by learning probabilistic transformations of previously observed malicious data representations, maintaining semantic functionality while varying structural and behavioral features; a discriminative neural processor trained adversarially with the generative neural processor, wherein the discriminative neural processor is configured to detect morphing malware by evaluating a probability distribution over multimodal telemetry embeddings and classifying anomalous process and flow behaviors in real time; a coordination processor that is communicatively connected to both the generative neural processor and the discriminative neural processor and is configured to orchestrate adversarial co-training, regulate detection thresholds, calculate reinforcement-based penalties for false negative results, and trigger countermeasures as soon as a detection confidence level exceeds a predefined adaptive threshold; a secure, system-integrated inference and enforcement unit configured to perform low-latency countermeasures at the network edge, including selective packet filtering, flow isolation, process interruption, or system microsegmentation, based on instructions from the coordinating processor; and a hardware-embedded security enclave that is embedded in the system and configured to store cryptographic keys, neural model parameters, and integrity affirmation data to ensure the confidentiality, authenticity, and immutability of model artifacts and policy configurations.
Owner:ANAJAVADIDHODDI RAMACHANDRA NAIK CHAYAPATHI BENGALURU +7

Server-free dynamic management and control method based on extended Berkley packet filter

The invention provides a server-free dynamic management and control method based on an extended Burkley packet filter, and the method comprises the steps: mounting an eBPF program to a kernel cgroup subsystem, monitoring a function instance creation / destruction event in real time, extracting metadata, dynamically generating a fine-grained network strategy, compiling the fine-grained network strategy into an eBPF byte code, and injecting the eBPF byte code into a Map format strategy table, realizing data packet level allowing / discarding control by using a flow control hook; and when the instance is destroyed, the strategy table rule is automatically cleared through a cgroprease event. Through kernel-level dynamic management and control, precise security protection, zero-trust micro-isolation and kernel layer malicious behavior interception of the function instance in the full life cycle are realized, and the security efficiency and the resource utilization rate of the cloud native environment are remarkably improved.
Owner:BEIJING PACTERA JINXIN TECH LTD

Performance detection method and device for AI infrastructure and storage medium

The invention discloses an AI infrastructure performance detection method and device and a storage medium, and belongs to the technical field of data processing. The method comprises the steps that according to chip information of container nodes, dynamic instrumentation is conducted on a kernel layer and a calculation layer by expanding a Burkley packet filter, first performance indexes of the kernel layer and the calculation layer are collected, a hardware management library function is called, second performance indexes of a chip hardware layer are collected, and on the basis of a control group mechanism, the kernel layer and the calculation layer are subjected to dynamic instrumentation; and obtaining meta-information of the business process group in the container node, constructing an association relationship between the first performance index and the business process group and between the second performance index and the business process group through association marking according to the meta-information, and performing association analysis on the first performance index and the second performance index based on the association relationship to obtain a performance detection result of the business process group. According to the method, the performance parameters are collected through a non-intrusive scheme, the performance indexes of different service processes are determined through a service association mode, and the accuracy of AI performance problem positioning is improved.
Owner:CHINA MERCHANTS BANK

Packet filtering strategy management method and data packet filtering method and device

The invention provides a management method of a packet filtering strategy and a data packet filtering method and device, and the management method comprises the steps: enabling the packet filtering strategy to be matched with a strategy template, and storing the matched packet filtering strategy to the strategy template of a corresponding type; each category of strategy template is configured with value ranges of parameters of at least two dimensions, and the combination modes of the dimensions of the parameters of different strategy templates are different; screening out candidate packet filtering strategies from the packet filtering strategies which are not matched with the strategy template, wherein the candidate packet filtering strategies are packet filtering strategies which coincide with the value range of the parameters of the strategy template; splitting a value range of a parameter coinciding with the strategy template from the candidate packet filtering strategy, generating a new packet filtering strategy, and storing the new packet filtering strategy in the corresponding strategy template; and taking the value range of the residual parameter which is not overlapped with the strategy template in the candidate packet filtering strategy as another new packet filtering strategy, and storing the new packet filtering strategy and other packet filtering strategies which are not matched with the strategy template in the strategy tree together.
Owner:HANGZHOU DPTECH TECH

Token injection in packet headers to support high volume packet filtering

A class of network packets can be labeled by inserting a token into a packet header field. Preferably the header field is available to intermediary devices in cleartext. A packet filter examines the packets, allowing packets with the token to pass while dropping others. For example, the token can indicate that the packet is part of a “trusted” class. The token can be calculated from a secret, shared between the sender and receiver, and a rotating value. In some embodiments, the token may be placed in all packets associated with a trusted sender or for some time before trust must be re-established. Alternatively, the token can be placed in an initial one or more packets of a particular flow, and the packet filter can look for such packet(s), deciding whether to allow or block them. The packet filter then treats subsequent packets in the same flow in the same way.
Owner:AKAMAI TECHNOLOGIES INC

Edge computing and distributed zero-trust architecture system and data processing method

The invention discloses an edge computing and distributed zero-trust architecture system and a data processing method. The system comprises an edge computing device cluster, a distributed zero-trust control center, an edge security gateway and a block chain identity infrastructure. The edge computing node collects hardware state, vulnerability and behavior data through the terminal security agent module; the block chain identity infrastructure provides distributed identity identification and verifiable credential service; the edge security gateway executes data packet filtering and single packet authentication; and the distributed zero-trust control center calculates a real-time security coefficient and generates a differentiation strategy, and the log is synchronized to the alliance chain for evidence storage. According to the data processing method, security access is realized through access request initiation, single packet authentication, data acquisition, trust evaluation, strategy execution and log evidence storage. According to the method, the edge device state and distributed zero trust are deeply fused, the problems of incomplete identity authentication and static permission control in an edge scene are solved, and the security and traceability of an edge computing network are improved.
Owner:BEIJING ANCHEN INFORMATION TECHNOLOGY CO LTD

GOTO action in network traffic policies

A traffic policy includes policy rules that specify branch actions in their action fields. A branch action specifies another policy rule in the traffic policy. Packet filters generated from the traffic policy represent the traffic policy rules and execution order semantics of the branch rules.
Owner:ARISTA NETWORKS INC

Network-packet filtering system and method

A network-packet filtering system is provided. The system includes one or more end hosts and a network-packet filtering device communicable with the end hosts and an external network. Each end host obtains its host-performance vector by executing a first neural network model based on its system-performance information. The network-packet filtering device determines whether to drop a packet from the external network or to pass the packet by executing a second neural network model based on the host-performance vectors and the packet.
Owner:NUVOTON

Semantic monitoring and causal delimiting method for affairs of electricity consumption information acquisition terminal

PendingCN121880064AAchieve non-intrusive depth observationIncrease the level of automationFault responseTimestampPower usage
The invention discloses an electricity consumption information acquisition terminal transaction semantic monitoring and causal delimiting method, which comprises the following steps: acquiring an application protocol data unit by utilizing an eBPF probe, generating a cross-layer unique transaction fingerprint based on extracted sessions, objects, businesses and calling identifiers, and generating a transaction event record by utilizing a pairing state machine; constructing a transaction observation window containing front and back extensions by taking a transaction observation timestamp as a reference, and screening and aggregating kernel events associated with the transaction fingerprint to obtain a transaction evidence set; and constructing a directed evidence graph based on the set, and calculating the confidence coefficient of each root cause category by using a scoring rule and an index normalization algorithm. According to the invention, non-intrusive deep observation of power acquisition business affairs is realized, and the automation level and fault diagnosis precision of power terminal operation and maintenance are improved.
Owner:NANJING XINLIAN ELECTRONICS CO LTD

Hash and tcam based combined packet classifier and method

The application discloses a kind of combination packet classifier and method based on hash and TCAM, adopt the combination of imperfect hash classification module and TCAM classification module, the complement of imperfect hash classification and TCAM classification on input key value space is realized;Compared with the traditional TCAM packet classification solution based on, the application reduces hardware resource utilization, system power consumption;Compared with the packet classification solution based on perfect hash, the application reduces the design cost of hash function and the time complexity of generation process under the premise of guaranteeing the function of classifier.The application can consider low space resource consumption, low power consumption and low delay in the classification stage, saves design cost in the classifier generation stage, and reduces the time complexity of generation process;Meanwhile, the application can better balance different types of hardware resources on reconfigurable hardware platforms such as FPGA, and provides a new way of thinking for the design of classifier in network tasks such as firewall packet filtering and routing table lookup.
Owner:XIAN MICROELECTRONICS TECH INST

Method for monitoring and enforcing secure policies in a device

A method for monitoring and enforcing secure policies in a device includes collecting kernel data from a kernel space by a packet filtering module operating in a user space. The kernel data is processed into events that are transmitted to a data bus, where the events are stored and provided to a policy enforcement module. The policy enforcement module evaluates the events with an algorithm to detect potential threat events. When a threat event is identified, one or more secure policies are selected and executed in the device as corresponding actions or commands. The method enables real-time monitoring of kernel activity and enforcement of security policies while maintaining the architecture in user space.
Owner:EXEIN SPA

Systems and methods for cyber threat detection based on new and / or updated cyber threat intelligence

Systems, methods, and apparatuses are described for detection and / or analysis of cyber threats based on updated cyber threat intelligence associated with cyber threats. Packet filtering output data such as logs of packet communications and / or copies of packets may be generated based on first cyber threat intelligence associated with a cyber threat. Updated criteria based on subsequent updated cyber threat intelligence may then be applied to the packet filtering output data.
Owner:CENTRIPETAL NETWORKS INC

Efficient Threat Context-Aware Packet Filtering for Network Protection

PendingUS20250358295A1Securing communicationCyber threat intelligenceAttack
A threat intelligence gateway (TIG) may protect TCP / IP networks from network (e.g., Internet) threats by enforcing certain policies on in-transit packets that are crossing network boundaries. The policies may be composed of packet filtering rules with packet-matching criteria derived from cyber threat intelligence (CTI) associated with Internet threats. These CTI-derived packet-filtering rules may be created offline by policy creation and management servers, which may distribute the policies to subscribing TIGs that subsequently enforce the policies on in-transit packets. Each packet filtering rule may specify a disposition that may be applied to a matching in-transit packet, such as deny / block / drop the in-transit packet or pass / allow / forward the in-transit packet, and also may specify directives that may be applied to a matching in-transit packet, such as log, capture, spoof-tcp-rst, etc. Often, however, the selection of a rule's disposition and directives that best protect the associated network may not be optimally determined before a matching in-transit packet is observed by the associated TIG. In such cases, threat context information that may only be available (e.g., computable) at in-transit packet observation and / or filtering time, such as current time-of-day, current TIG / network location, current TIG / network administrator, the in-transit packet being determined to be part of an active attack on the network, etc., may be helpful to determine the disposition and directives that may best protect the network from the threat associated with the in-transit packet. The present disclosure describes examples of methods, systems, and apparatuses that may be used for efficiently determining (e.g., accessing and / or computing), in response to the in-transit packet, threat context information associated with an in-transit packet. The threat context information may be used to efficiently determine the disposition and / or one or more directives to apply to the in-transit packet. This may result in dispositions and / or directives being applied to in-transit packets that better protect the network as compared with solely using dispositions and directives that were predetermined prior to receiving the in-transit packet.
Owner:CENTRIPETAL NETWORKS INC

Data packet filtering method and device, storage medium and electronic equipment

The invention relates to a data packet filtering method and device, a storage medium and electronic equipment. The method comprises the following steps: acquiring mobile data of equipment and signal data of the equipment; determining a data filtering rule of the equipment according to the mobile data and the signal data; and filtering the transmission data packet of the equipment according to the data filtering rule. The technical problem that the data packet is not safely filtered is solved.
Owner:FIBOCOM AUTO INC

Methods and Systems for Efficient Encrypted SNI Filtering for Cybersecurity Applications

A packet-filtering system described herein may be configured to filter packets with encrypted hostnames in accordance with one or packet-filtering rules. The packet-filtering system may resolve a plaintext hostname from ciphertext comprising an encrypted Server Name Indication (eSNI) value. The packet-filtering system may resolve the plaintext hostname using a plurality of techniques. Once the plaintext hostname is resolved, the packet-filtering system may then use the plaintext hostname to determine whether the packets are associated with one or more threat indicators. If the packet-filtering system determines that the packets are associated with one or more threat indicators, the packet-filtering system may apply a packet filtering operation associated with the packet-filtering rules to the packets.
Owner:CENTRIPETAL NETWORKS INC

Network control method, device, equipment, medium and program product

The embodiment of the invention provides a network control method and device, equipment, a medium and a program product, and relates to the technical field of terminal intelligent control. The method comprises the steps of obtaining a unique identifier of a target application program; constructing a network access control list containing the target application program; and configuring a network filtering rule for the target application program based on the network access control list and the unique identifier. Based on the method, the accuracy of network filtering rule configuration can be improved through the uniqueness of the unique identifier of the target application program, and misjudgment caused by factors such as address or port overlapping is avoided. And the network filtering rule is configured for the target application program based on the network access control list and the unique identifier, so that data packet filtering can be forcibly processed, and the forcibility and uniformity of the rule are ensured. Therefore, through the method, the accuracy, uniformity and mandatory of network control can be improved.
Owner:SHENZHEN TAILIWEI INTELLIGENT TECHNOLOGY CO LTD

Data packet filtering method and device, equipment, storage medium and vehicle

The invention relates to a data packet filtering method and device, equipment, a storage medium and a vehicle, the method is suitable for a network interface layer in a processor, and the method comprises the following steps: extracting first attribute information from a to-be-processed data packet; calculating target verification information corresponding to the to-be-processed data packet based on the first attribute information; target verification information is searched in all pieces of verification information obtained in advance, and all the pieces of verification information are obtained through calculation according to attribute information, collected in advance, of the expected data packet; when the target verification information is found, forwarding the to-be-processed data packet to a network protocol stack; and when the target verification information is not found, discarding the to-be-processed data packet. By calculating the target verification information corresponding to the to-be-processed data packet, whether the to-be-processed data packet is the expected data packet or not can be verified before the to-be-processed data packet is uploaded to the network protocol stack, so that inflow of an unexpected data packet is blocked, the calculation overhead of a processor is reduced, and the bandwidth utilization rate is improved.
Owner:BEIJING CO WHEELS TECH CO LTD

Duplicate message filtering system for industrial wireless networks

This invention relates to the technical field of industrial wireless communication. Specifically, it provides a duplicate packet filtering system for industrial wireless networks. The system includes: a packet feature extraction module, a hash value calculation module, a dynamic filter module, and a filtering decision and execution module. The packet feature extraction module extracts features from the current wireless packet. The hash value calculation module calculates the corresponding hash value based on the source MAC address of a first terminal. The dynamic filter module queries the hash RAM table based on the hash value to obtain the SA RAM index. The dynamic filter module retrieves the current entry corresponding to the SA RAM based on the SA RAM index. The dynamic filter module determines whether the current wireless packet is a duplicate packet based on the current entry corresponding to the SA RAM. The filtering decision and execution module filters out the current wireless packet when it is a duplicate packet. This invention reduces network resource waste, significantly reduces terminal processing load, and ensures real-time and reliable communication.
Owner:SHENYANG BONCHREE TECHNOLOGY CO LTD +1

User login auditing method, device and equipment, medium and product

The invention discloses a user login auditing method, device and equipment, a medium and a product. The method comprises the following steps: mounting an extension packet filter program to a target trigger point related to user login; under the condition that the target trigger point is triggered, acquiring a system call event of the target trigger point through the extension packet filter program, and transmitting to-be-audited event data associated with the system call event to a login audit daemon process of a user space; and performing user login auditing based on the to-be-audited event data through the login auditing daemon process, and generating a user login auditing result. According to the scheme, the system call event is acquired through the extension packet filter program mounting to perform user login auditing, so that the event call can be monitored in real time, and the real-time performance is high; the auditing process does not depend on log files, and the log tampering risk is avoided; kernel source codes, system configuration and the like do not need to be modified, the original authentication process and system stability are not influenced, the invasiveness is low, and the compatibility is high.
Owner:SHANGHAI JIACHE INFORMATION TECH CO LTD

Methods and systems for efficient adaptive logging of cyber threat incidents

ActiveUS12603862B2Securing communicationData packCyber threat intelligence
A packet-filtering network appliance such as a threat intelligence gateway (TIG) protects TCP / IP networks from Internet threats by enforcing certain policies on in-transit packets that are crossing network boundaries. The policies are composed of packet filtering rules derived from cyber threat intelligence (CTI). Logs of rule-matching packets and their associated flows are sent to cyberanalysis applications located at security operations centers (SOCs) and operated by cyberanalysts. Some cyber threats / attacks, or incidents, are composed of many different flows occurring at a very high rate, which generates a flood of logs that may overwhelm computer, storage, network, and cyberanalysis resources, thereby compromising cyber defenses. The present disclosure describes incident logging, in which a single incident log efficiently incorporates the logs of the many flows that comprise the incident, thereby potentially reducing resource consumption while improving the informational / cyberanalytical value of the incident log for cyberanalysis when compared to the component flow logs. Incident logging vs. flow logging can be automatically and adaptively switched on or off depending on the combination of resource consumption and informational / cyberanalytical value.
Owner:CENTRIPETAL NETWORKS INC

Operating system fingerprint simulation method, device, equipment, medium and product

The invention discloses an operating system fingerprint simulation method and device, equipment, a medium and a product. The method comprises the following steps: capturing a plurality of first detection messages received by a detection host by using an eBPF program through an eBPF virtual machine in a kernel mode; feature information corresponding to the multiple first detection messages is extracted, a second detection message in the multiple first detection messages is determined according to the feature information, and the second detection message belongs to an Nmap operating system fingerprint detection packet in any detection stage in Nmap operating system fingerprint scanning; filtering the second detection message; generating a performance event according to attribute information of an Nmap operating system fingerprint detection packet corresponding to the second detection message, and storing the performance event in an eBPF map data structure; and the user mode program reads the corresponding performance event through the file descriptor so as to simulate the fingerprint of the Nmap operating system. According to the embodiment of the invention, the influence on the performance of the operating system can be reduced to the minimum while the fingerprint of the operating system is disguised.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP +1

Method for efficiently analyzing message header with any self-defined length on TOFINO chip

The invention discloses a method for efficiently analyzing a message header with any self-defined length on a TOFINO chip, and belongs to the field of network flow packet filtering and shunting. The method specifically comprises the following steps: firstly, customizing the type and length of a message header according to a service scene; and then, adding the message length of the original message header and the length of the user-defined message header, and filling a length field of the user-defined message header with the message length of the original message header and the length of the user-defined message header. Thirdly, integrating and inputting the user-defined message header and the original message into a TOFINO chip, analyzing according to a length field in the user-defined message header, judging whether the length of the unanalyzed message is 0 or not, and if so, skipping and directly entering the analysis of the original message; otherwise, analyzing the user-defined message header, extracting the content of the message header, storing the content in the PHV of the chip for subsequent use, and placing a message header pointer at the head of the unanalyzed message; and after the user-defined message header is completely analyzed, entering the analysis of the original message. According to the invention, the message forwarding efficiency is improved.
Owner:BEIJING SCISTOR TECH

System and method for granting intermediary access to a data flow between non-kernel applications

Methods and apparatus for emerging use case support in user space networking architectures. In one embodiment, an apparatus configured to segregate packet data based on a packet type is disclosed. The exemplary embodiment provides a custom data type registry that enables the definition, addition, removal, modification, and / or prioritization of custom packet processing rules. Variants of the registry may support custom ethertype packets, network packets, and / or transport packets. In another embodiment, mechanisms for enabling an intermediary packet processing stage are described. Intermediary packet processing may enable user space system extensions that support e.g., packet filtering, packet modification, and / or other forms of packet processing.
Owner:APPLE INC

A data packet filtering method and device, a communication device, a chip and a storage medium

The present disclosure provides a data packet filtering method and device, a communication device, a chip and a storage medium. A modification instruction is received from a control console, the modification instruction being used to modify a first filter in first filtering information, the first filtering information including at least one first filter. A target filter list is determined according to the modification instruction, the target filter list including a first operation code, the first operation code being used to instruct a network device to replace the at least one first filter with a filter in the target filter list. Target filtering information is determined, the target filtering information being used to filter uplink data packets. The uplink data packets of a terminal can be filtered, the network device can be instructed through the first operation code, the complexity of terminal code can be reduced, and the processing efficiency, stability and reliability of the terminal can be improved.
Owner:BEIJING X RING TECHNOLOGY CO LTD

Iot device identification method based on locality sensitive hashing in smart home

The application discloses a kind of local sensitive hash-based internet of things equipment identification method: (1) obtaining device traffic at gateway, and classifying according to the physical address of specific device;(2) the device traffic of good classification is filtered, slicing and reorganization to create device signature;(3) using local sensitive hash algorithm to generate digest for each signature, digest is stored in digest database together with device label;(4) generate the digest of the traffic to be identified, compare it with all instances in the database, calculate four indexes;(5) use the three linear regression model trained by multi-index evaluation method to fit the similarity score of 10 pieces of signature aggregation, and the device with the highest fitting score is returned as the predicted value of the device.The application can realize fast and accurate fine-grained internet of things equipment identification, and avoids the cumbersome process of feature extraction and model training in machine learning, reduces the computing overhead and is simple to deploy.
Owner:HUAZHONG UNIV OF SCI & TECH

An eBPF-based non-intrusive intelligent agent behavior collection method, device, medium and program product

The application provides an eBPF-based non-intrusive intelligent agent behavior collection method, device, medium and program product. The method comprises the following steps: loading an extended Berkeley packet filter-based collection probe in an operating system kernel of a target computing node; collecting system call behaviors, network communication behaviors and process execution behaviors in an intelligent agent running process to obtain original behavior event data; transmitting the original behavior event data from the operating system kernel to a user state asynchronously through a data transmission mechanism between the kernel state and the user state; filtering, processing, protocol reorganizing and metadata enriching the original behavior event data in the user state to obtain structured behavior event data; performing metering processing on resource consumption of the intelligent agent in a model calling stage to obtain resource consumption indexes; and forming a full-link behavior event data stream based on the structured behavior event data and the resource consumption indexes. The application has the advantages of non-intrusiveness and low overhead, and improves the observability of the system.
Owner:SHANGHAI JIEYUE JIYUAN INTELLIGENT TECHNOLOGY CO LTD

Prioritizing data flows

Various embodiments include methods of managing mixed data flow types in communications in a network apparatus. The network apparatus may determine data flow priority levels of a plurality of data flows, identify high-priority data flows associated with a particular LAN interface, and assign a designated public IP address range or a designated public port range for the high-priority data. Upon receiving an uplink, the apparatus may select a source port number from the previously reserved range dedicated for high-priority data flows in response to the received packet matching one or more prioritized data flow packet filters, modify the received uplink packet, and forward the modified uplink packet to the next hop in the path towards the destination IP address in response to determining that the packet is enqueued successfully.
Owner:QUALCOMM INC

Protecting networks from cyber attacks and overloading

Packets may be received by a packet security gateway. Responsive to a determination that an overload condition has occurred in one or more networks associated with the packet security gateway, a first group of packet filtering rules may be applied to at least some of the packets. Applying the first group of packet filtering rules may include allowing at least a first portion of the packets to continue toward their respective destinations. Responsive to a determination that the overload condition has been mitigated, a second group of packet filtering rules may be applied to at least some of the packets. Applying the second group of packet filtering rules may include allowing at least a second portion of the packets to continue toward their respective destinations.
Owner:CENTRIPETAL NETWORKS INC

Methods and systems for the efficient enforcement of cybersecurity policies in network communication

Methods, devices, systems, and machine-readable media are disclosed that serve to improve the efficiency of packet filtering by reducing processing time and / or memory requirements. Any type of data structure, such as flat hash tables and / or rule trees, can be used by a packet filtering device to search for packet filtering rules for cybersecurity policies that should be applied to transmitted packets. The packet filtering device can search the index data structures for matches of search objects in the form of values ​​that the packet filtering device extracts from the transmitted packets to match them against the compliance criteria of the policy rules for threat indicators. Each of the index data structures can map rule identifiers (rule IDs) of policy rules to keys that are based on (or include) the compliance criteria of those rules.
Owner:CENTRIPETAL NETWORKS INC

Efficient rule matching method for high-complexity conditional expression rule body

The invention discloses an efficient rule matching method for a high-complexity condition expression rule body, and belongs to the technical field of network flow data packet filtering. And defining priorities among the operators and defining processing callback functions of the operators and the operands. Then, the rule body condition expression is scanned, analyzed and compiled, so that the rule body condition expression is converted into a similar executable binary program which can be executed by a plurality of users, and a result is calculated. Rule body matching: executing the binary programs which can be executed by the rule body type according to the compiled assembly instruction sequence; each calculation result of the expression is stored at the top of the stack, and a final result is stored at the bottom of the stack. According to the method, a lexical analysis method in a compiling principle is taken as a guiding policy, pre-compiling of an expression calculation process is completed, and expression matching calculation is accelerated; and meanwhile, the locality of the matching calculation process is enhanced, and the CPU processing capacity is fully utilized.
Owner:BEIJING SCISTOR TECH