Finite State Machine for Simultaneous Rule Checking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems face inefficiencies due to the need for multiple passes over incoming packets to check against multiple rules, leading to increased computational overhead and delayed data throughput when detecting undesirable content.
Innovation Solution
A system and method for simultaneously examining keywords in a data string against rule keywords using a finite state machine, allowing for the determination of satisfied rules in a single pass, thereby reducing the computational burden and improving data throughput.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple rules are applied to examine incoming packets for undesirable content, then security detection capability is improved, but computational overhead increases and data throughput decreases
Solution Approach 1:
The patent combines multiple rule-checking operations into a single unified process. Instead of sequentially applying each rule to examine packets, the system merges the keyword sets from all rules and performs one comprehensive search through the packet data string, thereby maintaining security detection capability while reducing computational overhead and improving throughput.
Solution Approach 2:
The invention creates a universal keyword matching mechanism that serves multiple security rules simultaneously. The single search process is designed to detect all undesirable content patterns across different rules in one pass, making the system multi-functional rather than requiring separate specialized checks for each rule.
2Adaptability or versatility
If multiple rules are applied to examine incoming packets, then detection of new threats is improved, but computational overhead increases
Solution Approach 1:
The patent merges the computational tasks of multiple rule evaluations into a single search operation. By combining all rule keywords into one unified search process, the system maintains its ability to detect new threats through comprehensive rule coverage while significantly reducing the total computational energy required compared to sequential rule application.
3Reliability
If multiple passes over packets are performed to check rules, then rule satisfaction determination is improved, but time consumption increases
Solution Approach 1:
The system performs preliminary preparation by pre-processing and combining all rule keywords into a unified search structure before actual packet processing. This preliminary action enables the system to determine rule satisfaction in a single pass through the packet data, eliminating the need for multiple sequential passes and thereby reducing time consumption while maintaining reliable rule satisfaction determination.
Data Source
AI summary
A method and system for checking data against a plurality of rules simultaneously. A data string having keywords in the data string is received. All of the keywords in the data string are simultaneously examined against rule keywords using for example, a finite state machine constructed by the Aho-Corasick algorithm. The rule keyword represents at least one rule of the plurality of rules. It is determined which of the plurality of rules are satisfied by the data string based on whether each keyword matches the rule keywords. Such rules may be used for application such as negative security policies.


