Multi-String Pattern Matching for Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computing systems performing multi-string pattern rule matching, such as intrusion detection systems, require multiple scans of data to detect matching patterns, which is time-consuming and inefficient, especially when patterns do not follow a specific order.

Innovation Solution

The system generates rule and pattern combinations with unique identifiers, allowing for a single scan to determine if all patterns in a rule are present in the data, using bit strings or state machines to efficiently match patterns in a payload.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If multiple scans of data are performed to detect matching patterns, then pattern matching accuracy is improved, but detection speed deteriorates

Engineering Contradiction:
Improvepattern matching accuracyVSAvoiddetection speed
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The patent pre-processes the payload data before pattern matching by generating all possible substrings of length matching the pattern and storing them in a hash table. This preliminary action allows the multiple pattern matching to be performed efficiently in a single scan, as all required substrings are already prepared and can be quickly checked against the patterns without requiring multiple passes through the data.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple scans of data are performed to detect matching patterns, then reliability of detection is improved, but loss of time increases

Engineering Contradiction:
Improvedetection reliabilityVSAvoidpattern matching time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent pre-processes the payload data before pattern matching by generating all possible substrings of length matching the pattern and storing them in a hash table. This preliminary action allows the multiple pattern matching to be performed efficiently in a single scan, as all required substrings are already prepared and can be quickly checked against the patterns without requiring multiple passes through the data.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple scans of data are performed to detect matching patterns, then completeness of pattern detection is improved, but productivity deteriorates

Engineering Contradiction:
Improvepattern detection completenessVSAvoidintrusion detection throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent pre-processes the payload data before pattern matching by generating all possible substrings of length matching the pattern and storing them in a hash table. This preliminary action allows the multiple pattern matching to be performed efficiently in a single scan, as all required substrings are already prepared and can be quickly checked against the patterns without requiring multiple passes through the data.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11954005B2String pattern matching for multi-string pattern rules in intrusion detection
Publication Date: 2024.04.09 VMWARE INC
  • US11954005B2 patent drawing
  • US11954005B2 patent drawing
  • US11954005B2 patent drawing

AI summary

In some embodiments, a method stores a plurality of identifiers for a plurality of rules. The plurality of rules each include a set of patterns, and a rule and a pattern combination is associated with an identifier in the plurality of identifiers. Information being sent on a network is scanned and the method determines when a pattern in the information matches a pattern for a rule. The method identifies an identifier for the pattern where the identifier identifies a rule and a pattern combination. Then, the method identifies the rule and the pattern combination based on the identifier. The set of patterns for the rule is found in the information based on determining that the rule and the pattern combinations for the rule have been found in the information.