Network Device Signature Rule Loading via Cloud Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face inefficiencies in managing and distributing signature rules across devices with varying configurations, leading to resource misallocation and functional restrictions due to incorrect selection of signature sub-libraries.

Innovation Solution

A method where network devices automatically select and load signature rules from a centralized library based on their specific device type configuration information, eliminating the need for tailored sub-libraries and reducing storage complexity on cloud servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If signature sub-libraries are tailored according to device type and model, then the signature rules match device requirements, but the device complexity and storage management complexity increase

Engineering Contradiction:
Improvesignature rule matching accuracyVSAvoidstorage management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a unified signature rule library that serves all device types and models, eliminating the need for multiple tailored sub-libraries. The system universally manages signature rules through a single interface while adapting to different device capabilities through automatic selection mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables self-service by allowing the network device to automatically determine its own type and model, then autonomously select and load the appropriate signature rules from the unified library without requiring manual intervention or complex external matching processes.

Inventive Principle:
Principle #25Self-service

2Reliability

If the scale of signature library grows to protect against more attacks, then the security coverage improves, but the storage space and loading time increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsignature rule loading time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts only the necessary signature rules from the comprehensive unified library based on the specific device's type and model requirements. This extraction process removes unnecessary signature rules that would otherwise occupy storage space and increase loading time, while maintaining complete security coverage for the specific device context.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If tailored signature sub-libraries are issued to different device types, then the functionality matches device capabilities, but the cloud server storage complexity increases

Engineering Contradiction:
Improvedevice capability matchingVSAvoidcloud server storage complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple device-specific signature sub-libraries into a single unified signature rule library. This consolidation maintains adaptability to different device capabilities through structured organization and metadata, while significantly reducing cloud server storage complexity by eliminating the need to manage multiple separate library files.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3425868B1Signature rule loading
Publication Date: 2024.01.17 NEW H3C TECH CO LTD
  • EP3425868B1 patent drawingFigure 1
  • EP3425868B1 patent drawingFigure 2
  • EP3425868B1 patent drawingFigure 3

AI summary

Disclosed is a method of loading a signature rule and a network device thereof. According to an example of the method, the network device may first receive a signature rule library sent by a cloud server, wherein the signature rule library contains one or more signature rules, each of which is associated with corresponding device type configuration information. The network device may determine for each signature rule whether device type configuration information associated with the signature rule matches local device type configuration information of the network device. If the device type configuration information associated with the signature rule matches the local device type configuration information of the network device, the network device may load the signature rule.