Network Device Signature Rule Loading via Cloud Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems face inefficiencies in managing and distributing signature rules across devices with varying configurations, leading to resource misallocation and functional restrictions due to incorrect selection of signature sub-libraries.
Innovation Solution
A method where network devices automatically select and load signature rules from a centralized library based on their specific device type configuration information, eliminating the need for tailored sub-libraries and reducing storage complexity on cloud servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If signature sub-libraries are tailored according to device type and model, then the signature rules match device requirements, but the device complexity and storage management complexity increase
Solution Approach 1:
The patent applies universality by creating a unified signature rule library that serves all device types and models, eliminating the need for multiple tailored sub-libraries. The system universally manages signature rules through a single interface while adapting to different device capabilities through automatic selection mechanisms.
Solution Approach 2:
The system enables self-service by allowing the network device to automatically determine its own type and model, then autonomously select and load the appropriate signature rules from the unified library without requiring manual intervention or complex external matching processes.
2Reliability
If the scale of signature library grows to protect against more attacks, then the security coverage improves, but the storage space and loading time increase
Solution Approach 1:
The patent extracts only the necessary signature rules from the comprehensive unified library based on the specific device's type and model requirements. This extraction process removes unnecessary signature rules that would otherwise occupy storage space and increase loading time, while maintaining complete security coverage for the specific device context.
3Adaptability or versatility
If tailored signature sub-libraries are issued to different device types, then the functionality matches device capabilities, but the cloud server storage complexity increases
Solution Approach 1:
The patent merges multiple device-specific signature sub-libraries into a single unified signature rule library. This consolidation maintains adaptability to different device capabilities through structured organization and metadata, while significantly reducing cloud server storage complexity by eliminating the need to manage multiple separate library files.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Disclosed is a method of loading a signature rule and a network device thereof. According to an example of the method, the network device may first receive a signature rule library sent by a cloud server, wherein the signature rule library contains one or more signature rules, each of which is associated with corresponding device type configuration information. The network device may determine for each signature rule whether device type configuration information associated with the signature rule matches local device type configuration information of the network device. If the device type configuration information associated with the signature rule matches the local device type configuration information of the network device, the network device may load the signature rule.