首页> 外国专利> Layered memory architecture for deterministic finite automaton based string matching useful in network intrusion detection and prevention systems and apparatuses

Layered memory architecture for deterministic finite automaton based string matching useful in network intrusion detection and prevention systems and apparatuses

机译:用于基于确定性有限自动机的字符串匹配的分层存储体系结构,可用于网络入侵检测和预防系统和设备

摘要

The present invention provides a method and apparatus for searching multiple strings within a packet data using deterministic finite automata. The apparatus includes means for updating memory tables stored in a layered memory architecture comprising a BRAM, an SRAM and a DRAM; a mechanism to strategically store the relevant data structure in the three memories based on the characteristics of data, size/capacity of the data structure, and frequency of access. The apparatus intelligently and efficiently places the associated data in different memories based on the observed fact that density of most rule-sets is around 10% for common data in typical network intrusion prevention systems. The methodology and layered memory architecture enable the apparatus implementing the present invention to achieve data processing line rates over 2 Gbps.
机译:本发明提供了一种使用确定性有限自动机在分组数据中搜索多个字符串的方法和装置。该装置包括用于更新存储在包括BRAM,SRAM和DRAM的分层存储器架构中的存储器表的装置;一种根据数据的特性,数据结构的大小/容量和访问频率将相关数据结构策略性地存储在三个存储器中的机制。该设备基于观察到的事实,即在典型的网络入侵防御系统中,大多数规则集的密度对于常见数据而言约为10%,可以智能,有效地将关联数据放置在不同的存储器中。该方法和分层存储器架构使实现本发明的设备能够实现超过2Gbps的数据处理线速。

著录项

  • 公开/公告号US2006101195A1

    专利类型

  • 公开/公告日2006-05-11

    原文格式PDF

  • 申请/专利权人 HEMANT KUMAR JAIN;

    申请/专利号US20040984244

  • 发明设计人 HEMANT KUMAR JAIN;

    申请日2004-11-08

  • 分类号G06F13/00;

  • 国家 US

  • 入库时间 2022-08-21 21:47:57

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号