发明授权
US07904961B2 Network attack detection using partial deterministic finite automaton pattern matching
有权
使用部分确定性有限自动机模式匹配的网络攻击检测
- 专利标题: Network attack detection using partial deterministic finite automaton pattern matching
- 专利标题(中): 使用部分确定性有限自动机模式匹配的网络攻击检测
-
申请号: US11738059申请日: 2007-04-20
-
公开(公告)号: US07904961B2公开(公告)日: 2011-03-08
- 发明人: Qingming Ma , Bryan Burns , Krishna Narayanaswamy , Vipin Rawat , Michael Chuong Shieh
- 申请人: Qingming Ma , Bryan Burns , Krishna Narayanaswamy , Vipin Rawat , Michael Chuong Shieh
- 申请人地址: US CA Sunnyvale
- 专利权人: Juniper Networks, Inc.
- 当前专利权人: Juniper Networks, Inc.
- 当前专利权人地址: US CA Sunnyvale
- 代理机构: Shumaker & Sieffert, P.A.
- 主分类号: G06F11/00
- IPC分类号: G06F11/00
摘要:
This disclosure describes techniques for determining whether network traffic contains one or more computer security threats. In order to determine whether a symbol stream conforms to the symbol pattern, a security device stores a full deterministic finite automaton (fDFA) that accepts streams of symbols that conform to the symbol pattern. The security device also creates a partial deterministic finite automaton (pDFA) that includes nodes that correspond to the nodes in the fDFA that have the highest visitation levels. The security device processes each symbol in the symbol stream using the pDFA until a symbol causes the pDFA to transition to a failure node or to an accepting node. If the symbol causes the pDFA to transition to the failure node, the security device processes the symbol and subsequent symbols in the symbol stream using the fDFA.
公开/授权文献
信息查询