首页> 外国专利> FPGA MATCHING METHOD OF HIGH SPEED SNORT RULE AND YARA RULE BASED ON FPGA

FPGA MATCHING METHOD OF HIGH SPEED SNORT RULE AND YARA RULE BASED ON FPGA

机译:基于FPGA的高速鼻尺和亚拉尺的FPGA匹配方法

摘要

The present invention relates to an FPGA-based fast snort rule and Yarra rule matching method, comprising: a rule conversion step of converting a snort rule and a yarra rule in a detection rule converter to store a fixed pattern and a PCRE pattern in a memory on a hardware board; A pattern matching step of receiving a packet input from a network based on the converted rule, parsing the packet in a packet FIFO and a fast packet processing module, and performing fixed pattern and PCRE pattern matching, respectively; Receives the header value and payload of the packet from the packet parsing, reconstructs the file, stores it in a memory inside the FPGA, and matches the stored hash values based on the additionally input packet to match the mitigation control signal in the detection result processing module. A hash matching step occurring; And a packet forwarding step of successively generating packet drop and packet forwarding by determining whether to relax the packet by reading the packet from the packet FIFO.
机译:本发明涉及一种基于FPGA的快速snort规则和yarra规则匹配方法,包括:规则转换步骤,其在检测规则转换器中转换snort规则和yarra规则,以将固定模式和PCRE模式存储在存储器中。在硬件板上;模式匹配步骤,根据转换后的规则,接收从网络输入的数据包,将其解析为数据包FIFO和快速数据包处理模块,分别进行固定模式和PCRE模式匹配;从数据包解析中接收数据包的报头值和有效载荷,重建文件,将其存储在FPGA内部的存储器中,并根据额外输入的数据包匹配存储的哈希值,以在检测结果处理中匹配缓解控制信号模块。发生哈希匹配步骤;以及一种分组转发步骤,其通过从分组FIFO中读取分组来确定是否放松分组来连续地产生分组丢弃和分组转发。

著录项

  • 公开/公告号KR102014741B1

    专利类型

  • 公开/公告日2019-08-28

    原文格式PDF

  • 申请/专利权人 (주)피즐리소프트;

    申请/专利号KR20170115181

  • 发明设计人 이호재;강병완;장성민;박석영;

    申请日2017-09-08

  • 分类号H04L29/06;G06F21/56;G06F9/30;H04L9/06;

  • 国家 KR

  • 入库时间 2022-08-21 11:47:57

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号