MATCHING WITH A LARGE VULNERABILITY SIGNATURE RULESET FOR HIGH PERFORMANCE NETWORK DEFENSE

Patent №

US 8,522,348

Granted

2013-08-27

Filed 2010

Owner

NORTHWESTERN UNIVERSITY, AN ILLINOIS NOT-FOR-PROFIT CORPORATION

Lab

AI components

2

kr · hardware

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

12846541

Systems, methods, and apparatus are provided for vulnerability signature based Network Intrusion Detection and/or Prevention which achieves high throughput comparable to that of the state-of-the-art regex-based systems while offering improved accuracy. A candidate selection algorithm efficiently matches thousands of vulnerability signatures simultaneously using a small amount of memory. A parsing transition state machine achieves fast protocol parsing. Certain examples provide a computer-implemented method for network intrusion detection. The method includes capturing a data message and invoking a protocol parser to parse the data message. The method also includes matching the parsed data message against a plurality of vulnerability signatures in parallel using a candidate selection algorithm and detecting an unwanted network intrusion based on an outcome of the matching.

Knowledge representationAI hardwareH04L 63/1416H04L 69/22H04L 63/1433

AI classification

Knowledge representation0.84
AI hardware0.84
Planning0.08
Machine learning0.01
Natural language0.01
Vision0.00
Evolutionary computation0.00
Speech0.00

Ownership

NORTHWESTERN UNIVERSITY, AN ILLINOIS NOT-FOR-PROFIT CORPORATION

assignment · 249630300

Assignors

CHEN, YAN, LI, ZHICHUN, XIA, GAO, LIU, BIN

On an employer assignment, the assignors are typically the inventors.

© 2026 NYSGPT2525 LLC