Dynamic rule chained recursive triggering method based on message content awareness and system
The invention discloses a dynamic rule chained recursive triggering method based on message content awareness and a system. According to main technical characteristics, on the basis of establishing adynamic rule chained recursive triggering system, for the problem that an existing TAP device cannot...
Gespeichert in:
Hauptverfasser: | , , , , , , , , , |
---|---|
Format: | Patent |
Sprache: | chi ; eng |
Schlagworte: | |
Online-Zugang: | Volltext bestellen |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Zusammenfassung: | The invention discloses a dynamic rule chained recursive triggering method based on message content awareness and a system. According to main technical characteristics, on the basis of establishing adynamic rule chained recursive triggering system, for the problem that an existing TAP device cannot carry out dynamic association analysis on message streams, triggers and an association relationshipbetween the triggers and triggering rules are added, through adoption of steps such as trigger configuration, static rule and trigger definition configuration, message matching, new dynamic rule generation, rule aging deletion and rule table updating, dynamic information such as such as IP addresses, ports and user identities in the externally input message streams are dynamically extracted, andthe new dynamic rules are recursively triggered, so the message streams can be precisely output to a rear end analysis system, input bandwidths of the rear end analysis can be clearly saved, and the performance loss of the rear |
---|