IP Library Granted Patent US 8,463,730
Granted Patent B1
US 8,463,730 · App. 12/605,287 · Granted Jun 11, 2013

Rapid evaluation of numerically large complex rules governing network and application transactions

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,463,730
App. No.
12/605,287
Granted
Jun 11, 2013
Kind
B1
Abstract

A solution for rapid evaluation of numerically large complex rules governing network and application transactions includes, at a network device, receiving network transaction record comprising a plurality of elements that characterize a network transaction, creating a hash of a result of concatenating the plurality of elements, and if the hash is found in a hash table comprising, for each network transaction rule, a hash of the plurality of elements comprising the rule, blocking the network transaction or alerting a network user that a prohibited transaction has occurred.

Claims (89)

1. A computer implemented method comprising:

at a network device, receiving network transaction record comprising a plurality of elements of possibly dissimilar data types, each of the plurality of elements characterizing a network transaction;

creating a hash of a result of concatenating the plurality of elements regardless of the type of each of the plurality of elements; and

if the hash is found in a hash table comprising, for each network transaction rule, a hash of the plurality of elements comprising the rule,

ignoring the network transaction;

blocking the network transaction; or

alerting a network user that a prohibited transaction has occurred.

2. The method of claim 1 wherein the creating further comprises, for each combination of elements in the network transaction record, creating a hash.

3. The method of claim 2 wherein a number of combinations of elements is reduced by eliminating combinations of elements that cannot be present in the same network transaction.

4. The method of claim 3 wherein the combinations of elements that cannot be present in the same network transaction comprise a combination of:

elements of a transaction specific to database operations; and

elements of a transaction specific to file operations.

5. The method of claim 2 wherein a number of combinations of elements is reduced by eliminating combinations of elements that include an element not found at least one rule.

6. The method of claim 1 , further comprising:

for each network transaction rule having a wild card for a portion of at least one of the plurality of elements comprising the rule, the hash is encoded as if the elements having a wild card were absent from the rule;

if the hash is found, matching the network transaction against the element having the wild card; and

if there is a match,

ignoring the network transaction;

blocking the network transaction; or

alerting a network user that a prohibited transaction has occurred.

7. The method of claim 1 , further comprising:

for each network transaction rule having a white list indication for a portion of at least one of the plurality of elements comprising the rule, the hash is encoded as if the elements having a wild card were absent from the rule;

if the hash is found, matching the network transaction against the element having the white list element; and

if there is no match,

ignoring the network transaction;

blocking the network transaction; or

alerting a network user that a prohibited transaction has occurred.

8. A network device comprising:

a memory; and

one or more processors configured to:

receive network transaction record comprising a plurality of elements of possibly dissimilar data types, each of the plurality of elements characterizing a network transaction;

create a hash of a result of concatenating the plurality of elements regardless of the type of each of the plurality of elements; and

if the hash is found in a hash table comprising, for each network transaction rule, a hash of the plurality of elements comprising the rule,

ignore the network transaction;

block the network transaction; or

alert a network user that a prohibited transaction has occurred.

9. The network device of claim 8 wherein the creating further comprises, for each combination of elements in the network transaction record, creating a hash.

10. The network device of claim 9 wherein a number of combinations of elements is reduced by eliminating combinations of elements that cannot be present in the same network transaction.

11. The network device of claim 10 wherein the combinations of elements that cannot be present in the same network transaction comprise a combination of:

elements of a transaction specific to database operations; and

elements of a transaction specific to file operations.

12. The network device of claim 9 wherein a number of combinations of elements is reduced by eliminating combinations of elements that include an element not found at least one rule.

13. The network device of claim 8 wherein the one or more processors are further configured to:

for each network transaction rule having a wild card for a portion of at least one of the plurality of elements comprising the rule, encode the hash as if the elements having a wild card were absent from the rule;

if the hash is found, match the network transaction against the element having the wild card; and

if there is a match,

ignore the network transaction;

block the network transaction; or

alert a network user that a prohibited transaction has occurred.

14. The network device of claim 8 wherein the one or more processors are further configured to:

for each network transaction rule having a white list indication for a portion of at least one of the plurality of elements comprising the rule, encode the hash as if the elements having a wild card were absent from the rule;

if the hash is found, match the network transaction against the element having the white list element; and

if there is no match,

ignore the network transaction;

block the network transaction; or

alert a network user that a prohibited transaction has occurred.

15. A program storage device readable by a machine, embodying a program of instructions executable by the machine to perform a method, the method comprising:

at a network device, receiving network transaction record comprising a plurality of elements of possibly dissimilar data types, each of the plurality of elements characterizing a network transaction;

creating a hash of a result of concatenating the plurality of elements regardless of the type of each of the plurality of elements; and

if the hash is found in a hash table comprising, for each network transaction rule, a hash of the plurality of elements comprising the rule,

ignoring the network transaction;

blocking the network transaction; or

alerting a network user that a prohibited transaction has occurred.

16. A network device comprising:

means for, at a network device, receiving network transaction record comprising a plurality of elements of possibly dissimilar data types, each of the plurality of elements characterizing a network transaction;

means for creating a hash of a result of concatenating the plurality of elements regardless of the type of each of the plurality of elements; and

means for, if the hash is found in a hash table comprising, for each network transaction rule,

a hash of the plurality of elements comprising the rule,

ignoring the network transaction;

blocking the network transaction; or

alerting a network user that a prohibited transaction has occurred.

17. A computer implemented method comprising:

at a network device, receiving network transaction record comprising a first plurality of elements of possibly dissimilar data types, each of the first plurality of elements characterizing a network transaction;

selectively removing one or more elements from the first plurality of elements according to a binary pattern to create a second plurality of elements;

creating a hash of a result of concatenating the second plurality of elements regardless of the type of each of the plurality of elements; and

if the hash is found in a hash table comprising, for each network transaction rule, a hash of a plurality of elements comprising the rule,

ignoring the network transaction;

blocking the network transaction; or

alerting a network user that a prohibited transaction has occurred.

18. A network device comprising:

a memory; and

one or more processors configured to:

receive network transaction record comprising a first plurality of elements of possibly dissimilar data types, each of the first plurality of elements characterizing a network transaction;

selectively remove one or more elements from the first plurality of elements according to a binary pattern to create a second plurality of elements;

create a hash of a result of concatenating the second plurality of elements regardless of the type of each of the plurality of elements; and

if the hash is found in a hash table comprising, for each network transaction rule, a hash of a plurality of elements comprising the rule,

ignoring the network transaction;

block the network transaction; or

alert a network user that a prohibited transaction has occurred.

Assignments (7)
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0314 →
MERGER Recorded Sep 23, 2013
From: PACKETMOTION, INC.
To: VMWARE, INC.
Reel/Frame 031261/0056 →
RELEASE OF SECURITY INTEREST Recorded Oct 3, 2011
From: SILICON VALLEY BANK
To: PACKETMOTION, INC.
Reel/Frame 027007/0249 →
RELEASE OF SECURITY INTEREST Recorded Oct 3, 2011
From: MMV FINANCE INC.
To: PACKETMOTION, INC.
Reel/Frame 027007/0120 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2011
From: SMITH, PAUL; GILES, RICK; SUN, TONY
To: PACKETMOTION, INC.
Reel/Frame 026690/0327 →
SECURITY AGREEMENT Recorded Jul 22, 2010
From: PACKETMOTION, INC.
To: SILICON VALLEY BANK
Reel/Frame 024729/0261 →
SECURITY AGREEMENT Recorded Jun 30, 2010
From: PACKETMOTION, INC.
To: MMV FINANCE INC.
Reel/Frame 024616/0020 →