IP Library Granted Patent US 11,539,750
Granted Patent B2
US 11,539,750 · App. 16/581,638 · Granted Dec 27, 2022

Systems and methods for network security memory reduction via distributed rulesets

Inventor: Dejan Nenov (Boise, ID)
Assignee: Fortress Cyber Security, LLC
H04L63/20H04L63/0263H04L67/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,539,750
App. No.
16/581,638
Granted
Dec 27, 2022
Kind
B2
Abstract

The present disclosure describes systems and methods for reducing rule set sizes via statistical redistribution throughout a plurality of network security appliances. A rule set may be generated for each security appliance that includes (i) a first set of rules based on known attacks, identified as rules for mandatory inclusion in the rule set; and (ii) a subset of the second set of rules, identified as rules for potential inclusion in the rule set, selected randomly according to a distribution percentage, score, or weight for each potentially included rule. Higher scored rules, which may be more likely vectors for potential attack, may be distributed to a greater number of appliances; while lower scored rules that may be less likely or represent more speculative attacks may be distributed to fewer appliances.

Claims (40)

1. A method for providing distributed rule sets for network security appliances, comprising:

generating, by a management server, from a rule database comprising a plurality of packet processing rules, each packet processing rule associated with a distribution percentage, a first rule set for a first security appliance, the first rule set comprising a first subset of the packet processing rules each associated with a 100% distribution percentage and a second subset of the packet processing rules associated with distribution percentages less than 100%;

generating, by the management server, a second rule set for a second security appliance, the second rule set comprising the first subset of the packet processing rules and a third subset of the packet processing rules associated with distribution percentages less than 100%, the packet processing rules of the third subset different from the packet processing rules of the second subset; and

transmitting, by the management server, the first rule set to the first security appliance and the second rule set to the second security appliance.

2. The method of claim 1 , wherein the first subset consists of packet processing rules identified in the rule database as mandatory.

3. The method of claim 1 , wherein generating the first rule set further comprises:

adding the first subset of the packet processing rules to the first rule set; and

adding the second subset of the packet processing rules to the first rule set by:

adding a first additional packet processing rule of the packet processing rules to the first rule set,

determining that a storage size of the first rule set is below a predetermined threshold, and

adding a second additional packet processing rule of the packet processing rules to the first rule set.

4. The method of claim 3 , further comprising adding an association of a device identifier of the first security appliance, in the rule database, to each entry corresponding to each packet processing rule included in the first rule set.

5. The method of claim 3 , wherein generating the first rule set further comprises determining that the storage size of the first rule set exceeds the predetermined threshold; and wherein transmitting the first rule set to the first security appliance is performed responsive to the determination.

6. The method of claim 3 , wherein adding the first additional packet processing rule to the first rule set further comprises:

selecting the first additional packet processing rule;

generating a random distribution score value; and

adding the first additional packet processing rule to the first rule set responsive to the random distribution score value being less than a distribution percentage associated with the first additional packet processing rule.

7. The method of claim 6 , wherein generating the random distribution score value further comprises retrieving the random distribution score value from a random number generator or pseudo random number generator of the management server.

8. The method of claim 6 , wherein generating the random distribution score value further comprises calculating a result of a hash function with inputs comprising a device identifier of the first security appliance.

9. A system for providing distributed rule sets for network security appliances, comprising:

a management server comprising a processor executing a rule distributor, a network interface in communication with a first security appliance and a second security appliance, and a storage device comprising a rule database comprising a plurality of packet processing rules, each packet processing rule associated with a distribution percentage;

wherein the rule distributor is configured to generate a plurality of rulesets having a common subset and a different subset by:

generating a first rule set for a first security appliance, the first rule set comprising a first subset of the packet processing rules associated with a 100% distribution percentage and a second subset of the packet processing rules associated with distribution percentages less than 100%, and

generate a second rule set for a second security appliance, the second rule set comprising the first subset of the packet processing rules associated with the 100% distribution percentage and a third subset of the packet processing rules associated with distribution percentages less than 100%, the packet processing rules of the third subset different from the packet processing rules of the second subset; and

wherein the network interface is configured to transmit the first rule set to the first security appliance and the second rule set to the second security appliance.

10. The system of claim 9 , wherein the first subset consists of packet processing rules identified in the rule database as mandatory.

11. The system of claim 9 , wherein the rule distributor is further configured for generating the first rule set by:

adding the first subset of the packet processing rules to the first rule set; and

adding the second subset of the packet processing rules to the first rule set by:

adding a first additional packet processing rule of the packet processing rules to the first rule set,

determining that a storage size of the first rule set is below a predetermined threshold, and

adding a second additional packet processing rule of the packet processing rules to the first rule set.

12. The system of claim 11 , wherein the rule distributor is further configured for determining that the storage size of the first rule set exceeds the predetermined threshold; and wherein transmitting the first rule set to the first security appliance is performed responsive to the determination.

13. The system of claim 11 , wherein the rule distributor is further configured for adding an association of a device identifier of the first security appliance, in the rule database, to each entry corresponding to each packet processing rule included in the first rule set.

14. The system of claim 11 , wherein the rule distributor is further configured for:

selecting the first additional packet processing rule,

generating a random distribution score value, and

adding the first additional packet processing rule to the first rule set responsive to the random distribution score value being less than a distribution percentage associated with the first additional packet processing rule.

15. The system of claim 14 , wherein the management server further comprises a random number generator or pseudo random number generator; and wherein the rule distributor is further configured for retrieving the random distribution score value from the random number generator or pseudo random number generator.

16. The system of claim 14 , wherein the rule distributor is further configured for calculating a result of a hash function with inputs comprising a device identifier of the first security appliance.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Jul 2, 2025
From: CANADIAN IMPERIAL BANK OF COMMERCE
To: FORTRESS CYBER SECURITY, LLC
Reel/Frame 071594/0876 →
SECURITY INTEREST Recorded Jun 30, 2025
From: FORTRESS CYBER SECURITY, LLC
To: WESTERN ALLIANCE BANK
Reel/Frame 071570/0495 →
SECURITY INTEREST Recorded Oct 2, 2023
From: FORTRESS CYBER SECURITY, LLC
To: CANADIAN IMPERIAL BANK OF COMMERCE
Reel/Frame 065097/0809 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 24, 2020
From: FORTRESS INFORMATION SECURITY, LLC
To: FORTRESS CYBER SECURITY, LLC
Reel/Frame 053578/0478 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 21, 2020
From: NENOV, DEJAN
To: FORTRESS INFORMATION SECURITY
Reel/Frame 053564/0577 →
Continuity (3)
Continuation 15702613 · Sep 12, 2017
Continuation 15292669 · Oct 13, 2016
Related Publication 20200021619A1 · Jan 16, 2020