×

Method for indexing a plurality of policy filters

  • US 20050114704A1
  • Filed: 11/26/2003
  • Published: 05/26/2005
  • Est. Priority Date: 11/26/2003
  • Status: Active Grant
First Claim
Patent Images

1. A method for dynamically creating and maintaining a set of indices in a computer, wherein the indices identify a plurality of filters defining a network policy and wherein the indices are used by a firewall to identify a matching filter, comprising:

  • creating a first index conforming to a first index type;

    identifying, in the first index, a first set of filters, each filter in the first set of filters specifying network packets subject to the network policy;

    maintaining statistics including a selected criteria and a corresponding value, wherein the value identifies a number of filters from the first set of filters meeting the selected criteria;

    determining that the corresponding value exceeds a threshold value;

    creating a second index conforming to a second index type;

    identifying, in the second index, a second set of filters, wherein the second set of filters are a subset of the first set of filters; and

    removing identification of the subset of filters from the first index.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×