Match engine for detection of multi-pattern rules
First Claim
1. A method of recognizing a specified group of patterns in a data stream, the method comprising:
- identifying a multi-pattern rule for said specified group of patterns in the data stream;
using a first array of finite state machines, in a first, pattern scanner stage, to scan the data stream for at least some of the patterns in the specified group;
for patterns in the specified group that are found in the data stream by the first array of finite state machines, sending pattern identifiers to a second array of finite state machines, in a second, rule processor stage;
using the second array of finite state machines for determining if the specified group of patterns is in the data stream in accordance with the identified multi-pattern rule by, at least in part, using said pattern identifiers; and
using a compiler to distribute a function that matches an individual pattern over the first, pattern scanner stage and the second, rule processor stage; and
wherein;
the method is used to recognize a multitude of specified groups of patterns in the data stream, and the second array of finite state machines determining if the specified group of patterns is in the data stream includes;
running a multitude of threads on the second array of finite state machines; and
using said multitude of threads to determine whether the multitude of specified groups of patterns are in the data stream; and
the sending pattern identifiers to the second array includes;
for each of the multitude of specified groups of patterns, for patterns in said each group that are found in the data stream by the first array of finite state machines, sending pattern identifiers to an associated one of the threads running on the second array of finite state machines.
1 Assignment
0 Petitions
Accused Products
Abstract
Methods, systems and computer program products are disclosed for detecting patterns in a data stream that match multi-pattern rules. One embodiment of the invention provides a method of recognizing a specified group of patterns in a data stream. The method comprises identifying a rule for said specified group of patterns in the data stream, and using a first array of finite state machines to scan the data stream for at least some of the patterns in the specified group. For patterns in the specified group that are found in the data stream by the first array of finite state machines, pattern identifiers are sent to a second array of finite state machines. The second array of finite state machines determines if the specified group of patterns is in the data stream in accordance with the identified rule by, at least in part, using said pattern identifiers.
32 Citations
12 Claims
-
1. A method of recognizing a specified group of patterns in a data stream, the method comprising:
-
identifying a multi-pattern rule for said specified group of patterns in the data stream; using a first array of finite state machines, in a first, pattern scanner stage, to scan the data stream for at least some of the patterns in the specified group; for patterns in the specified group that are found in the data stream by the first array of finite state machines, sending pattern identifiers to a second array of finite state machines, in a second, rule processor stage; using the second array of finite state machines for determining if the specified group of patterns is in the data stream in accordance with the identified multi-pattern rule by, at least in part, using said pattern identifiers; and using a compiler to distribute a function that matches an individual pattern over the first, pattern scanner stage and the second, rule processor stage; and
wherein;the method is used to recognize a multitude of specified groups of patterns in the data stream, and the second array of finite state machines determining if the specified group of patterns is in the data stream includes; running a multitude of threads on the second array of finite state machines; and using said multitude of threads to determine whether the multitude of specified groups of patterns are in the data stream; and the sending pattern identifiers to the second array includes; for each of the multitude of specified groups of patterns, for patterns in said each group that are found in the data stream by the first array of finite state machines, sending pattern identifiers to an associated one of the threads running on the second array of finite state machines. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8)
-
-
9. An article of manufacture comprising:
-
at least one computer usable hardware medium having computer readable program code logic to execute a machine instruction in a processing unit for using a computer to for recognizing a specified group of patterns in a data stream in accordance with a defined multi-pattern rule, said computer readable program code logic, when executing, performing the following; using a first array of finite state machines to scan the data stream for at least some of the patterns in the specified group; for patterns in the specified group that are found in the data stream by the first array of finite state machines, sending pattern identifiers to a second array of finite state machines; and using the second array of finite state machines for determining if the specified group of patterns is in the data stream in accordance with the identified multi-pattern rule by, at least in part, using said pattern identifiers wherein; the machine instruction is executed to use the computer for recognizing a multitude of specified groups of patterns in the data stream, and wherein the second array of finite state machines determining if the specified group of patterns is in the data stream includes; running a multitude of threads on the second array of finite state machines; and using said multitude of threads to determine whether the multitude of specified groups of patterns are in the data stream. - View Dependent Claims (10, 11, 12)
-
Specification