IL221174A

System and method of rule engine configuration

Abstract

This record has no abstract on file.

Term

No projected expiry on record.

  1. Priority and filed
  2. Published
  3. Today

25 claims: 3 independent, 22 dependent

  1. 1
    A rule engine controller, comprising:an input interface adapted to receive rules relating to a plurality of fields of filtered packets;and a rule manager processor configured to: receive a batch of rules through the input interface, define a plurality of anchor sets of fields of the filtered packets, such that each of the rules in the batch of received rules includes conditions relating to the fields of at least one of the plurality of anchor sets, assign each of the rules to one of the anchor sets;and configure the rules assigned to each anchor set into a respective filtering unit, such that the filtering unit begins the filtering of packets for the rules assigned to the anchor set with the fields of the anchor set.
  2. 21
    The rule engine of any of claims 1-20, comprising a filtering processor implementing the respective filtering units of the anchor sets and wherein the filtering processing unit is configured to perform only real time tasks operating at the rate of packet filtering.
  3. 23
    A method of configuring a packet filter for screening data packets for matching rules, comprising:receiving a batch of rules by a rule manager processor;selecting, by the rule manager processor, a plurality of rule types each corresponding to a set of fields of the filtered packets, such that each of the rules in the batch belongs to at least one of the rule types in that the rule includes conditions on each of the fields in the set of fields corresponding to the rule type, selecting, by the rule manager, for each rule type a structure of at least one lookup key matching the set of fields corresponding to the rule type;receiving, by the rule manager processor, a plurality of rules;determining, by the rule manager, for each received rule a corresponding rule type;configuring the rules assigned to each rule type into a respective filtering unit, such that the filtering unit begins the filtering of packets for the rules assigned to the rule type with the fields of the rule type.