Pattern detection

US9342709B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9342709-B2
Application numberUS-201013876586-A
CountryUS
Kind codeB2
Filing dateOct 27, 2010
Priority dateOct 27, 2010
Publication dateMay 17, 2016
Grant dateMay 17, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Data is moved through a pipeline as processing of the data unrelated to detection of pattern is performed. The detector detects the pattern within the data at a predetermined location or based on a predetermined reference as the data is moved through the pipeline, in parallel with the processing of the data as the data is moved through the pipeline. The detector detects the pattern within the data as the data is moved through the pipeline without delaying movement of the data into, through, and out of the pipeline.

First claim

Opening claim text (preview).

We claim: 1. A device, comprising: a pipeline implemented at least in hardware, through which data is moved to perform processing of the data unrelated to pattern detection; and a detector implemented at least in hardware, to: detect a first pattern at a first location within the data, in parallel with the processing of the data as the data is moved through the pipeline and without delaying movement of the data through the pipeline; access a reference parameter that specifies a location that is relative to a location of the first pattern; determine a second location based on the reference parameter and the information identifying the first location; and detect a second pattern at the determined second location in the data. 2. The device of claim 1 , further comprising: a storage to store the first pattern and a bitmask associated with the first pattern, the bitmask identifying do-not-care bits of the associated first pattern, wherein the detector is to detect the first pattern based on bits other than the do-not-care bits. 3. The device of claim 1 , wherein the detector is to store, in response to detecting the second pattern, information identifying the second location of the second pattern. 4. The device of claim 3 , wherein the detector is to store packet identifying information identifying a packet when the first pattern was detected. 5. The device of claim 1 , wherein the detector includes logic to perform an operation based on the detection of the first pattern and the detection of the second pattern. 6. The device of claim 1 , wherein the processing of the data performed in parallel with the detecting of the first pattern includes modifying a network address of the data. 7. The device of claim 1 , further comprising: a storage to store the information identifying the first location in response to the detecting of the first pattern, the storage to further store the reference parameter and a further reference parameter providing an indication of a starting point in the data to look for the first pattern. 8. The device of claim 7 , wherein the further reference parameter indicates the starting point in a header of a data packet to look for the first pattern. 9. The device of claim 1 , wherein the data includes a data packet, and wherein the detecting of the first pattern and the detecting of the second pattern are performed in the data packet. 10. A method, comprising: detecting, by a detector implemented at least in hardware, a first pattern within input data in a pipeline, the detecting being performed in parallel with processing of the input data as the input data is moved through the pipeline and without delaying movement of the input data into, through and out of the pipeline; in response to the detecting, storing information identifying a first location of the first pattern in the input data; accessing, by the detector, a reference parameter that specifies a location in data that is relative to a location of the first pattern; determining, by the detector, a second location based on the reference parameter and the information identifying the first location; and detecting, by the detector, a second pattern at the determined second location in the input data. 11. The method of claim 10 , further comprising accessing, by the detector, a further reference parameter indicating a location in the input data to look for the first pattern, the indicated location located in a header of a data packet. 12. The method of claim 11 , further comprising: associating with the first pattern a starting point in relation to the location indicated by the further reference parameter and a stopping point in relation to the starting point to identify a window of data where the detector is to look for the first pattern. 13. The method of claim 10 , further comprising: performing a logical operation based on the detection of the first pattern and the second pattern. 14. The device of claim 9 , wherein the detector is to indicate detection of at least one of a virus, a trojan, a worm, or spam in response to the detecting of the first pattern and the second pattern in the data packet. 15. The method of claim 10 , wherein the processing of the input data performed in parallel with the detecting of the first pattern includes modifying a network address of the input data. 16. The method of claim 10 , wherein the input data includes a data packet, and wherein the detecting of the first pattern and the detecting of the second pattern are performed in the data packet. 17. The method of claim 16 , further comprising: indicating detection of at least one of a virus, a trojan, a worm, or spam in response to detecting of the first pattern and the second pattern in the data packet. 18. A device, comprising: a storage device to store a plurality of patterns having a length of a predetermined number of bytes; and a plurality of parameters, associated with the plurality of patterns, each of the plurality of parameters including a reference, a start and a stop identifying where to detect the associated each of the plurality of patterns; and a plurality of correlators implemented in hardware and equal in number to a number of bytes of each row of a plurality of rows of a pipeline, each correlator is to provide a number of bytes of data that have been matched to one or more of the plurality of patterns, and each correlator having a unique offset to detect one or more of the plurality of patterns beginning at a different starting byte position of data within a given row of the pipeline; and wherein one of the plurality of patterns is indicated as having been detected within the data based on the number of bytes of the data that have been matched to the respective pattern by each correlator. 19. The device of claim 18 , wherein the reference identifies one of a plurality of layer headers, a packet payload, and a match location of a second one of the plurality of patterns, and wherein the start represents a starting point in a packet in relation to the reference, and the stop represents a stopping point in relation to the starting point to identify a window of bytes where each of the plurality of patterns may be detected. 20. The device of claim 19 , further including logic to perform an operation based on the detected patterns.

Assignees

Inventors

Classifications

  • Electricity · mapped topic

  • Monitoring · CPC title

  • Error detection; Error correction; Monitoring (error detection, correction or monitoring in information storage based on relative movement between record carrier and transducer G11B20/18; monitoring, i.e. supervising the progress of recording or reproducing G11B27/36; in static stores G11C29/00) · CPC title

  • the encryption apparatus using shift registers or memories for block-wise {or stream} coding, e.g. DES systems {or RC4; Hash functions; Pseudorandom sequence generators} · CPC title

  • Parsing or analysis of headers · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9342709B2 cover?
Data is moved through a pipeline as processing of the data unrelated to detection of pattern is performed. The detector detects the pattern within the data at a predetermined location or based on a predetermined reference as the data is moved through the pipeline, in parallel with the processing of the data as the data is moved through the pipeline. The detector detects the pattern within the d…
Who is the assignee on this patent?
Warren David A, Lavigne Bruce E, Hewlett Packard Entpr Dev Lp
What technology area does this patent fall under?
Primary CPC classification H04L63/1416. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue May 17 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).