Packet and intrusion rule latency threshold configuration
Packet and intrusion rule latency threshold configuration is a performance management mechanism that
-
uses thresholding to manage packet and rule processing performance in access control policies,
-
measures elapsed time for packet and rule processing operations, and
-
implements protective actions when configurable time thresholds are exceeded.
Processing mechanisms
This configuration includes two distinct processing mechanisms:
-
Packet latency thresholding: Measures the total elapsed time taken to process a packet by applicable decoders, preprocessors, and rules, and ceases inspection of the packet if the processing time exceeds a configurable threshold.
-
Rule latency thresholding: Measures the elapsed time each rule takes to process an individual packet, suspends the violating rule along with a group of related rules for a specified time if the processing time exceeds the rule latency threshold a configurable consecutive number of times, and restores the rules when the suspension expires.