Packet and intrusion rule latency threshold configuration

Packet and intrusion rule latency threshold configuration is a performance management mechanism that

  • uses thresholding to manage packet and rule processing performance in access control policies,

  • measures elapsed time for packet and rule processing operations, and

  • implements protective actions when configurable time thresholds are exceeded.

Processing mechanisms

This configuration includes two distinct processing mechanisms:

  • Packet latency thresholding: Measures the total elapsed time taken to process a packet by applicable decoders, preprocessors, and rules, and ceases inspection of the packet if the processing time exceeds a configurable threshold.

  • Rule latency thresholding: Measures the elapsed time each rule takes to process an individual packet, suspends the violating rule along with a group of related rules for a specified time if the processing time exceeds the rule latency threshold a configurable consecutive number of times, and restores the rules when the suspension expires.