A method and apparatus for storing an intrusion rule are provided. The
method stores a new intrusion rule in an intrusion detection system
having already stored intrusion rules, and includes: generating
combinations of divisions capable of dividing the new intrusion rule into
a plurality of partial intrusion rules; calculating the frequency of hash
value collisions between each of the generated division combinations and
the already stored intrusion rules; dividing the new intrusion rule
according to the division combination which has the lowest calculated
frequency of hash value collisions; and storing the divided new intrusion
rule in a corresponding position of the intrusion detection system.
According to the method and apparatus, the size of the storage unit
occupied by the intrusion rule can be reduced, and by performing pattern
matching, the performance of the intrusion detection system can be
enhanced.