IP Library › Granted Patent US 12,267,355
Granted Patent B2
US 12,267,355 · App. 17/527,150 · Granted Apr 1, 2025

Systems and methods of detecting and responding to a ransomware attack impacting a cloud-based file storage service

Inventors: Sean Hittel (Calgary, CA); Krishna Narayanaswamy (Saratoga, CA); Ravindra K. Balupari (San Jose, CA); Ravi Ithal (Fremont, CA)
Assignee: Netskope, Inc.
H04L63/145G06F16/907G06F21/552G06F21/565H04L63/1433G06F21/566G06F2221/2101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,267,355
App. No.
17/527,150
Filed
Nov 15, 2021
Granted
Apr 1, 2025
Kind
B2
Art Unit
2434
USPC
726/23
Abstract

The technology disclosed relates to detecting a data attack on a file system stored on an independent data store. The detecting includes scanning a list to identify files of the independent data store that have been updated within a timeframe, assembling current metadata for files identified by the scanning, obtaining historical metadata of the files, determining that a malicious activity is in process by analyzing the current metadata of the files and the historical metadata to identify a pattern of changes that exceeds a predetermined change velocity. Further, the detecting includes determining that the malicious activity is in process by analyzing the current metadata of the files and known patterns of malicious metadata to identify a match between the current metadata and the known patterns of malicious metadata, determining a machine/user that initiated the malicious activity, and implementing a response mechanism that restricts file modifications by the determined machine/user.

Claims (100)

1. A method of detecting a ransomware attack impacting a cloud-based file storage service, the method comprising:

collecting metadata on files stored on the cloud-based file storage service, wherein:

the collecting the metadata comprises:

collecting a first portion of the metadata using an inspective agent of a proxy device through an application programming interface to the cloud-based file storage service; and

collecting a second portion of the metadata using a client agent installed locally on client devices that manipulate the files stored on the cloud-based file storage service,

the cloud-based file storage service supports manipulation by creating, editing, and sharing the files, and

the collected metadata includes at least one of an extension of a file name, a magic number, and a size;

storing the collected metadata as historical metadata in a historical metadata storage, wherein the historical metadata storage is separate from and not under control of the cloud-based file storage service;

detecting multiple artifacts of the ransomware attack resulting from ransomware manipulation of the files, the detecting including:

comparing at least one of the extension, the magic number and the size included in the historical metadata to respective at least one of the extension, the magic number and the size included in current metadata of the files to identify changes in the files,

detecting a pattern of the identified changes from the historical metadata to the current metadata, and

detecting that the identified changes in the detected pattern exceed a predetermined change velocity to determine that the ransomware attack is in progress;

identifying a user and/or client device of the client devices that manipulated the files exhibiting the multiple artifacts; and

responding to the determination that the ransomware attack is in progress, the responding comprising:

restricting further manipulation of other files on the cloud-based file storage service by the identified user and/or client device.

2. The method of claim 1 , wherein;

the collecting the metadata further comprises collecting a third a portion of the metadata using an active agent of the proxy device; and

the proxy device is positioned between the client devices and the cloud-based file storage service.

3. The method of claim 1 , wherein the responding further comprises:

notifying the user and/or client device that the ransomware attack is in progress; and

providing a location of the ransomware attack to the user and/or client device.

4. The method of claim 2 , wherein the responding further comprises:

isolating the cloud-based file storage service the isolating comprising:

disconnecting the identified user and/or client device from the cloud-based file storage service, and

disconnecting additional users who have access to the cloud-based file storage service; and

preventing the identified user and/or client device from accessing the cloud-based file storage service.

5. The method of claim 1 , wherein the responding further comprises at least one of performing a backup of the files and performing a backup of the cloud-based file storage service on which the files are stored.

6. The method of claim 1 , wherein the responding further comprises:

forcing the identified user and/or client device to perform a local scan for the ransomware attack;

forcing a scan for the ransomware attack on any other cloud-based file storage service for which the identified user and/or client device has access;

forcing additional users who have access to the cloud-based file storage service to perform the local scan for the ransomware attack; and

forcing a scan for the ransomware attack on any other cloud-based file storage service for which the additional users have access.

7. The method of claim 1 , wherein:

the responding further comprises restoring a previous backup of the cloud-based file storage service; and

the restoring of the previous backup is automated or performed with user interaction.

8. The method of claim 1 , wherein the responding further comprises:

determining a creator of a file having caused the ransomware attack to be initiated on the identified user and/or client device based on the current metadata and the historical metadata; and

identifying and performing a specific response mechanism of multiple response mechanisms based on the determined creator.

9. A method of detecting a ransomware attack impacting a cloud-based file storage service, the method comprising:

collecting content properties from payloads of files stored on the cloud-based file storage service, wherein;

the collecting the content properties comprises:

collecting a first portion of the content properties using an inspective agent of a proxy device through an application programming interface to the cloud-based file storage service; and

collecting a second portion of the content properties using a client agent installed locally on client devices that manipulate the files stored on the cloud-based file storage service,

the cloud-based file storage service supports manipulation by creating, editing, and sharing the files, and

the collected content properties include at least one of a computed entropy or layered entropy, a locality-sensitive hashing (LSH), and an indication of an occurrence of a stub;

storing the collected content properties as historical content properties in a historical content properties storage, wherein the historical content properties storage is separate from and not under control of the cloud-based file storage service;

detecting multiple artifacts of the ransomware attack resulting from ransomware manipulation of the files, the detecting including:

comparing at least one of the computed entropy or layered entropy, the LSH, and the indication of the occurrence of the stub included in the historical content properties to respective at least one of the computed entropy or layered entropy, the LSH, and the indication of the occurrence of the stub included in current content properties of the files to identify changes in the files,

detecting a pattern of the identified changes from the historical content properties to the current content properties, and

detecting that the identified changes in the detected pattern exceed a predetermined change velocity to determine that the ransomware attack is in progress;

identifying a user and/or client device of the client devices that manipulated the files exhibiting the multiple artifacts; and

responding to the determination that the ransomware attack is in progress, the responding comprising:

restricting further manipulation of other files on the cloud-based file storage service by the identified user and/or client device.

10. The method of claim 9 , wherein;

the collecting the content properties further comprises collecting a third portion of the content properties using an active agent of the proxy device; and

the proxy device is positioned between users and the cloud-based file storage service.

11. The method of claim 9 , wherein the identified changes in the detected pattern are identified by determining a hamming distance between the LSH for the current content properties and the LSH for the historical content properties.

12. The method of claim 9 , wherein the responding further comprises:

calculating an entropy of the payloads of the files;

comparing the entropy of the files with entropies of known user-initiated encryption techniques to determine whether or not the identified user and/or client device has implemented a user-initiated encryption technique;

identifying each of the files for which the identified user and/or client device has implemented the user-initiated encryption technique;

determining that the ransomware attack is in process by analyzing the current content properties of the files and the historical content properties of the files, excluding the files for which the identified user and/or client device has implemented the user-initiated encryption technique, to identify the pattern of the identified changes between the current content properties and the historical content properties of the files that exceeds a predetermined change velocity; and

determining that the ransomware attack is in process by analyzing (i) the current content properties of the files, excluding the files for which the identified user and/or client device has implemented the user-initiated encryption technique, and (ii) known patterns of malicious content properties that indicate a known malicious file modification to identify a match between the current content properties of the files, excluding the files for which the identified user and/or client device has implemented the user-initiated encryption technique, and the known patterns of malicious content properties.

13. A method of detecting a ransomware attack impacting a cloud-based file storage service, the method comprising:

collecting metadata on files stored on the cloud-based file storage service, wherein:

the collecting the metadata comprises:

collecting a first portion of the metadata using an inspective agent of a proxy device through an application programming interface to the cloud-based file storage service; and

collecting a second portion of the metadata using a client agent installed locally on client devices that manipulate the files stored on the cloud-based file storage service,

the cloud-based file storage service supports manipulation by creating, editing, and sharing the files, and

the collected metadata includes at least one of an extension of a file name, a magic number, and a size;

storing the collected metadata as historical metadata in a historical metadata storage, wherein the historical metadata storage is separate from and not under control of the cloud-based file storage service;

detecting multiple artifacts of the ransomware attack resulting from ransomware manipulation of the files, the detecting including:

determining whether (i) the historical metadata exists for the files and (ii) a pattern of current metadata of the files exceeds a predetermined threshold, and

determining that the ransomware attack is in progress when (i) the historical metadata does not exist for the files and (ii) the pattern of current metadata of the files exceeds the predetermined threshold;

identifying a user and/or client device of the client devices that manipulated the files exhibiting the multiple artifacts; and

responding to the detection of the ransomware attack, the responding comprising:

restricting further manipulation of other files on the cloud-based file storage service by the identified user and/or client device.

14. The method of claim 13 , wherein;

the collecting the metadata further comprises collecting a third portion of the metadata using an active agent of the proxy device; and

the proxy device is positioned between the client devices and the cloud-based file storage service.

15. The method of claim 13 , wherein the responding further comprises:

notifying the user and/or client device that the ransomware attack is in progress; and

providing a location of the ransomware attack to the user and/or client device.

16. The method of claim 13 , wherein the responding further comprises:

isolating the cloud-based file storage service the isolating comprising:

disconnecting the identified user and/or client device from the cloud-based file storage service, and

disconnecting additional users who have access to the cloud-based file storage service; and

preventing the identified user and/or client device from accessing the cloud-based file storage service.

17. The method of claim 13 , wherein the responding further comprises at least one of performing a backup of the files and performing a backup of the cloud-based file storage service on which the files are stored.

18. The method of claim 13 , wherein the responding further comprises:

forcing the identified user and/or client device to perform a local scan for the ransomware attack;

forcing a scan for the ransomware attack on any other cloud-based file storage service for which the identified user and/or client device has access;

forcing additional users who have access to the cloud-based file storage service to perform the local scan for the ransomware attack; and

forcing a scan for the ransomware attack on any other cloud-based file storage service for which the additional users have access.

19. The method of claim 13 , wherein:

the responding further comprises restoring a previous backup of the cloud-based file storage service; and

the restoring of the previous backup is automated or performed with user interaction.

20. The method of claim 13 , wherein the responding further comprises:

determining a creator of a file having caused the ransomware attack to be initiated on the identified user and/or client device based on the current metadata and the historical metadata; and

identifying and performing a specific response mechanism of multiple response mechanisms based on the determined creator.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 7, 2024
From: HITTEL, SEAN; NARAYANASWAMY, KRISHNA; BALUPARI, RAVINDRA K.; ITHAL, RAVI
To: NETSKOPE, INC.
Reel/Frame 066408/0033 →
Continuity (4)
Continuation 16679020 · Nov 8, 2019
Continuation 15628547 · Jun 20, 2017
Provisional Application 62373288 · Aug 10, 2016
Related Publication 20220150262A1 · May 12, 2022
References Cited (160)
US 5440723A · Arnold et al. · 1995 [cited by applicant]
US 5452460A · Distelberg et al. · 1995 [cited by applicant]
US 6513122B1 · Magdych et al. · 2003 [cited by applicant]
US 6622248B1 · Hirai · 2003 [cited by applicant]
US 7080408B1 · Pak et al. · 2006 [cited by applicant]
US 7298864B2 · Jones · 2007 [cited by applicant]
US 7376719B1 · Shafer et al. · 2008 [cited by applicant]
US 7735116B1 · Gauvin · 2010 [cited by applicant]
US 7966654B2 · Crawford · 2011 [cited by applicant]
US 8000329B2 · Fendick et al. · 2011 [cited by applicant]
US 8296178B2 · Hudis et al. · 2012 [cited by applicant]
US 8346580B2 · Nakfoor · 2013 [cited by applicant]
US 8365243B1 · Lu et al. · 2013 [cited by applicant]
US 8677448B1 · Kauffman et al. · 2014 [cited by applicant]
US 8793151B2 · DelZoppo et al. · 2014 [cited by applicant]
US 8839417B1 · Jordan · 2014 [cited by applicant]
US 8856869B1 · Brinskelle · 2014 [cited by applicant]
US 9069955B2 · Dolph et al. · 2015 [cited by applicant]
US 9197601B2 · Pasdar · 2015 [cited by applicant]
US 9197628B1 · Hastings · 2015 [cited by applicant]
US 9225734B1 · Hastings · 2015 [cited by applicant]
US 9231968B2 · Fang et al. · 2016 [cited by applicant]
US 9246944B1 · Chen · 2016 [cited by applicant]
US 9280678B2 · Redberg · 2016 [cited by applicant]
US 9317686B1 · Ye · 2016 [cited by examiner]
US 9692759B1 · Chandrasekhar · 2017 [cited by applicant]
US 9811662B2 · Sharpe et al. · 2017 [cited by applicant]
US 9917817B1 · Lad et al. · 2018 [cited by applicant]
US 10084825B1 · Xu · 2018 [cited by applicant]
US 10162767B2 · Spurlock et al. · 2018 [cited by applicant]
US 10237282B2 · Nelson et al. · 2019 [cited by applicant]
US 10248797B1 · Shinde et al. · 2019 [cited by applicant]
US 10334442B2 · Vaughn et al. · 2019 [cited by applicant]
US 10382468B2 · Dods · 2019 [cited by applicant]
US 10484334B1 · Lee et al. · 2019 [cited by applicant]
US 10826941B2 · Jain et al. · 2020 [cited by applicant]
US 10860730B1 · Weaver et al. · 2020 [cited by applicant]
US 11032301B2 · Mandrychenko et al. · 2021 [cited by applicant]
US 11036856B2 · Graun et al. · 2021 [cited by applicant]
US 11089064B1 · Sarukkai et al. · 2021 [cited by applicant]
US 11281775B2 · Burdett et al. · 2022 [cited by applicant]
US 20020099666A1 · Dryer et al. · 2002 [cited by applicant]
US 20030055994A1 · Herrmann et al. · 2003 [cited by applicant]
US 20030063321A1 · Inoue et al. · 2003 [cited by applicant]
US 20030172292A1 · Judge · 2003 [cited by applicant]
US 20030204632A1 · Willebeek-Lemair et al. · 2003 [cited by applicant]
US 20040015719A1 · Lee et al. · 2004 [cited by applicant]
US 20050010593A1 · Fellenstein et al. · 2005 [cited by applicant]
US 20050271246A1 · Sharma et al. · 2005 [cited by applicant]
US 20060156401A1 · Newstadt et al. · 2006 [cited by applicant]
US 20070006293A1 · Balakrishnan et al. · 2007 [cited by applicant]
US 20070204018A1 · Chandra et al. · 2007 [cited by applicant]
US 20070237147A1 · Quinn et al. · 2007 [cited by applicant]
US 20080047013A1 · Claudatos · 2008 [cited by examiner]
US 20080069480A1 · Aarabi et al. · 2008 [cited by applicant]
US 20080134332A1 · Keohane et al. · 2008 [cited by applicant]
US 20090144818A1 · Kumar et al. · 2009 [cited by applicant]
US 20090249470A1 · Litvin et al. · 2009 [cited by applicant]
US 20090300351A1 · Lei et al. · 2009 [cited by applicant]
US 20100017436A1 · Wolge · 2010 [cited by applicant]
US 20100251369A1 · Grant · 2010 [cited by applicant]
US 20110119481A1 · Auradkar et al. · 2011 [cited by applicant]
US 20110145594A1 · Jho et al. · 2011 [cited by applicant]
US 20110321170A1 · Onodera et al. · 2011 [cited by applicant]
US 20120278896A1 · Fang et al. · 2012 [cited by applicant]
US 20130145483A1 · Dimuro et al. · 2013 [cited by applicant]
US 20130159694A1 · Chiueh et al. · 2013 [cited by applicant]
US 20130298190A1 · Sikka et al. · 2013 [cited by applicant]
US 20130347085A1 · Hawthorn et al. · 2013 [cited by applicant]
US 20140007182A1 · Qureshi et al. · 2014 [cited by applicant]
US 20140013112A1 · Cidon et al. · 2014 [cited by applicant]
US 20140026182A1 · Pearl et al. · 2014 [cited by applicant]
US 20140068030A1 · Chambers et al. · 2014 [cited by applicant]
US 20140068705A1 · Chambers et al. · 2014 [cited by applicant]
US 20140259093A1 · Narayanaswamy et al. · 2014 [cited by applicant]
US 20140259190A1 · Kiang et al. · 2014 [cited by applicant]
US 20140269279A1 · Ismail et al. · 2014 [cited by applicant]
US 20140282843A1 · Buruganahalli et al. · 2014 [cited by applicant]
US 20140317681A1 · Shende · 2014 [cited by applicant]
US 20140337862A1 · Valencia et al. · 2014 [cited by applicant]
US 20140344573A1 · Tsai et al. · 2014 [cited by applicant]
US 20140359282A1 · Shikfa et al. · 2014 [cited by applicant]
US 20140366079A1 · Pasdar · 2014 [cited by applicant]
US 20140380491A1 · Abuelsaad et al. · 2014 [cited by applicant]
US 20150074744A1 · McLean et al. · 2015 [cited by applicant]
US 20150100357A1 · Seese et al. · 2015 [cited by applicant]
US 20150135302A1 · Cohen et al. · 2015 [cited by applicant]
US 20150271207A1 · Jaiswal et al. · 2015 [cited by applicant]
US 20160275577A1 · Kolluri Venkata Sesha et al. · 2016 [cited by applicant]
US 20160323318A1 · Terrill et al. · 2016 [cited by applicant]
US 20160350145A1 · Botzer et al. · 2016 [cited by applicant]
US 20170064005A1 · Lee · 2017 [cited by applicant]
US 20170093917A1 · Chandra et al. · 2017 [cited by applicant]
US 20170250951A1 · Wang et al. · 2017 [cited by applicant]
US 20170286696A1 · Shetty et al. · 2017 [cited by applicant]
US 20170353496A1 · Pai et al. · 2017 [cited by applicant]
US 20170359725A1 · Bolte · 2017 [cited by examiner]
US 20180034835A1 · Iwanir · 2018 [cited by examiner]
US 20180324204A1 · McClory et al. · 2018 [cited by applicant]
US 20200050686A1 · Kamalapuram et al. · 2020 [cited by applicant]
US 20200372040A1 · Boehmann et al. · 2020 [cited by applicant]
US 20210367976A1 · Khurshid et al. · 2021 [cited by applicant]
EP 1063833A2 · 2000 [cited by applicant]
JP 2011234178A · 2011 [cited by applicant]
Scaife et al “Cryptolock and Drop It: Stopping Ransomware Attacks on User Data”, Jun. 2016, IEEE 36th International conference on Distributed Computing Systems. (Year: 2016). [cited by examiner]
“Cloud Data Loss Prevention Reference Architecture”, Netskope, Sep. 2015, WP-88-1, 2 pages. [cited by applicant]
“Data Breach: The Cloud Multiplier Effect”, Ponemon Institute, Jun. 4, 2014, 27 pages. [cited by applicant]
“Netskope Introspection,” netSkope, Inc., 2015, 3 pgs. [cited by applicant]
“Netskope the 15 Critical CASB Use Cases”, Netskope Inc., EB-141-1, dated 2015, 19 pages. [cited by applicant]
“The Netskope Active Platform Enabling Safe Migration to the Cloud”, Apr. 2015, DS-1-8, Netskope, Inc., 6 pages. [cited by applicant]
“The Netskope Advantage: Three “Must-Have” Requirements for Cloud Access Security Brokers”, Jul. 2015, WP-12-2 1 pages. [cited by applicant]
Cheng et al., “Cloud Security for Dummies, Netskope Special Edition,” John Wiley & Sons, Inc., dated 2015, 53 pages. [cited by applicant]
Kark et al, “Trends: Calculating the Cost of a Security Breach”, Forrester Research, Inc. Apr. 10, 2007, 7 pgs. [cited by applicant]
Liu et al., Data Loss Prevention, IT Professional, vol. 12, Issue 2, IEEE, Mar. 29, 2010, pp. 10-13. [cited by applicant]
Netskope, “The 5 Steps to Cloud Confidence”, Version 2, Jan. 29, 2014, 10 pages. [cited by applicant]
Oasis, Key Management Interoperability Protocols Use Cases Version 1.2, dated Mar. 18, 2013, 132 pages. [cited by applicant]
Pandire et al., Attack Detection in Cloud Virtual Environment and Prevention using Honeypot, International Conference in Inventive Research in Computing Applications {ICIRCA), IEEE, Jul. 11-12, 2018, pp. 515-520. [cited by applicant]
Office Action in U.S. Appl. No. 17/537,433, mailed Mar. 1, 2024, 23 pages. [cited by applicant]
Martin, Victoria “Cooperative Security Fabric,” The Fortinet Cookbook, Jun. 8, 2016, 6 pgs., archived Jul. 28, 2016 at https://web.archive.org/web/20160728170025/http://cookbook.fortinet.com/cooperative-security-fabric-… [cited by applicant]
Huckaby, Jeff “Ending Clear Text Protocols,” Rackaid.com, Dec. 9, 2008, 3 pgs. [cited by applicant]
Newton, Harry “fabric,” Newton's Telecom Dictionary, 30th Updated, Expanded, Anniversary Edition, 2016, 3 pgs. [cited by applicant]
Fortinet, “Fortinet Security Fabric Earns 100% Detection Scores Across Several Attack Vectors in NSS Labs' Latest Breach Detection Group Test [press release]”, Aug. 2, 2016, 4 pgs, available at https://www.fortinet.com/… [cited by applicant]
Fortinet, “Fortinet Security Fabric Named 2016 CRN Network Security Product of the Year [press release]”, Dec. 5, 2016, 4 pgs, available at https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2016/fortin… [cited by applicant]
McCullagh, Declan, “How safe is instant messaging? A security and privacy survey,” CNET, Jun. 9, 2008, 14 pgs. [cited by applicant]
Beck et al., “IBM and Cisco: Together for a World Class Data Center,” IBM Redbooks, Jul. 2013, 654 pgs. [cited by applicant]
Martin, Victoria “Installing internal FortiGates and enabling a security fabric,” The Fortinet Cookbook, Jun. 8, 2016, 11 pgs, archived Aug. 28, 2016 at https://web.archive.org/web/20160828235831/http://cookbook.fortine… [cited by applicant]
Zetter, Kim, “Revealed: The Internet's Biggest Security Hole,” Wired, Aug. 26, 2008, 13 pgs. [cited by applicant]
Adya et al., “Farsite: Federated, available, and reliable storage for an incompletely trusted environment,” SIGOPS Oper. Syst. Rev. 36, SI, Dec. 2002, pp. 1-14. [cited by applicant]
Agrawal et al., “Order preserving encryption for numeric data,” In Proceedings of the 2004 Acm Sigmod international conference on Management of data, Jun. 2004, pp. 563-574. [cited by applicant]
Balakrishnan et al., “A layered naming architecture for the Internet,” Acm Sigcomm Computer Communication Review, 34(4), 2004, pp. 343-352. [cited by applicant]
Downing et al., Naming Dictionary of Computer and Internet Terms, (11th Ed.) Barron's, 2013, 6 pgs. [cited by applicant]
Downing et al., Dictionary of Computer and Internet Terms, (10th Ed.) Barron's, 2009, 4 pgs. [cited by applicant]
Zoho Mail, “Email Protocols: What they are & their different types,” 2006, 7 pgs. available at https://www.zoho.com/mail/glossary/email-protocols.html# :˜:text=mode of communication.-, What are the different email proto… [cited by applicant]
NIIT, Special Edition Using Storage Area Networks, Que, 2002, 6 pgs. [cited by applicant]
Chapple, Mike, “Firewall redundancy: Deployment scenarios and benefits,” TechTarget, 2005, 5 pgs. available at https://www.techtarget.com/searchsecurity/tip/Firewall-redundancy-Deployment-scenarios-and-benefits? Offer=a… [cited by applicant]
Fortinet, FortiGate—3600 User Manual (vol. 1, Version 2.50 MR2) Sep. 5, 2003, 329 pgs. [cited by applicant]
Fortinet, FortiGate SOHO and SMB Configuration Example, (Version 3.0 MR5), Aug. 24, 2007, 54 pgs. [cited by applicant]
Fortinet, FortiSandbox—Administration Guide, (Version 2.3.2), Nov. 9, 2016, 191 pgs. [cited by applicant]
Fortinet, FortiSandbox Administration Guide, (Version 4.2.4) Jun. 12, 2023, 245 pgs. available at https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/fba32b46-b7c0-11ed-8e6d-fa163e15d75b/FortiSandbox-4… [cited by applicant]
Fortinet, FortiOS—Administration Guide, (Versions 6.4.0), Jun. 3, 2021, 1638 pgs. [cited by applicant]
Heady et al., “The Architecture of a Network Level Intrusion Detection System,” University of New Mexico, Aug. 15, 1990, 21 pgs. [cited by applicant]
Kephart et al., “Fighting Computer Viruses,” Scientific American (vol. 277, No. 5) Nov. 1997, pp. 88-93. [cited by applicant]
Wang, L., Chapter 5: Cooperative Security in D2D Communications, “Physical Layer Security in Wireless Cooperative Networks,” 41 pgs. first online on Sep. 1, 2017 at https://link.springer.com/chapter/10.1007/978-3-319-61… [cited by applicant]
Lee et al., “A Data Mining Framework for Building Intrusion Detection Models,” Columbia University, n.d. 13 pgs. [cited by applicant]
Merriam-Webster Dictionary, 2004, 5 pgs. [cited by applicant]
Microsoft Computer Dictionary, (5th Ed.), Microsoft Press, 2002, 8 pgs. [cited by applicant]
Microsoft Computer Dictionary, (4th Ed.), Microsoft Press, 1999, 5 pgs. [cited by applicant]
Mika et al., “Metadata Statistics for a Large Web Corpus,” LDOW2012, Apr. 16, 2012, 6 pgs. [cited by applicant]
Oxford Dictionary of Computing (6th Ed.), 2008, 5 pgs. [cited by applicant]
Paxson, Vern, “Bro: a System for Detecting Network Intruders in Real-Time,” Proceedings of the 7th USENIX Security Symposium, Jan. 1998, 22 pgs. [cited by applicant]
Fortinet Inc., U.S. Appl. No. 62/503,252, “Building a Cooperative Security Fabric of Hierarchically Interconnected Network Security Devices.” n.d., 87 pgs. [cited by applicant]
Song et al., “Practical techniques for searches on encrypted data,” In Proceeding 2000 IEEE symposium on security and privacy. S&P. 2000, May 2000, pp. 44-55. [cited by applicant]
Dean, Tamara, Guide to Telecommunications Technology, Course Technology, 2003, 5 pgs. [cited by applicant]
U.S. Appl. No. 60/520,577, “Device, System, and Method for Defending a Computer Network,” Nov. 17, 2003, 21 pgs. [cited by applicant]
U.S. Appl. No. 60/552,457, “Fortinet Security Update Technology,” Mar. 2004, 6 pgs. [cited by applicant]
Tittel, Ed, Unified Threat Management For Dummies, John Wiley & Sons, Inc., 2012, 76 pgs. [cited by applicant]
Fortinet, FortiOS Handbook: UTM Guide (Version 2), Oct. 15, 2010, 188 pgs. [cited by applicant]
Full Definition of Security, Wayback Machine Archive of Merriam-Webster on Nov. 17, 2016, 1 pg. [cited by applicant]
Definition of Cooperative, Wayback Machine Archive of Merriam-Webster on Nov. 26, 2016, 1 pg. [cited by applicant]
Pfaffenberger, Bryan, Webster's New World Computer Dictionary, (10th Ed.), 2003, 5 pgs. [cited by applicant]