IP Library › Granted Patent US 12,284,206
Granted Patent B2
US 12,284,206 · App. 17/537,433 · Granted Apr 22, 2025

Systems and methods of detecting and responding to ransomware on a cloud-based file storage system by identifying a volume of changes in the files stored on the cloud-based file storage system

Inventors: Sean Hittel (Calgary, CA); Krishna Narayanaswamy (Saratoga, CA); Ravindra K. Balupari (San Jose, CA); Ravi Ithal (Fremont, CA)
Assignee: Netskope, Inc.
H04L63/145G06F16/907G06F21/552G06F21/565H04L63/1433G06F21/566G06F2221/2101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,284,206
App. No.
17/537,433
Granted
Apr 22, 2025
Kind
B2
Abstract

The technology disclosed relates to detecting a ransomware attack on a cloud-based file storage system. The detecting includes collecting metadata on files at they are manipulated, storing the collected metadata as historical metadata, detecting multiple artifacts of the ransomware attack resulting from ransomware manipulation of the files by (i) comparing at least one of the extension, the magic number and the size included in the historical metadata to at least one of the extension, the magic number and the size included in current metadata of the files to identify a volume of changes in the files, and (ii) detecting that the identified volume of changes exceeds a change volume to determine that the ransomware attack is in progress, and identifying a user/machine that manipulated the files and responding to the determination that the ransomware attack is in progress by restricting further manipulation of other files by the identified user/machine.

Claims (97)

1. A method of detecting a ransomware attack impacting a cloud-based file storage service, the method comprising:

collecting metadata on files stored on the cloud-based file storage service, wherein:

the collecting the metadata comprises:

collecting a first portion of the metadata using an inspective agent of a proxy device through an application programming interface to the cloud-based file storage service; and

collecting a second portion of the metadata using a client agent installed locally on client devices that manipulate the files stored on the cloud-based file storage service,

the cloud-based file storage service supports manipulation by creating, editing, and sharing the files, and

the collected metadata includes at least one of an extension of a file name, a magic number, and a size;

storing the collected metadata as historical metadata in a historical metadata storage, wherein the historical metadata storage is separate from and not under control of the cloud-based file storage service;

detecting multiple artifacts of the ransomware attack resulting from ransomware manipulation of the files, the detecting including:

comparing at least one of the extension, the magic number and the size included in the historical metadata to at least one of the extension, the magic number and the size included in current metadata of the files to identify a volume of changes in the files, and

detecting that the identified volume of changes exceeds a predetermined change volume to determine that the ransomware attack is in progress;

identifying a user and/or client device of the client devices that manipulated the files exhibiting the multiple artifacts; and

responding to the determination that the ransomware attack is in progress, wherein the responding comprises:

restricting further manipulation of other files on the cloud-based file storage service by the identified user and/or client device.

2. The method of claim 1 , wherein;

the collecting the metadata further comprises collecting a third portion of the metadata using an active agent of the proxy device; and

the proxy device is positioned between the client devices and the cloud-based file storage service.

3. The method of claim 1 , wherein the responding further comprises:

notifying the user and/or client device that the ransomware attack was detected; and

providing a location of the ransomware attack to the user and/or client device.

4. The method of claim 1 , wherein the responding further comprises:

isolating the cloud-based file storage service, the isolating comprising:

disconnecting the identified user and/or client device from the cloud-based file storage service, and

disconnecting additional users who have access to the cloud-based file storage service; and

preventing the identified user and/or client device from accessing the cloud-based file storage service.

5. The method of claim 1 , wherein the responding further comprises at least one of performing a backup of the files and performing a backup of the cloud-based file storage service on which the files are stored.

6. The method of claim 1 , wherein the responding further comprises:

forcing the identified user and/or client device to perform a local scan for the ransomware attack; forcing a scan for the ransomware attack on any other cloud-based file storage service for which the identified user and/or client device has access;

forcing additional users who have access to the cloud-based file storage service to perform the local scan for the ransomware attack; and

forcing a scan for the ransomware attack on any other cloud-based file storage service for which the additional users have access.

7. The method of claim 1 , wherein:

the responding further comprises restoring a previous backup of the cloud-based file storage service; and

the restoring of the previous backup is automated or performed with user interaction.

8. The method of claim 1 , wherein the responding further comprises:

determining a creator of a file having caused the ransomware attack to be initiated on the identified user and/or client device based on the current metadata and the historical metadata; and

identifying and performing a specific response mechanism of multiple response mechanisms based on the determined creator.

9. A method of detecting a ransomware attack impacting a cloud-based file storage service, the method comprising:

collecting content properties from payloads of files stored on the cloud-based file storage service, wherein:

the collecting the content properties comprises:

collecting a first portion of the content properties using an inspective agent of a proxy device through an application programming interface to the cloud-based file storage service; and

collecting a second portion of the content properties using a client agent installed locally on client devices that manipulate the files stored on the cloud-based file storage service,

the cloud-based file storage service supports manipulation by creating, editing, and sharing the files, and

the collected content properties include at least one of a computed entropy or layered entropy, a locality-sensitive hashing (LSH), and an indication of an occurrence of a stub;

storing the collected content properties as historical content properties in a historical content properties storage, wherein the historical content properties storage is separate from and not under control of the cloud-based file storage service;

detecting multiple artifacts of the ransomware attack resulting from ransomware manipulation of the files, the detecting including:

comparing at least one of the computed entropy or layered entropy, the LSH, and the indication of the occurrence of the stub included in the historical content properties to respective at least one of the computed entropy or layered entropy, the LSH, and the indication of the occurrence of the stub included in current content properties of the files to identify a volume of changes in the files, and

detecting that the identified volume of changes exceeds a predetermined change volume to determine that the ransomware attack is in progress;

identifying a user and/or client device of the client devices that manipulated the files exhibiting the multiple artifacts; and

responding to the determination that the ransomware attack is in progress, the responding comprising:

restricting further manipulation of other files on the cloud-based file storage service by the identified user and/or client device.

10. The method of claim 9 , wherein:

the collecting the content properties further comprises collecting a third portion of the content properties using an active agent of the proxy device; and

the proxy device is positioned between the client devices and the cloud-based file storage service.

11. The method of claim 9 , wherein the identified volume of changes are identified by determining a hamming distance between the LSH for the current content properties and the LSH for the historical content properties.

12. The method of claim 9 , wherein the responding further comprises:

calculating an entropy of the payloads of the files;

comparing the entropy of the payloads of the files with entropies of known user-initiated encryption techniques to determine whether or not the identified user and/or client device has implemented a user-initiated encryption technique;

identifying each of the files for which the identified user and/or client device has implemented the user-initiated encryption technique;

determining that the ransomware attack is in process by analyzing the current content properties of the files and the historical content properties of the files, excluding the files for which the identified user and/or client device has implemented the user-initiated encryption technique, to identify the volume of changes between the current content properties and the historical content properties of the files that exceeds the predetermined change volume; and

determining that the ransomware attack is in process by analyzing (i) the current content properties of the files, excluding the files for which the identified user and/or client device has implemented the user-initiated encryption technique, and (ii) known patterns of malicious content properties that indicate a known malicious file modification to identify a match between the current content properties of the files, excluding the files for which the identified user and/or client device has implemented the user-initiated encryption technique, and the known patterns of malicious content properties.

13. A method of detecting a ransomware attack impacting a cloud-based file storage service, the method comprising:

collecting metadata on files stored on the cloud-based file storage service, wherein:

the collecting the metadata comprises:

collecting a first portion of the metadata using an inspective agent of a proxy device through an application programming interface to the cloud-based file storage service; and

collecting a second portion of the metadata using a client agent installed locally on client devices that manipulate the files stored on the cloud-based file storage service,

the cloud-based file storage service supports manipulation by creating, editing, and sharing the files, and

the collected metadata includes at least one of an extension of a file name, a magic number, and a size;

storing the collected metadata as historical metadata in a historical metadata storage, wherein the historical metadata storage is separate from and not under control of the cloud-based file storage service;

detecting multiple artifacts of the ransomware attack resulting from ransomware manipulation of the files, the detecting including:

determining whether the historical metadata exists for the files and a pattern of current metadata for the files, and

determining that the ransomware attack is in progress when (i) the historical metadata does not exist for one or more of the files and (ii) the pattern of the current metadata of the one or more of the files corresponds to a known pattern of malicious metadata;

identifying a user and/or client device of the client devices that manipulated the files exhibiting the multiple artifacts; and

responding to the detection of the ransomware attack, the responding comprising:

restricting further manipulation of other files on the cloud-based file storage service by the identified user and/or client device.

14. The method of claim 13 , wherein the responding further comprises:

notifying the user and/or client device that the ransomware attack is in progress; and

providing a location of the ransomware attack to the user and/or client device.

15. The method of claim 13 , wherein the responding further comprises:

isolating the cloud-based file storage service the isolating comprising:

disconnecting the identified user and/or client device from the cloud-based file storage service, and

disconnecting additional users who have access to the cloud-based file storage service; and

preventing the identified user and/or client device from accessing the cloud-based file storage service.

16. The method of claim 13 , wherein the responding further comprises at least one of performing a backup of the files and performing a backup of the cloud-based file storage service on which the files are stored.

17. The method of claim 13 , wherein the responding further comprises:

forcing the identified user and/or client device to perform a local scan for the ransomware attack;

forcing a scan for the ransomware attack on any other cloud-based file storage service for which the identified user and/or client device has access;

forcing additional users who have access to the cloud-based file storage service to perform the local scan for the ransomware attack; and

forcing a scan for the ransomware attack on any other cloud-based file storage service for which the additional users have access.

18. The method of claim 13 , wherein:

the responding further comprises restoring a previous backup of the cloud-based file storage service; and

the restoring of the previous backup is automated or performed with user interaction.

19. The method of claim 13 , wherein the responding further comprises:

determining a creator of a file having caused the ransomware attack to be initiated on the identified user and/or client device based on the current metadata and the historical metadata; and

identifying and performing a specific response mechanism of multiple response mechanisms based on the determined creator.

20. The method of claim 13 , wherein:

the collecting the metadata further comprises collecting a third portion of the metadata using an active agent of the proxy device; and

the proxy device is positioned between the client devices and the cloud-based file storage service.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE SPELLING OF THE ASSIGNEE'S NAME PREVIOUSLY RECORDED ON REEL 59020 FRAME 984. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Aug 15, 2024
From: HITTEL, SEAN; NARAYANASWAMY, KRISHNA; BALUPARI, RAVINDRA K.; ITHAL, RAVI
To: NETSKOPE, INC.
Reel/Frame 068654/0683 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 16, 2022
From: HITTEL, SEAN; NARAYANASWAMY, KRISHNA; BALUPARI, RAVINDRA K.; ITHAL, RAVI
To: NETSCOPE, INC.
Reel/Frame 059020/0984 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 29, 2021
From: HITTEL, SEAN; NARAYANASWAMY, KRISHNA; BALUPARI, RAVINDRA K.
To: NETSCOPE, INC.
Reel/Frame 058233/0342 →
Continuity (4)
Continuation 16673922 · Nov 4, 2019
Continuation 15628551 · Jun 20, 2017
Provisional Application 62373288 · Aug 10, 2016
Related Publication 20220166781A1 · May 26, 2022
References Cited (164)
US 5440723A · Arnold et al. · 1995 [cited by applicant]
US 5452460A · Distelberg et al. · 1995 [cited by applicant]
US 6513122B1 · Magdych et al. · 2003 [cited by applicant]
US 6622248B1 · Hirai · 2003 [cited by applicant]
US 7080408B1 · Pak et al. · 2006 [cited by applicant]
US 7298864B2 · Jones · 2007 [cited by applicant]
US 7376719B1 · Shafer et al. · 2008 [cited by applicant]
US 7735116B1 · Gauvin · 2010 [cited by applicant]
US 7966654B2 · Crawford · 2011 [cited by applicant]
US 8000329B2 · Fendick et al. · 2011 [cited by applicant]
US 8296178B2 · Hudis et al. · 2012 [cited by applicant]
US 8346580B2 · Nakfoor · 2013 [cited by applicant]
US 8365243B1 · Lu et al. · 2013 [cited by applicant]
US 8677448B1 · Kauffman et al. · 2014 [cited by applicant]
US 8793151B2 · DelZoppo et al. · 2014 [cited by applicant]
US 8839417B1 · Jordan · 2014 [cited by applicant]
US 8856869B1 · Brinskelle · 2014 [cited by applicant]
US 9069955B2 · Dolph et al. · 2015 [cited by applicant]
US 9197601B2 · Pasdar · 2015 [cited by applicant]
US 9197628B1 · Hastings · 2015 [cited by applicant]
US 9225734B1 · Hastings · 2015 [cited by applicant]
US 9231968B2 · Fang et al. · 2016 [cited by applicant]
US 9246944B1 · Chen · 2016 [cited by applicant]
US 9280678B2 · Redberg · 2016 [cited by applicant]
US 9317686B1 · Ye · 2016 [cited by examiner]
US 9692759B1 · Chandrasekhar · 2017 [cited by applicant]
US 9811662B2 · Sharpe et al. · 2017 [cited by applicant]
US 9917817B1 · Lad et al. · 2018 [cited by applicant]
US 10084825B1 · Xu · 2018 [cited by applicant]
US 10162767B2 · Spurlock et al. · 2018 [cited by applicant]
US 10237282B2 · Nelson et al. · 2019 [cited by applicant]
US 10248797B1 · Shinde et al. · 2019 [cited by applicant]
US 10334442B2 · Vaughn et al. · 2019 [cited by applicant]
US 10382468B2 · Dods · 2019 [cited by applicant]
US 10469525B2 · Hittel et al. · 2019 [cited by applicant]
US 10476907B2 · Hittel et al. · 2019 [cited by applicant]
US 10484334B1 · Lee et al. · 2019 [cited by applicant]
US 10826941B2 · Jain et al. · 2020 [cited by applicant]
US 10860730B1 · Weaver et al. · 2020 [cited by applicant]
US 11032301B2 · Mandrychenko et al. · 2021 [cited by applicant]
US 11036856B2 · Graun et al. · 2021 [cited by applicant]
US 11089064B1 · Sarukkai et al. · 2021 [cited by applicant]
US 11178172B2 · Hittel et al. · 2021 [cited by applicant]
US 11190540B2 · Hittel et al. · 2021 [cited by applicant]
US 11281775B2 · Burdett et al. · 2022 [cited by applicant]
US 20020099666A1 · Dryer et al. · 2002 [cited by applicant]
US 20030055994A1 · Herrmann et al. · 2003 [cited by applicant]
US 20030063321A1 · Inoue et al. · 2003 [cited by applicant]
US 20030172292A1 · Judge · 2003 [cited by applicant]
US 20030204632A1 · Willebeek-Lemair et al. · 2003 [cited by applicant]
US 20040015719A1 · Lee et al. · 2004 [cited by applicant]
US 20050010593A1 · Fellenstein et al. · 2005 [cited by applicant]
US 20050271246A1 · Sharma et al. · 2005 [cited by applicant]
US 20060156401A1 · Newstadt et al. · 2006 [cited by applicant]
US 20070006293A1 · Balakrishnan et al. · 2007 [cited by applicant]
US 20070204018A1 · Chandra et al. · 2007 [cited by applicant]
US 20070237147A1 · Quinn et al. · 2007 [cited by applicant]
US 20080047013A1 · Claudatos · 2008 [cited by examiner]
US 20080069480A1 · Aarabi et al. · 2008 [cited by applicant]
US 20080134332A1 · Keohane et al. · 2008 [cited by applicant]
US 20090144818A1 · Kumar et al. · 2009 [cited by applicant]
US 20090249470A1 · Litvin et al. · 2009 [cited by applicant]
US 20090300351A1 · Lei et al. · 2009 [cited by applicant]
US 20100017436A1 · Wolge · 2010 [cited by applicant]
US 20100251369A1 · Grant · 2010 [cited by applicant]
US 20110119481A1 · Auradkar et al. · 2011 [cited by applicant]
US 20110145594A1 · Jho et al. · 2011 [cited by applicant]
US 20110321170A1 · Onodera et al. · 2011 [cited by applicant]
US 20120278896A1 · Fang et al. · 2012 [cited by applicant]
US 20130145483A1 · Dimuro et al. · 2013 [cited by applicant]
US 20130159694A1 · Chiueh et al. · 2013 [cited by applicant]
US 20130298190A1 · Sikka et al. · 2013 [cited by applicant]
US 20130347085A1 · Hawthorn et al. · 2013 [cited by applicant]
US 20140007182A1 · Qureshi et al. · 2014 [cited by applicant]
US 20140013112A1 · Cidon et al. · 2014 [cited by applicant]
US 20140026182A1 · Pearl et al. · 2014 [cited by applicant]
US 20140068030A1 · Chambers et al. · 2014 [cited by applicant]
US 20140068705A1 · Chambers et al. · 2014 [cited by applicant]
US 20140259093A1 · Narayanaswamy et al. · 2014 [cited by applicant]
US 20140259190A1 · Kiang et al. · 2014 [cited by applicant]
US 20140269279A1 · Ismail et al. · 2014 [cited by applicant]
US 20140282843A1 · Buruganahalli et al. · 2014 [cited by applicant]
US 20140317681A1 · Shende · 2014 [cited by applicant]
US 20140337862A1 · Valencia et al. · 2014 [cited by applicant]
US 20140344573A1 · Tsai et al. · 2014 [cited by applicant]
US 20140359282A1 · Shikfa et al. · 2014 [cited by applicant]
US 20140366079A1 · Pasdar · 2014 [cited by applicant]
US 20140380491A1 · Abuelsaad et al. · 2014 [cited by applicant]
US 20150074744A1 · McLean et al. · 2015 [cited by applicant]
US 20150100357A1 · Seese et al. · 2015 [cited by applicant]
US 20150135302A1 · Cohen et al. · 2015 [cited by applicant]
US 20150271207A1 · Jaiswal et al. · 2015 [cited by applicant]
US 20160275577A1 · Kolluri Venkata Sesha et al. · 2016 [cited by applicant]
US 20160323318A1 · Terrill et al. · 2016 [cited by applicant]
US 20160350145A1 · Botzer et al. · 2016 [cited by applicant]
US 20170064005A1 · Lee · 2017 [cited by applicant]
US 20170093917A1 · Chandra et al. · 2017 [cited by applicant]
US 20170250951A1 · Wang et al. · 2017 [cited by applicant]
US 20170286696A1 · Shetty · 2017 [cited by examiner]
US 20170353496A1 · Pai et al. · 2017 [cited by applicant]
US 20170359725A1 · Bolte · 2017 [cited by examiner]
US 20180034835A1 · Iwanir · 2018 [cited by examiner]
US 20180324204A1 · McClory et al. · 2018 [cited by applicant]
US 20200050686A1 · Kamalapuram et al. · 2020 [cited by applicant]
US 20200372040A1 · Boehmann et al. · 2020 [cited by applicant]
US 20210367976A1 · Khurshid et al. · 2021 [cited by applicant]
EP 1063833A2 · 2000 [cited by applicant]
JP 2011234178A · 2011 [cited by applicant]
Scaife et al “Cryptolock and Drop It: Stopping Ransomware Attacks on User Data”, Jun. 2016, IEEE 36th International conference on Distributed Computing Systems (Year: 2016). [cited by examiner]
“Cloud Data Loss Prevention Reference Architecture”, Netskope, Sep. 2015, WP-88-1, 2 pages. [cited by applicant]
“Data Breach: The Cloud Multiplier Effect”, Ponemon Institute, Jun. 4, 2014, 27 pages. [cited by applicant]
“Netskope Introspection,” netSkope, Inc., 2015, 3 pgs. [cited by applicant]
“Netskope The 15 Critical CASB Use Cases”, Netskope Inc., EB-141-1, dated 2015, 19 pages. [cited by applicant]
“The Netskope Active Platform Enabling Safe Migration to the Cloud”, Apr. 2015, DS-1-8, Netskope, Inc., 6 pages. [cited by applicant]
“The Netskope Advantage: Three “Must-Have” Requirements for Cloud Access Security Brokers”, Jul. 2015, WP-12-2 1 pages. [cited by applicant]
Cheng et al., “Cloud Security for Dummies, Netskope Special Edition,” John Wiley & Sons, Inc., dated 2015, 53 pages. [cited by applicant]
Kark et al, “Trends: Calculating the Cost of a Security Breach”, Forrester Research, Inc. Apr. 10, 2007, 7 pgs. [cited by applicant]
Liu et al., Data Loss Prevention, IT Professional, vol. 12, Issue 2, IEEE, Mar. 29, 2010, pp. 10-13. [cited by applicant]
Netskope, “The 5 Steps to Cloud Confidence”, Version 2, Jan. 29, 2014, 10 pages. [cited by applicant]
Oasis, Key Management Interoperability Protocols Use Cases Version 1.2, dated Mar. 18, 2013, 132 pages. [cited by applicant]
Pandire et al., Attack Detection in Cloud Virtual Environment and Prevention using Honeypot, International Conference Un Inventive Research in Computing Applications {ICIRCA), IEEE, Jul. 11-12, 2018, pp. 515-520. [cited by applicant]
Office Action in U.S. Appl. No. 17/527,150, mailed Feb. 29, 2024, 23 pages. [cited by applicant]
Martin, Victoria “Cooperative Security Fabric,” The Fortinet Cookbook, Jun. 8, 2016, 6 pgs., archived Jul. 28, 2016 at https://web.archive.org/web/20160728170025/http://cookbook.fortinet.com/cooperative-security-fabric-… [cited by applicant]
Huckaby, Jeff “Ending Clear Text Protocols,” Rackaid.com, Dec. 9, 2008, 3 pgs. [cited by applicant]
Newton, Harry “fabric,” Newton's Telecom Dictionary, 30th Updated, Expanded, Anniversary Edition, 2016, 3 pgs. [cited by applicant]
Fortinet, “Fortinet Security Fabric Earns 100% Detection Scores Across Several Attack Vectors in NSS Labs' Latest Breach Detection Group Test [press release]”, Aug. 2, 2016, 4 pgs, available at https://www.fortinet.com/… [cited by applicant]
Fortinet, “Fortinet Security Fabric Named 2016 CRN Network Security Product of the Year [press release]”, Dec. 5, 2016, 4 pgs, available at https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2016/fortin… [cited by applicant]
Mccullagh, Declan, “How safe is instant messaging? A security and privacy survey,” CNET, Jun. 9, 2008, 14 pgs. [cited by applicant]
Beck et al., “IBM and Cisco: Together for a World Class Data Center,” IBM Redbooks, Jul. 2013, 654 pgs. [cited by applicant]
Martin, Victoria “Installing internal FortiGates and enabling a security fabric,” The Fortinet Cookbook, Jun. 8, 2016, 11 pgs, archived Aug. 28, 2016 at https://web.archive.org/web/20160828235831/http://cookbook.fortine… [cited by applicant]
Zetter, Kim, “Revealed: The Internet's Biggest Security Hole,” Wired, Aug. 26, 2008, 13 pgs. [cited by applicant]
Adya et al., “Farsite: Federated, available, and reliable storage for an incompletely trusted environment,” SIGOPS Oper. Syst. Rev. 36, SI, Dec. 2002, pp. 1-14. [cited by applicant]
Agrawal et al., “Order preserving encryption for numeric data,” In Proceedings of the 2004 ACM SIGMOD international conference on Management of data, Jun. 2004, pp. 563-574. [cited by applicant]
Balakrishnan et al., “A layered naming architecture for the Internet,” ACM SIGCOMM Computer Communication Review, 34(4), 2004, pp. 343-352. [cited by applicant]
Downing et al., Naming Dictionary of Computer and Internet Terms, (11th Ed.) Barron's, 2013, 6 pgs. [cited by applicant]
Downing et al., Dictionary of Computer and Internet Terms, (10th Ed.) Barron's, 2009, 4 pgs. [cited by applicant]
Zoho Mail, “Email Protocols: What they are & their different types,” 2006, 7 pgs. available at https://www.zoho.com/mail/glossary/email-protocols.html#:˜: text=mode of communication.-,What are the different email protoc… [cited by applicant]
NIIT, Special Edition Using Storage Area Networks, Que, 2002, 6 pgs. [cited by applicant]
Chapple, Mike, “Firewall redundancy: Deployment scenarios and benefits,” TechTarget, 2005, 5 pgs. available at https://www.techtarget.com/searchsecurity/tip/Firewall-redundancy-Deployment-scenarios-and-benefits?Offer=ab… [cited by applicant]
Fortinet, FortiGate—3600 User Manual (vol. 1, Version 2.50 MR2) Sep. 5, 2003, 329 pgs. [cited by applicant]
Fortinet, FortiGate SOHO and SMB Configuration Example, (Version 3.0 MR5), Aug. 24, 2007, 54 pgs. [cited by applicant]
Fortinet, FortiSandbox—Administration Guide, (Version 2.3.2), Nov. 9, 2016, 191 pgs. [cited by applicant]
Fortinet, FortiSandbox Administration Guide, (Version 4.2.4) Jun. 12, 2023, 245 pgs. available at https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/fba32b46-b7c0-11ed-8e6d-fa163e15d75b/FortiSandbox-4… [cited by applicant]
Fortinet, FortiOS—Administration Guide, (Versions 6.4.0), Jun. 3, 2021, 1638 pgs. [cited by applicant]
Heady et al., “The Architecture of a Network Level Intrusion Detection System,” University of New Mexico, Aug. 15, 1990, 21 pgs. [cited by applicant]
Kephart et al., “Fighting Computer Viruses,” Scientific American (vol. 277, No. 5) Nov. 1997, pp. 88-93. [cited by applicant]
Wang, L., Chapter 5: Cooperative Security in D2D Communications, “Physical Layer Security in Wireless Cooperative Networks,” 41 pgs. first online on Sep. 1, 2017 at https://link.springer.com/chapter/10.1007/978-3-319-61… [cited by applicant]
Lee et al., “A Data Mining Framework for Building Intrusion Detection Models,” Columbia University, n.d. 13 pgs. [cited by applicant]
Merriam-Webster Dictionary, 2004, 5 pgs. [cited by applicant]
Microsoft Computer Dictionary, (5th Ed.), Microsoft Press, 2002, 8 pgs. [cited by applicant]
Microsoft Computer Dictionary, (4th Ed.), Microsoft Press, 1999, 5 pgs. [cited by applicant]
Mika et al., “Metadata Statistics for a Large Web Corpus,” LDOW2012, Apr. 16, 2012, 6 pgs. [cited by applicant]
Oxford Dictionary of Computing (6th Ed.), 2008, 5 pgs. [cited by applicant]
Paxson, Vern, “Bro: a System for Detecting Network Intruders in Real-Time,” Proceedings of the 7th USENIX Security Symposium, Jan. 1998, 22 pgs. [cited by applicant]
Fortinet Inc., U.S. Appl. No. 62/503,252, “Building a Cooperative Security Fabric of Hierarchically Interconnected Network Security Devices.” n.d., 87 pgs. [cited by applicant]
Song et al., “Practical techniques for searches on encrypted data,” In Proceeding 2000 IEEE symposium on security and privacy. S&p. 2000, May 2000, pp. 44-55. [cited by applicant]
Dean, Tamara, Guide to Telecommunications Technology, Course Technology, 2003, 5 pgs. [cited by applicant]
U.S. Appl. No. 60/520,577, “Device, System, and Method for Defending a Computer Network,” Nov. 17, 2003, 21 pgs. [cited by applicant]
U.S. Appl. No. 60/552,457, “Fortinet Security Update Technology,” Mar. 2004, 6 pgs. [cited by applicant]
Tittel, Ed, Unified Threat Management For Dummies, John Wiley & Sons, Inc., 2012, 76 pgs. [cited by applicant]
Fortinet, FortiOS Handbook: UTM Guide (Version 2), Oct. 15, 2010, 188 pgs. [cited by applicant]
Full Definition of Security, Wayback Machine Archive of Merriam-Webster on Nov. 17, 2016, 1 pg. [cited by applicant]
Definition of Cooperative, Wayback Machine Archive of Merriam-Webster on Nov. 26, 2016, 1 pg. [cited by applicant]
Pfaffenberger, Bryan, Webster's New World Computer Dictionary, (10th Ed.), 2003, 5 pgs. [cited by applicant]