IP Library Granted Patent US 12,413,553
Granted Patent B2
US 12,413,553 · App. 17/693,550 · Granted Sep 9, 2025

Methods and systems for efficient network protection

Inventors: Sean Moore (Hollis, NH); Jess P. Parnell (Grayson, GA); Jonathan R. Rogers (Hampton Falls, NH)
Assignee: Centripetal Networks, LLC
H04L63/0236H04L43/028H04L63/1416H04L63/1433H04L63/20H04L69/16H04L63/0227
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,413,553
App. No.
17/693,550
Granted
Sep 9, 2025
Kind
B2
Abstract

Methods and systems are disclosed for integrating cyber threat intelligence (CTI), threat metadata, and threat intelligence gateways with analysis systems to form efficient and effective system for active, proactive, and reactive network protection. A network gateway may be composed of multiple stages. A first stage may include a threat intelligence gateway (TIG). A second stage may include one or more cyber analysis systems that ingest TIG-filtered communications and associated threat metadata signals. A third stage may include network protection logic that determines which protective actions. The gateway may be provisioned and configured with rules that specify the network protection policies to be enforced. The gateway may ingest all communications flowing between the protected network and the unprotected network.

Claims (88)

1. A network protection device comprising:

one or more processors; and

memory storing instructions that, when executed by the one or more processors, cause the network protection device to:

receive, by at least one cyber analysis system, a configuration signal to configure the at least one cyber analysis system to perform at least one particular analysis method;

receive, by a gateway configured with a plurality of packet filtering rules, a plurality of packets associated with a protected network;

filter, by the gateway and based on the plurality of packet filtering rules, the plurality of packets to determine a first portion of the plurality of packets that is associated with a potential threat by comparing, for each one of the plurality of packets, data associated with each one of the plurality of packets with threat intelligence data based on the plurality of packet filtering rules;

generate, by the gateway and based on a determination that the first portion of the plurality of packets are associated with the potential threat, threat metadata associated with the first portion of the plurality of packets;

receive, by at the least one cyber analysis system, the first portion of the plurality of packets and the generated threat metadata associated with the first portion of the plurality of packets;

analyze, by the at least one cyber analysis system, the first portion of the plurality of packets using the at least one particular analysis method to identify a second portion of the plurality of packets as a threat;

determine, based on analyzing the first portion of the plurality of packets and based on the received threat metadata, at least one protective action for the second portion of the plurality of packets; and

process, based on the determined at least one protective action, the second portion of the plurality of packets to implement the at least one protective action.

2. The network protection device of claim 1 , wherein the instructions, when executed by the one or more processors, cause the network protection device to forward, by the gateway, a third portion of the plurality of packets to their intended destinations, wherein the third portion of the plurality of packets do not match any of the plurality of packet filtering rules.

3. The network protection device of claim 1 , wherein the instructions, when executed by the one or more processors, cause the network protection device to determine, by the gateway and based on a fidelity of packet filtering threat intelligence data, whether to transmit the first portion of the plurality of packets and the generated threat metadata associated with the first portion of the plurality of packets to the at least one cyber analysis system.

4. The network protection device of claim 3 , wherein the instructions, when executed by the one or more processors, cause the network protection device to transmit, based on a determination that the fidelity of packet filtering threat intelligence data is low, a copy of the first portion of the plurality of packets and the generated threat metadata associated with the first portion of the plurality of packets to the at least one cyber analysis system.

5. The network protection device of claim 1 , wherein the instructions, when executed by the one or more processors, cause the network protection device to transmit, based on a determination that a fidelity of packet filtering threat intelligence data is low, a third portion of the plurality of packets to their destination.

6. The network protection device of claim 1 , wherein the instructions, when executed by the one or more processors, cause the network protection device to determine, based on the threat metadata associated with the first portion of the plurality of packets, the at least one cyber analysis system to process the first portion of the plurality of packets.

7. The network protection device of claim 6 , wherein the at least one cyber analysis system is determined by a broker based on the received first portion of the plurality of packets and the threat metadata associated with the first portion of the plurality of packets.

8. The network protection device of claim 1 , wherein the instructions, when executed by the one or more processors, cause the network protection device to:

generate, by the gateway, a log of the first portion of the plurality of packets and the threat metadata associated with the first portion of the plurality of packets; and

transmit, by the gateway, the log to a system administrator.

9. The network protection device of claim 8 , wherein the instructions, when executed by the one or more processors, cause the network protection device to:

update the log based on second threat metadata generated by the at least one cyber analysis system, wherein the updated log comprises both threat metadata generated by the gateway and the second threat metadata generated by the at least one cyber analysis system; and

transmit, by the at least one cyber analysis system to a system administrator, the updated log including metadata related to at least one threat.

10. The network protection device of claim 9 , wherein the instructions, when executed by the one or more processors, cause the network protection device to:

determine that at least one packet filtering rule of the plurality of packet filtering rules should be reconfigured;

receive, by the gateway from the system administrator, updated rule information; and

update, by the gateway and based on the updated rule information received from the system administrator, at least one of the plurality of packet filtering rules of the gateway.

11. The network protection device of claim 10 , wherein the instructions, when executed by the one or more processors, cause the network protection device to configure the gateway with the at least one packet filtering rule generated based on cyber threat intelligence.

12. The network protection device of claim 1 , wherein the at least one protective action comprises:

forwarding the second portion of the plurality of packets to their destination; and

monitoring a flow of packets associated with the second portion of the plurality of packets.

13. The network protection device of claim 1 , wherein the at least one protective action comprises at least one of active protective processing, proactive protective processing, or reactive protective processing,

wherein active protective processing comprises reconfiguring the gateway to block packets associated with a same packet flow as the second portion of the plurality of packets,

wherein proactive protective processing comprises extracting threat intelligence data from the second portion of the plurality of packets and reconfiguring the gateway based on the extracted threat intelligence data, and

wherein reactive protective processing comprises transmitting, to a management device, metadata associated with the second portion of the plurality of packets.

14. The network protection device of claim 1 , wherein the at least one cyber analysis system comprises at least one of a network intrusion detection device, a network intrusion protection device, a network signature detection device, a monitoring device, a sandbox analysis device, or a malware analysis device.

15. The network protection device of claim 1 , wherein the at least one protective action comprises at least one of:

blocking further communications associated with the second portion of the plurality of packets;

extracting threat intelligence data from the second portion of the plurality of packets and generating rules based on the extracted threat intelligence data;

quarantining an infected host device associated with the second portion of the plurality of packets; or

forwarding logs associated with the second portion of the plurality of packets to a management device.

16. A method for network protection, the method comprising:

receiving, by at least one cyber analysis system, a configuration signal to configure the at least one cyber analysis system to perform at least one particular analysis method;

receiving, by a gateway configured with a plurality of packet filtering rules, a plurality of packets associated with a protected network;

filtering, by the gateway and based on the plurality of packet filtering rules, the plurality of packets to determine a first portion of the plurality of packets that is associated with a potential threat by comparing, for each one of the plurality of packets, data associated with each one of the plurality of packets with threat intelligence data based on the plurality of packet filtering rules;

generating, by the gateway and based on a determination that the first portion of the plurality of packets are associated with the potential threat, threat metadata associated with the first portion of the plurality of packets;

receiving, by at the least one cyber analysis system, the first portion of the plurality of packets and the generated threat metadata associated with the first portion of the plurality of packets;

analyzing, by the at least one cyber analysis system, the first portion of the plurality of packets using the at least one particular analysis method to identify a second portion of the plurality of packets as a threat;

determining, based on the analyzing the first portion of the plurality of packets and based on the received threat metadata, at least one protective action for the second portion of the plurality of packets; and

processing, based on the determined at least one protective action, the second portion of the plurality of packets to implement the at least one protective action.

17. The method of claim 16 , further comprising:

generating, by the gateway, a log of the first portion of the plurality of packets and the threat metadata associated with the first portion of the plurality of packets; and

transmitting, by the gateway, the log to a system administrator.

18. The method of claim 17 , further comprising:

updating the log based on second threat metadata generated by the at least one cyber analysis system, wherein the updated log comprises both threat metadata generated by the gateway and the second threat metadata generated by the at least one cyber analysis system; and

transmitting, by the at least one cyber analysis system to a system administrator, log files including metadata related to at least one threat.

19. The method of claim 18 , further comprising:

determining that at least one packet filtering rule of the plurality of packet filtering rules should be reconfigured;

receiving, by the gateway from the system administrator, updated rule information; and

updating, by the gateway and based on the updated rule information received from the system administrator, at least one of the plurality of packet filtering rules of the gateway.

20. The method of claim 19 , further comprising configuring the gateway with the at least one packet filtering rule generated based on cyber threat intelligence.

21. The method of claim 16 , wherein the at least one protective action comprises:

forwarding the second portion of the plurality of packets to their destination; and

monitoring a flow of packets associated with the second portion of the plurality of packets.

22. The method of claim 16 , wherein the at least one protective action comprises at least one of active protective processing, proactive protective processing, or reactive protective processing,

wherein active protective processing comprises reconfiguring the gateway to block packets associated with a same packet flow as the second portion of the plurality of packets,

wherein proactive protective processing comprises extracting threat intelligence data from the second portion of the plurality of packets and reconfiguring the gateway based on the extracted threat intelligence data, and

wherein reactive protective processing comprises transmitting, to a management device, metadata associated with the second portion of the plurality of packets.

23. The method of claim 16 , wherein the at least one protective action comprises at least one of:

blocking further communications associated with the second portion of the plurality of packets;

extracting threat intelligence data from the second portion of the plurality of packets and generating rules based on the extracted threat intelligence data;

quarantining an infected host device associated with the second portion of the plurality of packets; or

forwarding logs associated with the second portion of the plurality of packets to a management device.

24. One or more non-transitory computer-readable media comprising instructions that, when executed, cause a network protection device to:

receive, by at least one cyber analysis system, a configuration signal to configure the at least one cyber analysis system to perform at least one particular analysis method;

receive, by a gateway configured with a plurality of packet filtering rules, a plurality of packets associated with a protected network;

filter, by the gateway and based on the plurality of packet filtering rules, the plurality of packets to determine a first portion of the plurality of packets that is associated with a potential threat by comparing, for each one of the plurality of packets, data associated with each one of the plurality of packets with threat intelligence data based on the plurality of packet filtering rules;

generate, by the gateway and based on a determination that the first portion of the plurality of packets are associated with the potential threat, threat metadata associated with the first portion of the plurality of packets;

receive, by at the least one cyber analysis system, the first portion of the plurality of packets and the generated threat metadata associated with the first portion of the plurality of packets;

analyze, by the at least one cyber analysis system, the first portion of the plurality of packets using the at least one particular analysis method to identify a second portion of the plurality of packets as a threat;

determine, based on analyzing the first portion of the plurality of packets and based on the received threat metadata, at least one protective action for the second portion of the plurality of packets; and

process, based on the determined at least one protective action, the second portion of the plurality of packets to implement the at least one protective action.

25. The one or more non-transitory computer-readable media of claim 24 , wherein the instructions, when executed, cause the network protection device to forward, by the gateway, a third portion of the plurality of packets to their intended destinations, wherein the third portion of the plurality of packets do not match any of the plurality of packet filtering rules.

26. The one or more non-transitory computer-readable media of claim 24 , wherein the instructions, when executed, cause the network protection device to determine, by the gateway and based on a fidelity of packet filtering threat intelligence data, whether to transmit the first portion of the plurality of packets and the generated threat metadata associated with the first portion of the plurality of packets to the at least one cyber analysis system.

27. The one or more non-transitory computer-readable media of claim 26 , wherein the instructions, when executed, cause the network protection device to transmit, based on a determination that the fidelity of packet filtering threat intelligence data is low, a copy of the first portion of the plurality of packets and the generated threat metadata associated with the first portion of the plurality of packets to the at least one cyber analysis system.

28. The one or more non-transitory computer-readable media of claim 24 , wherein the instructions, when executed, cause the network protection device to determine, based on the threat metadata associated with the first portion of the plurality of packets, the at least one cyber analysis system to process the first portion of the plurality of packets.

29. The one or more non-transitory computer-readable media of claim 28 , wherein the at least one cyber analysis system is determined by a broker based on the received first portion of the plurality of packets and the threat metadata associated with the first portion of the plurality of packets.

30. The one or more non-transitory computer-readable media of claim 24 , wherein the instructions, when executed, cause the network protection device to transmit, based on a determination that a fidelity of packet filtering threat intelligence data is low, a third portion of the plurality of packets to their destination.

Assignments (2)
CHANGE OF NAME Recorded Feb 7, 2023
From: CENTRIPETAL NETWORKS, INC.
To: CENTRIPETAL NETWORKS, LLC
Reel/Frame 062666/0239 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2022
From: MOORE, SEAN; PARNELL, JESS; ROGERS, JONATHAN R.
To: CENTRIPETAL NETWORKS, INC.
Reel/Frame 059252/0762 →
Continuity (3)
Continuation 16406311 · May 8, 2019
Continuation 16030374 · Jul 9, 2018
Related Publication 20220210125A1 · Jun 30, 2022
References Cited (400)
US 6098172A · Coss et al. · 2000 [cited by applicant]
US 6147976A · Shand et al. · 2000 [cited by applicant]
US 6226372B1 · Beebe et al. · 2001 [cited by applicant]
US 6279113B1 · Vaidya · 2001 [cited by applicant]
US 6317837B1 · Kenworthy · 2001 [cited by applicant]
US 6484261B1 · Wiegel · 2002 [cited by applicant]
US 6611875B1 · Chopra et al. · 2003 [cited by applicant]
US 6662235B1 · Callis et al. · 2003 [cited by applicant]
US 6678827B1 · Rothermel et al. · 2004 [cited by applicant]
US 6826694B1 · Dutta et al. · 2004 [cited by applicant]
US 6907042B1 · Oguchi · 2005 [cited by applicant]
US 6971028B1 · Lyle et al. · 2005 [cited by applicant]
US 7089581B1 · Nagai et al. · 2006 [cited by applicant]
US 7095716B1 · Ke et al. · 2006 [cited by applicant]
US 7107613B1 · Chen et al. · 2006 [cited by applicant]
US 7143438B1 · Coss et al. · 2006 [cited by applicant]
US 7152240B1 · Green et al. · 2006 [cited by applicant]
US 7185368B2 · Copeland, III · 2007 [cited by applicant]
US 7215637B1 · Ferguson et al. · 2007 [cited by applicant]
US 7225269B2 · Watanabe · 2007 [cited by applicant]
US 7227842B1 · Ji et al. · 2007 [cited by applicant]
US 7237267B2 · Rayes et al. · 2007 [cited by applicant]
US 7263099B1 · Woo et al. · 2007 [cited by applicant]
US 7296288B1 · Hill et al. · 2007 [cited by applicant]
US 7299353B2 · Le Pennec et al. · 2007 [cited by applicant]
US 7331061B1 · Ramsey et al. · 2008 [cited by applicant]
US 7478429B2 · Lyon · 2009 [cited by applicant]
US 7499412B2 · Matityahu et al. · 2009 [cited by applicant]
US 7539186B2 · Aerrabotu et al. · 2009 [cited by applicant]
US 7610621B2 · Turley et al. · 2009 [cited by applicant]
US 7684400B2 · Govindarajan et al. · 2010 [cited by applicant]
US 7710885B2 · Ilnicki et al. · 2010 [cited by applicant]
US 7721084B2 · Salminen et al. · 2010 [cited by applicant]
US 7746862B1 · Zuk et al. · 2010 [cited by applicant]
US 7792775B2 · Matsuda · 2010 [cited by applicant]
US 7814158B2 · Malik · 2010 [cited by applicant]
US 7814546B1 · Strayer et al. · 2010 [cited by applicant]
US 7818794B2 · Wittman · 2010 [cited by applicant]
US 7849502B1 · Bloch et al. · 2010 [cited by applicant]
US 7913303B1 · Rouland et al. · 2011 [cited by applicant]
US 7954143B2 · Aaron · 2011 [cited by applicant]
US 8004994B1 · Darisi et al. · 2011 [cited by applicant]
US 8009566B2 · Zuk et al. · 2011 [cited by applicant]
US 8037517B2 · Fulp et al. · 2011 [cited by applicant]
US 8042167B2 · Fulp et al. · 2011 [cited by applicant]
US 8117655B2 · Spielman · 2012 [cited by applicant]
US 8156206B2 · Kiley et al. · 2012 [cited by applicant]
US 8176561B1 · Hurst et al. · 2012 [cited by applicant]
US 8219675B2 · Ivershen · 2012 [cited by applicant]
US 8271645B2 · Rajan et al. · 2012 [cited by applicant]
US 8306994B2 · Kenworthy · 2012 [cited by applicant]
US 8307029B2 · Davis et al. · 2012 [cited by applicant]
US 8331234B1 · Newton et al. · 2012 [cited by applicant]
US 8422391B2 · Zhu · 2013 [cited by applicant]
US 8495725B2 · Ahn · 2013 [cited by applicant]
US 8510821B1 · Brandwine et al. · 2013 [cited by applicant]
US 8726379B1 · Stiansen et al. · 2014 [cited by applicant]
US 8789135B1 · Pani · 2014 [cited by applicant]
US 8806638B1 · Mani · 2014 [cited by applicant]
US 8832832B1 · Visbal · 2014 [cited by applicant]
US 8856926B2 · Narayanaswamy et al. · 2014 [cited by applicant]
US 8935785B2 · Pandrangi · 2015 [cited by applicant]
US 8953458B2 · Leong et al. · 2015 [cited by applicant]
US 9094445B2 · Moore et al. · 2015 [cited by applicant]
US 9124552B2 · Moore · 2015 [cited by applicant]
US 9137205B2 · Rogers et al. · 2015 [cited by applicant]
US 9154446B2 · Gemelli et al. · 2015 [cited by applicant]
US 9160713B2 · Moore · 2015 [cited by applicant]
US 9172627B2 · Kjendal et al. · 2015 [cited by applicant]
US 9223972B1 · Vincent et al. · 2015 [cited by applicant]
US 9419942B1 · Buruganahalli et al. · 2016 [cited by applicant]
US 9531672B1 · Li et al. · 2016 [cited by applicant]
US 9591015B1 · Amin et al. · 2017 [cited by applicant]
US 9634911B2 · Meloche · 2017 [cited by applicant]
US 9686193B2 · Moore · 2017 [cited by applicant]
US 10333898B1 · Moore · 2019 [cited by applicant]
US 20010039579A1 · Trcka et al. · 2001 [cited by applicant]
US 20010039624A1 · Kellum · 2001 [cited by applicant]
US 20020016858A1 · Sawada et al. · 2002 [cited by applicant]
US 20020038339A1 · Xu · 2002 [cited by applicant]
US 20020049899A1 · Kenworthy · 2002 [cited by applicant]
US 20020083345A1 · Halliday et al. · 2002 [cited by applicant]
US 20020112188A1 · Syvanne · 2002 [cited by applicant]
US 20020152209A1 · Merugu et al. · 2002 [cited by applicant]
US 20020164962A1 · Mankins et al. · 2002 [cited by applicant]
US 20020165949A1 · Na et al. · 2002 [cited by applicant]
US 20020186683A1 · Buck et al. · 2002 [cited by applicant]
US 20020198981A1 · Corl et al. · 2002 [cited by applicant]
US 20030005122A1 · Freimuth et al. · 2003 [cited by applicant]
US 20030014665A1 · Anderson et al. · 2003 [cited by applicant]
US 20030018591A1 · Komisky · 2003 [cited by applicant]
US 20030035370A1 · Brustoloni · 2003 [cited by applicant]
US 20030051026A1 · Carter et al. · 2003 [cited by applicant]
US 20030088787A1 · Egevang · 2003 [cited by applicant]
US 20030097590A1 · Syvanne · 2003 [cited by applicant]
US 20030105976A1 · Copeland · 2003 [cited by applicant]
US 20030120622A1 · Nurmela et al. · 2003 [cited by applicant]
US 20030123456A1 · Denz et al. · 2003 [cited by applicant]
US 20030142681A1 · Chen et al. · 2003 [cited by applicant]
US 20030145225A1 · Bruton et al. · 2003 [cited by applicant]
US 20030154297A1 · Suzuki et al. · 2003 [cited by applicant]
US 20030154399A1 · Zuk et al. · 2003 [cited by applicant]
US 20030188192A1 · Tang et al. · 2003 [cited by applicant]
US 20030212900A1 · Liu et al. · 2003 [cited by applicant]
US 20030220940A1 · Futoransky et al. · 2003 [cited by applicant]
US 20040010712A1 · Hui et al. · 2004 [cited by applicant]
US 20040015719A1 · Lee et al. · 2004 [cited by applicant]
US 20040073655A1 · Kan et al. · 2004 [cited by applicant]
US 20040088542A1 · Daude et al. · 2004 [cited by applicant]
US 20040093513A1 · Cantrell et al. · 2004 [cited by applicant]
US 20040098511A1 · Lin et al. · 2004 [cited by applicant]
US 20040114518A1 · MacFaden et al. · 2004 [cited by applicant]
US 20040123220A1 · Johnson et al. · 2004 [cited by applicant]
US 20040131056A1 · Dark · 2004 [cited by applicant]
US 20040148520A1 · Talpade et al. · 2004 [cited by applicant]
US 20040151155A1 · Jouppi · 2004 [cited by applicant]
US 20040172529A1 · Culbert · 2004 [cited by applicant]
US 20040172557A1 · Nakae et al. · 2004 [cited by applicant]
US 20040177139A1 · Schuba et al. · 2004 [cited by applicant]
US 20040181690A1 · Rothermel et al. · 2004 [cited by applicant]
US 20040193943A1 · Angelino et al. · 2004 [cited by applicant]
US 20040199629A1 · Bomer et al. · 2004 [cited by applicant]
US 20040205360A1 · Norton et al. · 2004 [cited by applicant]
US 20040250124A1 · Chesla et al. · 2004 [cited by applicant]
US 20050010765A1 · Swander et al. · 2005 [cited by applicant]
US 20050024189A1 · Weber · 2005 [cited by applicant]
US 20050071650A1 · Jo et al. · 2005 [cited by applicant]
US 20050076227A1 · Kang et al. · 2005 [cited by applicant]
US 20050108557A1 · Kayo et al. · 2005 [cited by applicant]
US 20050114704A1 · Swander · 2005 [cited by applicant]
US 20050117576A1 · McDysan et al. · 2005 [cited by applicant]
US 20050125697A1 · Tahara · 2005 [cited by applicant]
US 20050138204A1 · Iyer et al. · 2005 [cited by applicant]
US 20050138353A1 · Spies et al. · 2005 [cited by applicant]
US 20050141537A1 · Kumar et al. · 2005 [cited by applicant]
US 20050183140A1 · Goddard · 2005 [cited by applicant]
US 20050229246A1 · Rajagopal et al. · 2005 [cited by applicant]
US 20050249214A1 · Peng · 2005 [cited by applicant]
US 20050251570A1 · Heasman et al. · 2005 [cited by applicant]
US 20050283823A1 · Okajo et al. · 2005 [cited by applicant]
US 20050286522A1 · Paddon et al. · 2005 [cited by applicant]
US 20060031928A1 · Conley et al. · 2006 [cited by applicant]
US 20060048142A1 · Roese et al. · 2006 [cited by applicant]
US 20060053491A1 · Khuti et al. · 2006 [cited by applicant]
US 20060070122A1 · Bellovin · 2006 [cited by applicant]
US 20060080733A1 · Khosmood et al. · 2006 [cited by applicant]
US 20060085849A1 · Culbert · 2006 [cited by applicant]
US 20060104202A1 · Reiner · 2006 [cited by applicant]
US 20060114899A1 · Toumura et al. · 2006 [cited by applicant]
US 20060133377A1 · Jain · 2006 [cited by applicant]
US 20060136987A1 · Okuda · 2006 [cited by applicant]
US 20060137009A1 · Chesla · 2006 [cited by applicant]
US 20060146879A1 · Anthias et al. · 2006 [cited by applicant]
US 20060159028A1 · Curran-Gray et al. · 2006 [cited by applicant]
US 20060195896A1 · Fulp et al. · 2006 [cited by applicant]
US 20060212572A1 · Afek et al. · 2006 [cited by applicant]
US 20060248580A1 · Fulp et al. · 2006 [cited by applicant]
US 20060262798A1 · Joshi et al. · 2006 [cited by applicant]
US 20070056038A1 · Lok · 2007 [cited by applicant]
US 20070083924A1 · Lu · 2007 [cited by applicant]
US 20070118894A1 · Bhatia · 2007 [cited by applicant]
US 20070147380A1 · Ormazabal et al. · 2007 [cited by applicant]
US 20070211644A1 · Ottamalika et al. · 2007 [cited by applicant]
US 20070240208A1 · Yu et al. · 2007 [cited by applicant]
US 20070291789A1 · Kutt et al. · 2007 [cited by applicant]
US 20080005795A1 · Acharya et al. · 2008 [cited by applicant]
US 20080028467A1 · Kommareddy et al. · 2008 [cited by applicant]
US 20080043739A1 · Suh et al. · 2008 [cited by applicant]
US 20080072307A1 · Maes · 2008 [cited by applicant]
US 20080077705A1 · Li et al. · 2008 [cited by applicant]
US 20080080493A1 · Weintraub et al. · 2008 [cited by applicant]
US 20080086435A1 · Chesla · 2008 [cited by applicant]
US 20080101234A1 · Nakil et al. · 2008 [cited by applicant]
US 20080163333A1 · Kasralikar · 2008 [cited by applicant]
US 20080201772A1 · Mondaeev et al. · 2008 [cited by applicant]
US 20080229415A1 · Kapoor et al. · 2008 [cited by applicant]
US 20080235755A1 · Blaisdell et al. · 2008 [cited by applicant]
US 20080279196A1 · Friskney et al. · 2008 [cited by applicant]
US 20080301765A1 · Nicol et al. · 2008 [cited by applicant]
US 20080313738A1 · Enderby · 2008 [cited by applicant]
US 20080320116A1 · Briggs · 2008 [cited by applicant]
US 20090028160A1 · Eswaran et al. · 2009 [cited by applicant]
US 20090138938A1 · Harrison et al. · 2009 [cited by applicant]
US 20090144819A1 · Babbar et al. · 2009 [cited by applicant]
US 20090150972A1 · Moon et al. · 2009 [cited by applicant]
US 20090172800A1 · Wool · 2009 [cited by applicant]
US 20090222877A1 · Diehl et al. · 2009 [cited by applicant]
US 20090240698A1 · Shukla et al. · 2009 [cited by applicant]
US 20090262723A1 · Pelletier et al. · 2009 [cited by applicant]
US 20090262741A1 · Jungck et al. · 2009 [cited by applicant]
US 20090300759A1 · Wang et al. · 2009 [cited by applicant]
US 20090328219A1 · Narayanaswamy · 2009 [cited by applicant]
US 20100011433A1 · Harrison et al. · 2010 [cited by applicant]
US 20100011434A1 · Kay · 2010 [cited by applicant]
US 20100082811A1 · Van Der Merwe et al. · 2010 [cited by applicant]
US 20100095367A1 · Narayanaswamy · 2010 [cited by applicant]
US 20100107240A1 · Thaler et al. · 2010 [cited by applicant]
US 20100115621A1 · Staniford et al. · 2010 [cited by applicant]
US 20100132027A1 · Ou · 2010 [cited by applicant]
US 20100195503A1 · Raleigh · 2010 [cited by applicant]
US 20100199346A1 · Ling et al. · 2010 [cited by applicant]
US 20100202299A1 · Strayer et al. · 2010 [cited by applicant]
US 20100211678A1 · McDysan et al. · 2010 [cited by applicant]
US 20100232445A1 · Bellovin · 2010 [cited by applicant]
US 20100242098A1 · Kenworthy · 2010 [cited by applicant]
US 20100268799A1 · Maestas · 2010 [cited by applicant]
US 20100296441A1 · Barkan · 2010 [cited by applicant]
US 20100303240A1 · Beachem et al. · 2010 [cited by applicant]
US 20110055916A1 · Ahn · 2011 [cited by applicant]
US 20110055923A1 · Thomas · 2011 [cited by applicant]
US 20110088092A1 · Nguyen et al. · 2011 [cited by applicant]
US 20110141900A1 · Jayawardena et al. · 2011 [cited by applicant]
US 20110154470A1 · Grimes et al. · 2011 [cited by applicant]
US 20110185055A1 · Nappier et al. · 2011 [cited by applicant]
US 20110214157A1 · Korsunsky et al. · 2011 [cited by applicant]
US 20110270956A1 · McDysan et al. · 2011 [cited by applicant]
US 20110277034A1 · Hanson · 2011 [cited by applicant]
US 20120023576A1 · Sorensen et al. · 2012 [cited by applicant]
US 20120084866A1 · Stolfo · 2012 [cited by applicant]
US 20120086928A1 · Baselmans et al. · 2012 [cited by applicant]
US 20120106354A1 · Pleshek et al. · 2012 [cited by applicant]
US 20120110656A1 · Santos et al. · 2012 [cited by applicant]
US 20120113987A1 · Riddoch et al. · 2012 [cited by applicant]
US 20120240135A1 · Risbood et al. · 2012 [cited by applicant]
US 20120240185A1 · Kapoor et al. · 2012 [cited by applicant]
US 20120264443A1 · Ng et al. · 2012 [cited by applicant]
US 20120314617A1 · Erichsen et al. · 2012 [cited by applicant]
US 20120331543A1 · Bostrom et al. · 2012 [cited by applicant]
US 20130007257A1 · Ramaraj et al. · 2013 [cited by applicant]
US 20130047020A1 · Hershko et al. · 2013 [cited by applicant]
US 20130059527A1 · Hasesaka et al. · 2013 [cited by applicant]
US 20130061294A1 · Kenworthy · 2013 [cited by applicant]
US 20130104236A1 · Ray et al. · 2013 [cited by applicant]
US 20130117852A1 · Stute · 2013 [cited by applicant]
US 20130139236A1 · Rubinstein et al. · 2013 [cited by applicant]
US 20130254766A1 · Zuo et al. · 2013 [cited by applicant]
US 20130291100A1 · Ganapathy et al. · 2013 [cited by applicant]
US 20130305311A1 · Puttaswamy Naga et al. · 2013 [cited by applicant]
US 20140075510A1 · Sonoda et al. · 2014 [cited by applicant]
US 20140082204A1 · Shankar et al. · 2014 [cited by applicant]
US 20140082730A1 · Vashist et al. · 2014 [cited by applicant]
US 20140115654A1 · Rogers et al. · 2014 [cited by applicant]
US 20140150051A1 · Bharali et al. · 2014 [cited by applicant]
US 20140201123A1 · Ahn et al. · 2014 [cited by applicant]
US 20140215561A1 · Roberson et al. · 2014 [cited by applicant]
US 20140215574A1 · Erb et al. · 2014 [cited by applicant]
US 20140245423A1 · Lee · 2014 [cited by applicant]
US 20140259170A1 · Amsler · 2014 [cited by applicant]
US 20140281030A1 · Cui et al. · 2014 [cited by applicant]
US 20140283004A1 · Moore · 2014 [cited by applicant]
US 20140283030A1 · Moore et al. · 2014 [cited by applicant]
US 20140317397A1 · Martini · 2014 [cited by applicant]
US 20140317737A1 · Shin et al. · 2014 [cited by applicant]
US 20140337613A1 · Martini · 2014 [cited by applicant]
US 20140365372A1 · Ross et al. · 2014 [cited by applicant]
US 20140366132A1 · Stiansen et al. · 2014 [cited by applicant]
US 20150033336A1 · Wang et al. · 2015 [cited by applicant]
US 20150052601A1 · White et al. · 2015 [cited by applicant]
US 20150106930A1 · Honda et al. · 2015 [cited by applicant]
US 20150128274A1 · Giokas · 2015 [cited by applicant]
US 20150135325A1 · Stevens et al. · 2015 [cited by applicant]
US 20150207809A1 · Macaulay · 2015 [cited by applicant]
US 20150237012A1 · Moore · 2015 [cited by applicant]
US 20150244734A1 · Olson et al. · 2015 [cited by applicant]
US 20150256431A1 · Buchanan et al. · 2015 [cited by applicant]
US 20150304354A1 · Rogers et al. · 2015 [cited by applicant]
US 20150334125A1 · Bartos et al. · 2015 [cited by applicant]
US 20150341389A1 · Kurakami · 2015 [cited by applicant]
US 20150347246A1 · Matsui et al. · 2015 [cited by applicant]
US 20150350229A1 · Mitchell · 2015 [cited by applicant]
US 20150372977A1 · Yin · 2015 [cited by applicant]
US 20150373043A1 · Wang et al. · 2015 [cited by applicant]
US 20160020968A1 · Aumann et al. · 2016 [cited by applicant]
US 20160028751A1 · Cruz Mota et al. · 2016 [cited by applicant]
US 20160065611A1 · Fakeri-Tabrizi et al. · 2016 [cited by applicant]
US 20160112443A1 · Grossman et al. · 2016 [cited by applicant]
US 20160119365A1 · Barel · 2016 [cited by applicant]
US 20160127417A1 · Janssen · 2016 [cited by applicant]
US 20160191558A1 · Davison · 2016 [cited by applicant]
US 20160205069A1 · Blocher et al. · 2016 [cited by applicant]
US 20160219065A1 · Dasgupta et al. · 2016 [cited by applicant]
US 20160285706A1 · Rao · 2016 [cited by applicant]
US 20160294870A1 · Banerjee et al. · 2016 [cited by applicant]
US 20160366099A1 · Jordan · 2016 [cited by applicant]
US 20170223046A1 · Singh · 2017 [cited by applicant]
US 20170272469A1 · Kraemer et al. · 2017 [cited by applicant]
US 20200106742A1 · Moore · 2020 [cited by applicant]
AU 2005328336B2 · 2011 [cited by applicant]
AU 2006230171B2 · 2012 [cited by applicant]
CA 2600236A1 · 2006 [cited by applicant]
CN 101459660A · 2009 [cited by applicant]
CN 101651692A · 2010 [cited by applicant]
EP 1006701A2 · 2000 [cited by applicant]
EP 1313290A1 · 2003 [cited by applicant]
EP 1484884A2 · 2004 [cited by applicant]
EP 1677484A2 · 2006 [cited by applicant]
EP 2385676A1 · 2011 [cited by applicant]
EP 2498442A1 · 2012 [cited by applicant]
EP 1864226B1 · 2013 [cited by applicant]
KR 20010079361A · 2001 [cited by applicant]
WO 2005046145A1 · 2005 [cited by applicant]
WO 2006093557A2 · 2006 [cited by applicant]
WO 2006105093A2 · 2006 [cited by applicant]
WO 2007109541A2 · 2007 [cited by applicant]
WO 2011038420A2 · 2011 [cited by applicant]
WO 2012146265A1 · 2012 [cited by applicant]
WO 2017086928A1 · 2017 [cited by applicant]
G.V. Rooij, “Real Stateful TCP Packet Filtering in IP Filter”, Proceedings of the 10th USENIX Security Symposium, 2001. [cited by applicant]
Greenwald, Michael; “Designing an Academic Firewall: Policy, Practice, and Experience with Surf”; IEEE, Proceedings of SNDSS, 1996. [cited by applicant]
J. Xu et al., “Design and Evaluation of a High-Performance ATM Firewall Switch and Its Applications”, IEEE Journal on Selected Areas in Communications, 17(6): 1190-1200, Jun. 1999. [cited by applicant]
J.K. Lenstra et al., “Complexity of Scheduling Under Precedence Constraints”, Operations Research, 26(1): 22-35, 1978. [cited by applicant]
Kindervag, et al. “Build Security Into Your Network's DNA: The Zero Trust Network Architecture,” Forrester Research Inc.; Nov. 5, 2010, pp. 1-26. [cited by applicant]
L. Qui et al., “Fast Firewall Implementations for Software and Hardware-Based Routers”, Proceedings of ACM Sigmetrics, Jun. 2001. [cited by applicant]
Lee et al., “Development Framework for Firewall Processors,” IEEE, pp. 352-355 (2002). [cited by applicant]
M. Al-Suwaiyel et al., “Algorithms for Trie Compaction”, ACM Transactions on Database Systems, 9(2): 243-263, Jun. 1984. [cited by applicant]
M. Christiansen et al., “Using IDDs for Packet Filtering,” Technical Report, BRICS, Oct. 2002. [cited by applicant]
M. Degermark et al., “Small Forwarding Tables for Fast Routing Lookups”, Proceedings of ACM SIGCOMM, 4-13, 1997. [cited by applicant]
Mizuno et al., A New Remote Configurable Firewall System for Home-use Gateways, Jan. 2005. Second IEEE Consumer Communications and Networking Conference, pp. 599-601. [cited by applicant]
Moore, S, “SBIR Case Study: Centripetal Networks: How CNI Leveraged DHS S&T SBIR Funding to Launch a Successful Cyber Security Company,” 2012 Principal Investigators' Meeting, Cyber Security Division, Oct. 10, 2014. [cited by applicant]
Nichols, et al., “Definition of the Differentiated Services Field (DS Field) in the IPV4 and IPV6 Headers,” Network Working Group RFC 2474, Dec. 1998, 20 pages. [cited by applicant]
O. Paul et al., “A full Bandwidth ATM Firewall”, Proceedings of the 6th European Symposium on Research in Computer Security ESORICS'2000, 2000. [cited by applicant]
P. Warkhede et al., “Fast Packet Classification for Two-Dimensional Conflict-Free Filters”, Proceedings of IEEE INFOCOM, 1434-1443, 2001. [cited by applicant]
Palo Alto Networks; “Designing a Zero Trust Network With Next-Generation Firewalls”; pp. 1-10; last viewed on Oct. 21, 2012. [cited by applicant]
Perkins, “IP Encapsulation with IP,” Network Working Group RFC 2003, Oct. 1996, 14 pages. [cited by applicant]
R. Funke et al., “Performance Evaluation of Firewalls in Gigabit-Networks”, Proceedings of the Symposium on Performance Evaluation of Computer and Telecommunication Systems, 1999. [cited by applicant]
R. Rivest, “On Self-Organizing Sequential Search Heuristics”, Communications of the ACM, 19(2): 1976. [cited by applicant]
R.L. Graham et al., “Optimization and Approximation in Deterministic Sequencing and Scheduling: A Survey”, Annals of Discrete Mathematics, 5: 287-326, 1979. [cited by applicant]
Reumann, John; “Adaptive Packet Filters”; IEEE, 2001, Department of Electrical Engineering and Computer Science, the University of Michigan, Ann Arbor, MI. [cited by applicant]
S,M. Bellovin et al., “Network Firewalls”, IEEE Communications Magazine, 50-57, 1994. [cited by applicant]
S. Goddard et al., “An Unavailability Analysis of Firewall Sandwich Configurations”, Proceedings of the 6th IEEE Symposium on High Assurance Systems Engineering, 2001. [cited by applicant]
S. Suri et al., “Packet Filtering in High Speed Networks”, Proceedings of the Symposium on Discrete Algorithms, 969-970, 1999. [cited by applicant]
Singh, Rajeev et al. “Detecting and Reducing the Denial of Service attacks in WLANs”, Dec. 2011, World Congress on Information and Communication TEchnologies, pp. 968-973. [cited by applicant]
Sourcefire 3D System User Guide, Version 4.10, Mar. 16, 2011, 2123 pages. [cited by applicant]
Statement RE: Related Application, dated Jul. 24, 2015. [cited by applicant]
Tarsa et al., “Balancing Trie-Based Policy representations for Network Firewalls,” Department of Computer Science, Wake Forest University, pp. 1-6 (2006). [cited by applicant]
U. Ellermann et al., “Firewalls for ATM Networks”, Proceedings of INFOSEC'COM, 1998. [cited by applicant]
V. Srinivasan et al., “Fast and Scalable Layer Four Switching”, Proceedings of ACM SIGCOMM, 191-202, 1998. [cited by applicant]
V.P. Ranganath, “A Set-Based Approach to Packet Classification”, Proceedings of the IASTED International Conference on Parallel and Distributed Computing and Systems, 889-894, 2003. [cited by applicant]
W.E. Leland et al., “On the Self-Similar Nature of Ethernet Traffic”, IEEE Transactions on Networking, 2(1); 15, 1994. [cited by applicant]
W.E. Smith, “Various Optimizers for Single-Stage Productions”, Naval Research Logistics Quarterly, 3: 59-66, 1956. [cited by applicant]
X. Gan et al., “LSMAC vs. LSNAT: Scalable Cluster-based Web servers”, Journal of Networks, Software Tools, and Applications, 3(3): 175-185, 2000. [cited by applicant]
Ylonen, et al., “The Secure Shell (SSH) Transport Layer Protocol,” SSH Communication Security Corp, Newtork Working Group RFC 4253, Jan. 2006, 32 pages. [cited by applicant]
Mar. 11, 2019 (US) Final Office Action—U.S. Appl. No. 16/030,354. [cited by applicant]
Feb. 21, 2019 (US) Final Office Action—U.S. Appl. No. 15/382,806. [cited by applicant]
Jan. 24, 2019 (US) Decision—Institution of Inter Partes Review of U.S. Pat. No. 9,160,713 B2—IPR 2018-01437. [cited by applicant]
Mar. 8, 2019 (US) Notice of Allowance and Fees Due—U.S. Appl. No. 16/030,374. [cited by applicant]
Aug. 21, 2018 (US) Petition for Inter Partes Review of U.S. Pat. No. 9,686,193—IPR2018-01559. [cited by applicant]
Aug. 15, 2018 (US) Declaration of Staurt Staniford, PhD in Support of Petition for Inter Partes Review of U.S. Pat. No. 9,686,193—IPR2018-01556. [cited by applicant]
Jan. 24, 2019 (US) Decision—Institution of Inter Partes Review of U.S. Pat. No. 9,124,552 B2—IPR 2018-01436. [cited by applicant]
Mar. 18, 2019 (AU) First Examination Report—App. 2016379156. [cited by applicant]
Apr. 8, 2019 (US) Final Office Action—U.S. Appl. No. 15/413,947. [cited by applicant]
Aug. 10, 2018 (US) Declaration of Kevin Jeffay, PhD in Support of Fourth Petition for Inter Partes Review of U.S. Pat. No. 9,137,205—IPR2018-01506. [cited by applicant]
Aug. 10, 2018 (US) Fourth Petition for Inter Partes Review of U.S. Pat. No. 9,137,205—IPR2018-01506. [cited by applicant]
Aug. 3, 2018 (US) Third Petition for Inter Partes Review of U.S. Pat. No. 9,137,205—IPR2018-01505. [cited by applicant]
Aug. 3, 2018 (US) Declaration of Kevin Jeffay, PhD in Support of Third Petition for Inter Partes Review of U.S. Pat. No. 9,137,205—IPR2018-01505. [cited by applicant]
Aug. 3, 2018 (US) Declaration of Kevin Jeffay, PhD in Support of Third Petition for Inter Partes Review of U.S. Pat. No. 9,560,077—IPR2018-01513. [cited by applicant]
Jul. 20, 2018 (US) Petition for Inter Partes Review of U.S. Pat. No. 9,160,713—IPR2018-01437. [cited by applicant]
Jul. 26, 2018 (US) Declaration of Kevin Jeffay, PhD in Support of First Petition for Inter Partes Review of U.S. Pat. No. 9,137,205—IPR2018-01443. [cited by applicant]
Jul. 26, 2018 (US) Declaration of Kevin Jeffay, PhD in Support of Second Petition for Inter Partes Review of U.S. Pat. No. 9,137,205—IPR2018-01444. [cited by applicant]
Jul. 27, 2018 (US) First Petition for Inter Partes Review of U.S. Pat. No. 9,137,205—IPR2018-01443. [cited by applicant]
Jul. 27, 2018 (US) Non-Final Office Action—U.S. Appl. No. 15/382,806. [cited by applicant]
Jul. 27, 2018 (US) Second Petition for Inter Partes Review of U.S. Pat. No. 9,137,205—IPR2018-01444. [cited by applicant]
Jul. 5, 2018 (US) Non-Final Office Action—U.S. Appl. No. 15/413,750. [cited by applicant]
Mar. 15, 2018 (EP) Second Communication pursuant to Article 94(3) EPC—App. 13765547.8. [cited by applicant]
Mar. 16, 2018 (EP) Communication Pursuant to Rule 164(2)(b) and Article 94(3) EPC—App. 15722292.8. [cited by applicant]
Mar. 21, 2018 (AU) First Examination Report—App. 2015382393. [cited by applicant]
Mar. 8, 2018 (US) Non-Final Office Action—U.S. Appl. No. 14/745,207. [cited by applicant]
May 25, 2018 (US) Notice of Allowance—U.S. Appl. No. 15/413,834. [cited by applicant]
Nov. 14, 2018 (US) Final Office Action—U.S. Appl. No. 14/745,207. [cited by applicant]
Oct. 12, 2018 (US) Non-Final Office Action—U.S. Appl. No. 16/039,896. [cited by applicant]
Oct. 4, 2018 (US) Non-Final Office Action—U.S. Appl. No. 16/030,374. [cited by applicant]
Oct. 4, 2018 (US) Notice of Allowance—U.S. Appl. No. 15/827,477. [cited by applicant]
Sep. 17, 2018 (US) Declaration of Narasimha Reddy Ph.D., in Support of Petition for Inter Partes Review of U.S. Pat. No. 9,560,176 (First)—IRP2018-01654. [cited by applicant]
Sep. 17, 2018 (US) Declaration of Narasimha Reddy Ph.D., in Support of Petition for Inter Partes Review of U.S. Pat. No. 9,560,176 (Second)—IRP2018-01655. [cited by applicant]
Sep. 17, 2018 (US) Petition for Inter Partes Review of U.S. Pat. No. 9,560,176 (First) IPR 2018-01654. [cited by applicant]
Sep. 17, 2018 (US) Petition for Inter Partes review of U.S. Pat. No. 9,560,176 (Second)—IPR2018-01655. [cited by applicant]
Sep. 27, 2018 (WO) International Search Report and Written Opinion—App. PCT/US2018/043367. [cited by applicant]
Sep. 4, 2018 (WO) International Search Report and Written Opinion—App. PCT/US2018/041355. [cited by applicant]
Sep. 27, 2018 (US) Non-Final Office Action—U.S. Appl. No. 15/614,956. [cited by applicant]
Feb. 6, 2019 (US) Final Office Action—U.S. Appl. No. 15/413,750. [cited by applicant]
Feb. 6, 2019 (US) Notice of Allowance and Fees Due—U.S. Appl. No. 16/039,896. [cited by applicant]
Jan. 24, 2019 (US) Notice of Allowance—U.S. Appl. No. 15/610,995. [cited by applicant]
Mar. 8, 2019 (US) Notice of Allowance and Fees Due—U.S. Appl. No. 16/060,374. [cited by applicant]
A. Feldmann et al., “Tradeoffs for Packet Classification”, Proceedings of the IEEE INFOCOM, 397-413, 2000. [cited by applicant]
A. Hari et al., “Detecting and Resolving Packet Filter Conflicts”, Proceedings of IEEE INFOCOM, 1203-1212, 2000. [cited by applicant]
Acharya et al., “OptWall: A Hierarchical Traffic-Aware Firewall,” Department of Computer Science, Telecommunications Program, University of Pittsburgh, pp. 1-11 (2007). [cited by applicant]
Anonymous: “The Distribution of Malicious Domains,” The DomainTools Report, 2016 Edition, Mar. 9, 2016 (Mar. 9, 2016), pp. 1-11, XP055502306, Retrieved from: https://www.domaintools.com/resources/white-papers/the-domain… [cited by applicant]
Bellion, “High Performance Packet Classification”, http://www.hipac.org (Publication Date Unknown). [cited by applicant]
Blake, et al., “An Architecture for Differentiated Services,” Network Working Group RFC 2475, Dec. 1998, 36 pages. [cited by applicant]
C. Benecke, “A Parallel Packet Screen for High Speed Networks”, Proceedings of the 15th Annual Computer Security Applications Conference, 1999. [cited by applicant]
Chen, et al, “Research on the Anomaly Discovering Algorithm of the Packet Filtering Rule Sets,” Sep. 2010, First International Confererence on Pervasive Computing, Signal Processing and Applications, pp. 362-366. [cited by applicant]
D. Comer, “Analysis of a Heuristic for Full Trie Minimization”, ACM Transactions on Database Systems, 6(3): 513-537, Sep. 1981. [cited by applicant]
D. Decasper et al., “Router Plugins: A Software Architecture for Next-Generation Routers”, IEEE/ACM Transactions on Networking, 8(1): Feb. 2000. [cited by applicant]
D. Eppstein et al., “Internet Packet Filter Management and Rectangle Geometry”, Proceedings of the Symposium on Discrete Algorithms, 827-835, 2001. [cited by applicant]
E. Al-Shaer et al., “Firewall Policy Advisor for Anomaly Discovery and Rule Editing”, Proceedings of the IFIP/IEEE International Symposium on Integrated Network Management, 2003. [cited by applicant]
E. Al-Shaer et al., “Modeling and Management of Firewall Policies”, IEEE Transactions on Network and Service Management, 1(1): 2004. [cited by applicant]
E. Fulp et al., “Network Firewall Policy Tries”, Technical Report, Computer Science Department, Wake Forest University, 2004. [cited by applicant]
E. Fulp, “Optimization of Network Firewall Policies Using Ordered Sets and Directed Acyclical Graphs”, Technical Report, Computer Scient Department, Wake Forest University, Jan. 2004. [cited by applicant]
E. Fulp, “Preventing Denial of Service Attacks on Quality of Service”, Proceedings of the 2001 DARPA Information Survivability Conference and Exposition II, 2001. [cited by applicant]
E.L. Lawler, “Sequencing Jobs to Minimize Total Weighted Completion Time Subject to Precedence Constraints”, Annals of Discrete Mathematics, 2: 75-90, 1978. [cited by applicant]