IP Library Granted Patent US 12,452,270
Granted Patent B2
US 12,452,270 · App. 17/980,623 · Granted Oct 21, 2025

Protecting networks from cyber attacks and overloading

Inventors: Sean Moore (Hollis, NH); Steven Rogers (Leesburg, VA); John Daniel Scoggins, Sr. (Leesburg, VA)
Assignee: Centripetal Networks, LLC
H04L63/1425H04L47/11H04L63/0227H04L63/0236H04L63/0263H04L63/14H04L63/1408H04L63/1441H04L63/1458
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,452,270
App. No.
17/980,623
Granted
Oct 21, 2025
Kind
B2
Abstract

Packets may be received by a packet security gateway. Responsive to a determination that an overload condition has occurred in one or more networks associated with the packet security gateway, a first group of packet filtering rules may be applied to at least some of the packets. Applying the first group of packet filtering rules may include allowing at least a first portion of the packets to continue toward their respective destinations. Responsive to a determination that the overload condition has been mitigated, a second group of packet filtering rules may be applied to at least some of the packets. Applying the second group of packet filtering rules may include allowing at least a second portion of the packets to continue toward their respective destinations.

Claims (95)

1. A method comprising:

receiving, by a packet-filtering device located at an internet access point, a first group of packet filtering rules and a second group of packet filtering rules, wherein:

the first group of packet filtering rules comprise rules for handling network traffic, during an overload condition, associated with one or more first devices identified as associated with one or more emergency services and that is directed to one or more communication applications; and

the second group of packet filtering rules comprise rules for handling network traffic, during the overload condition, associated with one or more second devices identified as not being associated with one or more emergency services;

receiving, via a first network and during a first overload condition, a plurality of packets;

applying, based on a determination that a first subset of the plurality of packets are associated with the one or more first devices and based on a determination that the first subset of the plurality of packets are associated with the one or more communication applications, the first group of packet filtering rules to allow the first subset of the plurality of packets to access the one or more communication applications hosted on one or more application servers connected to a second network; and

applying, based on a determination that a second subset of the plurality of packets are associated with the one or more second devices, the second group of packet filtering rules to prevent the second subset of the plurality of packets from accessing the one or more communication applications hosted on the one or more application servers connected to the second network.

2. The method of claim 1 , further comprising:

receiving, by the packet-filtering device located at the internet access point and based on a determination that the first overload condition has been mitigated to a first degree, a third group of packet filtering rules; and

applying the third group of packet filtering rules to the second subset of the plurality of packets to allow a first portion of the second subset of the plurality of packets to access the one or more communication applications hosted on the one or more application servers connected to the second network.

3. The method of claim 1 , further comprising:

determining that the first subset of the plurality of packets are associated with the one or more first devices based on one or more source addresses associated with the first subset of the plurality of packets.

4. The method of claim 1 , further comprising:

determining that the first subset of the plurality of packets are associated with the one or more first devices based on one or more destination addresses associated with the first subset of the plurality of packets.

5. The method of claim 1 , further comprising:

determining that a third subset of packets, of the plurality of packets, comprises gateway protocol data; and

applying, based on a determination that the first group of packet filtering rules applies to the gateway protocol data, the first group of packet filtering rules to the third subset of packets to allow the third subset of packets to continue toward its destination.

6. The method of claim 1 , further comprising:

determining that a third subset of packets, of the plurality of packets, comprises domain name system (DNS) data; and

applying, based on a determination that the first group of packet filtering rules applies to DNS data, the first group of packet filtering rules to the third subset of packets to allow the third subset of packets to continue toward its destination.

7. The method of claim 1 , further comprising:

determining that a third subset of packets, of the plurality of packets, comprises network time protocol (NTP) data; and

applying, based on a determination that the first group of packet filtering rules applies to NTP data, the first group of packet filtering rules to the third subset of packets to allow the third subset of packets to continue toward its destination.

8. The method of claim 1 , wherein the receiving the first group of packet filtering rules and the second group of packet filtering rules comprises:

receiving the first group of packet filtering rules and the second group of packet filtering rules via a management network, wherein the management network is out-of-band relative to the second network.

9. The method of claim 1 , wherein the one or more communication applications comprise at least one of:

telephony;

messaging;

e-mail; or

web.

10. The method of claim 1 , wherein the overload condition comprises a denial of service attack.

11. A packet filtering device, located at an internet access point, comprising:

one or more processors; and

memory storing instructions that, when executed by the one or more processors, cause the packet filtering device to:

receive a first group of packet filtering rules and a second group of packet filtering rules, wherein:

the first group of packet filtering rules comprise rules for handling network traffic, during an overload condition, associated with one or more first devices identified as associated with one or more emergency services and that is directed to one or more communication applications; and

the second group of packet filtering rules comprise rules for handling network traffic, during the overload condition, associated with one or more second devices identified as not being associated with one or more emergency services;

receive, via a first network and during a first overload condition, a plurality of packets;

apply, based on a determination that a first subset of the plurality of packets are associated with the one or more first devices and based on a determination that the first subset of the plurality of packets are associated with the one or more communication applications, the first group of packet filtering rules to allow the first subset of the plurality of packets to access the one or more communication applications hosted on one or more application servers connected to a second network; and

apply, based on a determination that a second subset of the plurality of packets are associated with the one or more second devices, the second group of packet filtering rules to prevent the second subset of the plurality of packets from accessing the one or more communication applications hosted on the one or more application servers connected to the second network.

12. The packet filtering device of claim 11 , wherein the instructions, when executed by the one or more processors, cause the packet filtering device to:

receive, based on a determination that the first overload condition has been mitigated to a first degree, a third group of packet filtering rules; and

apply the third group of packet filtering rules to the second subset of the plurality of packets to allow a first portion of the second subset of the plurality of packets to access the one or more communication applications hosted on the one or more application servers connected to the second network.

13. The packet filtering device of claim 11 , wherein the instructions, when executed by the one or more processors, cause the packet filtering device to:

determine that the first subset of the plurality of packets are associated with the one or more first devices based on one or more source addresses associated with the first subset of the plurality of packets.

14. The packet filtering device of claim 11 , wherein the instructions, when executed by the one or more processors, cause the packet filtering device to:

determine that the first subset of the plurality of packets are associated with the one or more first devices based on one or more destination addresses associated with the first subset of the plurality of packets.

15. The packet filtering device of claim 11 , wherein the instructions, when executed by the one or more processors, cause the packet filtering device to:

determine that a third subset of packets, of the plurality of packets, comprises gateway protocol data; and

apply, based on a determination that the first group of packet filtering rules applies to the gateway protocol data, the first group of packet filtering rules to the third subset of packets to allow the third subset of packets to continue toward its destination.

16. The packet filtering device of claim 11 , wherein the instructions, when executed by the one or more processors, cause the packet filtering device to:

determine that a third subset of packets, of the plurality of packets, comprises domain name system (DNS) data; and

apply, based on a determination that the first group of packet filtering rules applies to DNS data, the first group of packet filtering rules to the third subset of packets to allow the third subset of packets to continue toward its destination.

17. The packet filtering device of claim 11 , wherein the instructions, when executed by the one or more processors, cause the packet filtering device to:

determine that a third subset of packets, of the plurality of packets, comprises network time protocol (NTP) data; and

apply, based on a determination that the first group of packet filtering rules applies to NTP data, the first group of packet filtering rules to the third subset of packets to allow the third subset of packets to continue toward its destination.

18. The packet filtering device of claim 11 , wherein the instructions, when executed by the one or more processors, cause the packet filtering device to:

receiving the first group of packet filtering rules and the second group of packet filtering rules via a management network, wherein the management network is out-of-band relative to the second network.

19. The packet filtering device of claim 11 , wherein the one or more communication applications comprise at least one of:

telephony;

messaging;

e-mail; or

web.

20. The packet filtering device of claim 11 , wherein the overload condition comprises a denial of service attack.

21. A non-transitory computer-readable medium comprising instructions that, when executed, configure a packet-filtering device, located at an internet access point, to:

receive a first group of packet filtering rules and a second group of packet filtering rules, wherein:

the first group of packet filtering rules comprise rules for handling network traffic, during an overload condition, associated with one or more first devices identified as associated with one or more emergency services and that is directed to one or more communication applications; and

the second group of packet filtering rules comprise rules for handling network traffic, during the overload condition, associated with one or more second devices identified as not being associated with one or more emergency services;

receive, via a first network and during a first overload condition, a plurality of packets;

apply, based on a determination that a first subset of the plurality of packets are associated with the one or more first devices and based on a determination that the first subset of the plurality of packets are associated with the one or more communication applications, the first group of packet filtering rules to allow the first subset of the plurality of packets to access the one or more communication applications hosted on one or more application servers connected to a second network; and

apply, based on a determination that a second subset of the plurality of packets are associated with the one or more second devices, the second group of packet filtering rules to prevent the second subset of the plurality of packets from accessing the one or more communication applications hosted on the one or more application servers connected to the second network.

22. The non-transitory computer-readable medium of claim 21 , wherein the instructions, when executed, configure the packet-filtering device to:

receive, based on a determination that the first overload condition has been mitigated to a first degree, a third group of packet filtering rules; and

apply the third group of packet filtering rules to the second subset of the plurality of packets to allow a first portion of the second subset of the plurality of packets to access the one or more communication applications hosted on the one or more application servers connected to the second network.

23. The non-transitory computer-readable medium of claim 21 , wherein the instructions, when executed, configure the packet-filtering device to:

determine that the first subset of the plurality of packets are associated with the one or more first devices based on one or more source addresses associated with the first subset of the plurality of packets.

24. The non-transitory computer-readable medium of claim 21 , wherein the instructions, when executed, configure the packet-filtering device to:

determine that the first subset of the plurality of packets are associated with the one or more first devices based on one or more destination addresses associated with the first subset of the plurality of packets.

25. The non-transitory computer-readable medium of claim 21 , wherein the instructions, when executed, configure the packet-filtering device to:

determine that a third subset of packets, of the plurality of packets, comprises gateway protocol data; and

apply, based on a determination that the first group of packet filtering rules applies to the gateway protocol data, the first group of packet filtering rules to the third subset of packets to allow the third subset of packets to continue toward its destination.

26. The non-transitory computer-readable medium of claim 21 , wherein the instructions, when executed, configure the packet-filtering device to:

determine that a third subset of packets, of the plurality of packets, comprises domain name system (DNS) data; and

apply, based on a determination that the first group of packet filtering rules applies to DNS data, the first group of packet filtering rules to the third subset of packets to allow the third subset of packets to continue toward its destination.

27. The non-transitory computer-readable medium of claim 21 , wherein the instructions, when executed, configure the packet-filtering device to:

determine that a third subset of packets, of the plurality of packets, comprises network time protocol (NTP) data; and

apply, based on a determination that the first group of packet filtering rules applies to NTP data, the first group of packet filtering rules to the third subset of packets to allow the third subset of packets to continue toward its destination.

28. The non-transitory computer-readable medium of claim 21 , wherein the instructions, when executed, configure the packet-filtering device to:

receiving the first group of packet filtering rules and the second group of packet filtering rules via a management network, wherein the management network is out-of-band relative to the second network.

29. The non-transitory computer-readable medium of claim 21 , wherein the one or more communication applications comprise at least one of:

telephony;

messaging;

e-mail; or

web.

30. The non-transitory computer-readable medium of claim 21 , wherein the overload condition comprises a denial of service attack.

Assignments (2)
CHANGE OF NAME Recorded Feb 7, 2023
From: CENTRIPETAL NETWORKS, INC.
To: CENTRIPETAL NETWORKS, LLC
Reel/Frame 062666/0239 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 4, 2022
From: MOORE, SEAN; ROGERS, STEVEN; SCOGGINS, JOHN DANIEL, SR.
To: CENTRIPETAL NETWORKS, INC.
Reel/Frame 061655/0075 →
Continuity (4)
Continuation 17089911 · Nov 5, 2020
Continuation 14745207 · Jun 19, 2015
Continuation 13838471 · Mar 15, 2013
Related Publication 20230126426A1 · Apr 27, 2023
References Cited (400)
US 6098172A · Coss et al. · 2000 [cited by applicant]
US 6147976A · Shand et al. · 2000 [cited by applicant]
US 6226372B1 · Beebe et al. · 2001 [cited by applicant]
US 6279113B1 · Vaidya · 2001 [cited by applicant]
US 6317837B1 · Kenworthy · 2001 [cited by applicant]
US 6484261B1 · Wiegel · 2002 [cited by applicant]
US 6611875B1 · Chopra et al. · 2003 [cited by applicant]
US 6662235B1 · Callis et al. · 2003 [cited by applicant]
US 6678827B1 · Rothermel et al. · 2004 [cited by applicant]
US 6826694B1 · Dutta et al. · 2004 [cited by applicant]
US 6907042B1 · Oguchi · 2005 [cited by applicant]
US 6971028B1 · Lyle et al. · 2005 [cited by applicant]
US 7089581B1 · Nagai et al. · 2006 [cited by applicant]
US 7095716B1 · Ke et al. · 2006 [cited by applicant]
US 7107613B1 · Chen et al. · 2006 [cited by applicant]
US 7143438B1 · Coss et al. · 2006 [cited by applicant]
US 7152240B1 · Green et al. · 2006 [cited by applicant]
US 7185368B2 · Copeland, III · 2007 [cited by applicant]
US 7215637B1 · Ferguson et al. · 2007 [cited by applicant]
US 7225269B2 · Watanabe · 2007 [cited by applicant]
US 7227842B1 · Ji et al. · 2007 [cited by applicant]
US 7237267B2 · Rayes et al. · 2007 [cited by applicant]
US 7263099B1 · Woo et al. · 2007 [cited by applicant]
US 7296288B1 · Hill et al. · 2007 [cited by applicant]
US 7299353B2 · Le Pennec et al. · 2007 [cited by applicant]
US 7331061B1 · Ramsey et al. · 2008 [cited by applicant]
US 7478429B2 · Lyon · 2009 [cited by applicant]
US 7499412B2 · Matityahu et al. · 2009 [cited by applicant]
US 7539186B2 · Aerrabotu et al. · 2009 [cited by applicant]
US 7610621B2 · Turley et al. · 2009 [cited by applicant]
US 7684400B2 · Govindarajan et al. · 2010 [cited by applicant]
US 7710885B2 · Ilnicki · 2010 [cited by examiner]
US 7721084B2 · Salminen et al. · 2010 [cited by applicant]
US 7792775B2 · Matsuda · 2010 [cited by applicant]
US 7814158B2 · Malik · 2010 [cited by applicant]
US 7814546B1 · Strayer et al. · 2010 [cited by applicant]
US 7818794B2 · Wittman · 2010 [cited by applicant]
US 7849502B1 · Bloch et al. · 2010 [cited by applicant]
US 7913303B1 · Rouland et al. · 2011 [cited by applicant]
US 7954143B2 · Aaron · 2011 [cited by applicant]
US 8004994B1 · Darisi et al. · 2011 [cited by applicant]
US 8009566B2 · Zuk et al. · 2011 [cited by applicant]
US 8037517B2 · Fulp et al. · 2011 [cited by applicant]
US 8042167B2 · Fulp et al. · 2011 [cited by applicant]
US 8117655B2 · Spielman · 2012 [cited by applicant]
US 8156206B2 · Kiley et al. · 2012 [cited by applicant]
US 8176561B1 · Hurst et al. · 2012 [cited by applicant]
US 8219675B2 · Ivershen · 2012 [cited by applicant]
US 8271645B2 · Rajan et al. · 2012 [cited by applicant]
US 8306994B2 · Kenworthy · 2012 [cited by applicant]
US 8307029B2 · Davis et al. · 2012 [cited by applicant]
US 8331234B1 · Newton et al. · 2012 [cited by applicant]
US 8422391B2 · Zhu · 2013 [cited by applicant]
US 8495725B2 · Ahn · 2013 [cited by applicant]
US 8510821B1 · Brandwine et al. · 2013 [cited by applicant]
US 8726379B1 · Stiansen et al. · 2014 [cited by applicant]
US 8789135B1 · Pani · 2014 [cited by applicant]
US 8806638B1 · Mani · 2014 [cited by applicant]
US 8832832B1 · Visbal · 2014 [cited by applicant]
US 8856926B2 · Narayanaswamy et al. · 2014 [cited by applicant]
US 8935785B2 · Pandrangi · 2015 [cited by applicant]
US 9094445B2 · Moore et al. · 2015 [cited by applicant]
US 9124552B2 · Moore · 2015 [cited by applicant]
US 9137205B2 · Rogers et al. · 2015 [cited by applicant]
US 9154446B2 · Gemelli et al. · 2015 [cited by applicant]
US 9160713B2 · Moore · 2015 [cited by applicant]
US 9172627B2 · Kjendal et al. · 2015 [cited by applicant]
US 9419942B1 · Buruganahalli et al. · 2016 [cited by applicant]
US 9531672B1 · Li et al. · 2016 [cited by applicant]
US 9634911B2 · Meloche · 2017 [cited by applicant]
US 9686193B2 · Moore · 2017 [cited by applicant]
US 20010039579A1 · Trcka et al. · 2001 [cited by applicant]
US 20010039624A1 · Kellum · 2001 [cited by applicant]
US 20020016858A1 · Sawada et al. · 2002 [cited by applicant]
US 20020038339A1 · Xu · 2002 [cited by applicant]
US 20020049899A1 · Kenworthy · 2002 [cited by applicant]
US 20020083345A1 · Halliday et al. · 2002 [cited by applicant]
US 20020112188A1 · Syvanne · 2002 [cited by applicant]
US 20020152209A1 · Merugu et al. · 2002 [cited by applicant]
US 20020164962A1 · Mankins et al. · 2002 [cited by applicant]
US 20020165949A1 · Na et al. · 2002 [cited by applicant]
US 20020186683A1 · Buck et al. · 2002 [cited by applicant]
US 20020198981A1 · Corl et al. · 2002 [cited by applicant]
US 20030005122A1 · Freimuth et al. · 2003 [cited by applicant]
US 20030014665A1 · Anderson et al. · 2003 [cited by applicant]
US 20030018591A1 · Komisky · 2003 [cited by applicant]
US 20030035370A1 · Brustoloni · 2003 [cited by applicant]
US 20030051026A1 · Carter et al. · 2003 [cited by applicant]
US 20030088787A1 · Egevang · 2003 [cited by applicant]
US 20030097590A1 · Syvanne · 2003 [cited by applicant]
US 20030105976A1 · Copeland · 2003 [cited by applicant]
US 20030120622A1 · Nurmela et al. · 2003 [cited by applicant]
US 20030123456A1 · Denz et al. · 2003 [cited by applicant]
US 20030142681A1 · Chen et al. · 2003 [cited by applicant]
US 20030145225A1 · Bruton et al. · 2003 [cited by applicant]
US 20030154297A1 · Suzuki et al. · 2003 [cited by applicant]
US 20030154399A1 · Zuk et al. · 2003 [cited by applicant]
US 20030188192A1 · Tang et al. · 2003 [cited by applicant]
US 20030212900A1 · Liu et al. · 2003 [cited by applicant]
US 20030220940A1 · Futoransky et al. · 2003 [cited by applicant]
US 20040010712A1 · Hui et al. · 2004 [cited by applicant]
US 20040015719A1 · Lee et al. · 2004 [cited by applicant]
US 20040073655A1 · Kan et al. · 2004 [cited by applicant]
US 20040088542A1 · Daude et al. · 2004 [cited by applicant]
US 20040093513A1 · Cantrell et al. · 2004 [cited by applicant]
US 20040098511A1 · Lin et al. · 2004 [cited by applicant]
US 20040114518A1 · MacFaden et al. · 2004 [cited by applicant]
US 20040123220A1 · Johnson et al. · 2004 [cited by applicant]
US 20040131056A1 · Dark · 2004 [cited by applicant]
US 20040148520A1 · Talpade et al. · 2004 [cited by applicant]
US 20040151155A1 · Jouppi · 2004 [cited by applicant]
US 20040172529A1 · Culbert · 2004 [cited by applicant]
US 20040172557A1 · Nakae et al. · 2004 [cited by applicant]
US 20040177139A1 · Schuba et al. · 2004 [cited by applicant]
US 20040181690A1 · Rothermel et al. · 2004 [cited by applicant]
US 20040193943A1 · Angelino et al. · 2004 [cited by applicant]
US 20040199629A1 · Bomer et al. · 2004 [cited by applicant]
US 20040205360A1 · Norton et al. · 2004 [cited by applicant]
US 20040250124A1 · Chesla et al. · 2004 [cited by applicant]
US 20050010765A1 · Swander et al. · 2005 [cited by applicant]
US 20050024189A1 · Weber · 2005 [cited by applicant]
US 20050071650A1 · Jo et al. · 2005 [cited by applicant]
US 20050076227A1 · Kang et al. · 2005 [cited by applicant]
US 20050108557A1 · Kayo et al. · 2005 [cited by applicant]
US 20050114704A1 · Swander · 2005 [cited by applicant]
US 20050117576A1 · McDysan et al. · 2005 [cited by applicant]
US 20050125697A1 · Tahara · 2005 [cited by applicant]
US 20050138204A1 · Iyer et al. · 2005 [cited by applicant]
US 20050138353A1 · Spies et al. · 2005 [cited by applicant]
US 20050141537A1 · Kumar et al. · 2005 [cited by applicant]
US 20050183140A1 · Goddard · 2005 [cited by applicant]
US 20050229246A1 · Rajagopal et al. · 2005 [cited by applicant]
US 20050249214A1 · Peng · 2005 [cited by applicant]
US 20050251570A1 · Heasman et al. · 2005 [cited by applicant]
US 20050283823A1 · Okajo et al. · 2005 [cited by applicant]
US 20050286522A1 · Paddon et al. · 2005 [cited by applicant]
US 20060031928A1 · Conley et al. · 2006 [cited by applicant]
US 20060048142A1 · Roese · 2006 [cited by examiner]
US 20060053491A1 · Khuti et al. · 2006 [cited by applicant]
US 20060070122A1 · Bellovin · 2006 [cited by applicant]
US 20060080733A1 · Khosmood et al. · 2006 [cited by applicant]
US 20060085849A1 · Culbert · 2006 [cited by applicant]
US 20060104202A1 · Reiner · 2006 [cited by applicant]
US 20060114899A1 · Toumura et al. · 2006 [cited by applicant]
US 20060133377A1 · Jain · 2006 [cited by applicant]
US 20060136987A1 · Okuda · 2006 [cited by applicant]
US 20060137009A1 · Chesla · 2006 [cited by applicant]
US 20060146879A1 · Anthias et al. · 2006 [cited by applicant]
US 20060159028A1 · Curran-Gray et al. · 2006 [cited by applicant]
US 20060195896A1 · Fulp et al. · 2006 [cited by applicant]
US 20060212572A1 · Afek et al. · 2006 [cited by applicant]
US 20060248580A1 · Fulp et al. · 2006 [cited by applicant]
US 20060262798A1 · Joshi et al. · 2006 [cited by applicant]
US 20070056038A1 · Lok · 2007 [cited by applicant]
US 20070083924A1 · Lu · 2007 [cited by applicant]
US 20070118894A1 · Bhatia · 2007 [cited by applicant]
US 20070147380A1 · Ormazabal et al. · 2007 [cited by applicant]
US 20070211644A1 · Ottamalika et al. · 2007 [cited by applicant]
US 20070240208A1 · Yu et al. · 2007 [cited by applicant]
US 20070291789A1 · Kutt et al. · 2007 [cited by applicant]
US 20080005795A1 · Acharya et al. · 2008 [cited by applicant]
US 20080028467A1 · Kommareddy et al. · 2008 [cited by applicant]
US 20080043739A1 · Suh et al. · 2008 [cited by applicant]
US 20080072307A1 · Maes · 2008 [cited by applicant]
US 20080077705A1 · Li et al. · 2008 [cited by applicant]
US 20080080493A1 · Weintraub et al. · 2008 [cited by applicant]
US 20080086435A1 · Chesla · 2008 [cited by applicant]
US 20080101234A1 · Nakil et al. · 2008 [cited by applicant]
US 20080163333A1 · Kasralikar · 2008 [cited by applicant]
US 20080201772A1 · Mondaeev et al. · 2008 [cited by applicant]
US 20080229415A1 · Kapoor et al. · 2008 [cited by applicant]
US 20080235755A1 · Blaisdell et al. · 2008 [cited by applicant]
US 20080279196A1 · Friskney et al. · 2008 [cited by applicant]
US 20080301765A1 · Nicol et al. · 2008 [cited by applicant]
US 20080313738A1 · Enderby · 2008 [cited by applicant]
US 20080320116A1 · Briggs · 2008 [cited by applicant]
US 20090028160A1 · Eswaran et al. · 2009 [cited by applicant]
US 20090138938A1 · Harrison et al. · 2009 [cited by applicant]
US 20090144819A1 · Babbar et al. · 2009 [cited by applicant]
US 20090150972A1 · Moon et al. · 2009 [cited by applicant]
US 20090172800A1 · Wool · 2009 [cited by applicant]
US 20090222877A1 · Diehl et al. · 2009 [cited by applicant]
US 20090240698A1 · Shukla et al. · 2009 [cited by applicant]
US 20090262723A1 · Pelletier et al. · 2009 [cited by applicant]
US 20090262741A1 · Jungck et al. · 2009 [cited by applicant]
US 20090300759A1 · Wang et al. · 2009 [cited by applicant]
US 20090328219A1 · Narayanaswamy · 2009 [cited by applicant]
US 20100011433A1 · Harrison et al. · 2010 [cited by applicant]
US 20100011434A1 · Kay · 2010 [cited by applicant]
US 20100082811A1 · Van Der Merwe et al. · 2010 [cited by applicant]
US 20100095367A1 · Narayanaswamy · 2010 [cited by applicant]
US 20100107240A1 · Thaler et al. · 2010 [cited by applicant]
US 20100115621A1 · Staniford et al. · 2010 [cited by applicant]
US 20100132027A1 · Ou · 2010 [cited by applicant]
US 20100195503A1 · Raleigh · 2010 [cited by applicant]
US 20100199346A1 · Ling et al. · 2010 [cited by applicant]
US 20100202299A1 · Strayer et al. · 2010 [cited by applicant]
US 20100211678A1 · McDysan et al. · 2010 [cited by applicant]
US 20100232445A1 · Bellovin · 2010 [cited by applicant]
US 20100240377A1 · De Pasquale · 2010 [cited by examiner]
US 20100242098A1 · Kenworthy · 2010 [cited by applicant]
US 20100268799A1 · Maestas · 2010 [cited by applicant]
US 20100296441A1 · Barkan · 2010 [cited by applicant]
US 20100303240A1 · Beachem et al. · 2010 [cited by applicant]
US 20110055916A1 · Ahn · 2011 [cited by applicant]
US 20110055923A1 · Thomas · 2011 [cited by applicant]
US 20110088092A1 · Nguyen et al. · 2011 [cited by applicant]
US 20110141900A1 · Jayawardena · 2011 [cited by examiner]
US 20110154470A1 · Grimes et al. · 2011 [cited by applicant]
US 20110185055A1 · Nappier et al. · 2011 [cited by applicant]
US 20110214157A1 · Korsunsky et al. · 2011 [cited by applicant]
US 20110270956A1 · McDysan et al. · 2011 [cited by applicant]
US 20110277034A1 · Hanson · 2011 [cited by applicant]
US 20120023576A1 · Sorensen et al. · 2012 [cited by applicant]
US 20120084866A1 · Stolfo · 2012 [cited by applicant]
US 20120106354A1 · Pleshek et al. · 2012 [cited by applicant]
US 20120110656A1 · Santos et al. · 2012 [cited by applicant]
US 20120113987A1 · Riddoch et al. · 2012 [cited by applicant]
US 20120240135A1 · Risbood et al. · 2012 [cited by applicant]
US 20120240185A1 · Kapoor et al. · 2012 [cited by applicant]
US 20120264443A1 · Ng et al. · 2012 [cited by applicant]
US 20120314617A1 · Erichsen et al. · 2012 [cited by applicant]
US 20120331543A1 · Bostrom et al. · 2012 [cited by applicant]
US 20130007257A1 · Ramaraj et al. · 2013 [cited by applicant]
US 20130047020A1 · Hershko et al. · 2013 [cited by applicant]
US 20130055374A1 · Kustarz · 2013 [cited by examiner]
US 20130059527A1 · Hasesaka et al. · 2013 [cited by applicant]
US 20130061294A1 · Kenworthy · 2013 [cited by applicant]
US 20130104236A1 · Ray et al. · 2013 [cited by applicant]
US 20130117852A1 · Stute · 2013 [cited by applicant]
US 20130139236A1 · Rubinstein et al. · 2013 [cited by applicant]
US 20130254766A1 · Zuo et al. · 2013 [cited by applicant]
US 20130291100A1 · Ganapathy et al. · 2013 [cited by applicant]
US 20130305311A1 · Puttaswamy Naga et al. · 2013 [cited by applicant]
US 20140075510A1 · Sonoda et al. · 2014 [cited by applicant]
US 20140082204A1 · Shankar et al. · 2014 [cited by applicant]
US 20140082730A1 · Vashist et al. · 2014 [cited by applicant]
US 20140115654A1 · Rogers et al. · 2014 [cited by applicant]
US 20140150051A1 · Bharali et al. · 2014 [cited by applicant]
US 20140201123A1 · Ahn et al. · 2014 [cited by applicant]
US 20140215561A1 · Roberson et al. · 2014 [cited by applicant]
US 20140215574A1 · Erb et al. · 2014 [cited by applicant]
US 20140245423A1 · Lee · 2014 [cited by applicant]
US 20140259170A1 · Amsler · 2014 [cited by applicant]
US 20140281030A1 · Cui et al. · 2014 [cited by applicant]
US 20140283004A1 · Moore · 2014 [cited by applicant]
US 20140283030A1 · Moore et al. · 2014 [cited by applicant]
US 20140317397A1 · Martini · 2014 [cited by applicant]
US 20140317737A1 · Shin et al. · 2014 [cited by applicant]
US 20140337613A1 · Martini · 2014 [cited by applicant]
US 20140365372A1 · Ross et al. · 2014 [cited by applicant]
US 20140366132A1 · Stiansen et al. · 2014 [cited by applicant]
US 20150033336A1 · Wang et al. · 2015 [cited by applicant]
US 20150052601A1 · White et al. · 2015 [cited by applicant]
US 20150106930A1 · Honda et al. · 2015 [cited by applicant]
US 20150128274A1 · Giokas · 2015 [cited by applicant]
US 20150135325A1 · Stevens et al. · 2015 [cited by applicant]
US 20150207809A1 · MacAulay · 2015 [cited by applicant]
US 20150237012A1 · Moore · 2015 [cited by applicant]
US 20150244734A1 · Olson et al. · 2015 [cited by applicant]
US 20150256431A1 · Buchanan et al. · 2015 [cited by applicant]
US 20150304354A1 · Rogers et al. · 2015 [cited by applicant]
US 20150334125A1 · Bartos et al. · 2015 [cited by applicant]
US 20150341389A1 · Kurakami · 2015 [cited by applicant]
US 20150347246A1 · Matsui et al. · 2015 [cited by applicant]
US 20150350229A1 · Mitchell · 2015 [cited by applicant]
US 20150372977A1 · Yin · 2015 [cited by applicant]
US 20150373043A1 · Wang et al. · 2015 [cited by applicant]
US 20160020968A1 · Aumann et al. · 2016 [cited by applicant]
US 20160028751A1 · Cruz Mota et al. · 2016 [cited by applicant]
US 20160065611A1 · Fakeri-Tabrizi et al. · 2016 [cited by applicant]
US 20160112443A1 · Grossman et al. · 2016 [cited by applicant]
US 20160119365A1 · Barel · 2016 [cited by applicant]
US 20160127417A1 · Janssen · 2016 [cited by applicant]
US 20160191558A1 · Davison · 2016 [cited by applicant]
US 20160205069A1 · Blocher et al. · 2016 [cited by applicant]
US 20160219065A1 · Dasgupta et al. · 2016 [cited by applicant]
US 20160285706A1 · Rao · 2016 [cited by applicant]
US 20160294870A1 · Banerjee et al. · 2016 [cited by applicant]
US 20160366099A1 · Jordan · 2016 [cited by applicant]
US 20170223046A1 · Singh · 2017 [cited by applicant]
US 20170272469A1 · Kraemer et al. · 2017 [cited by applicant]
AU 2005328336B2 · 2011 [cited by applicant]
AU 2006230171B2 · 2012 [cited by applicant]
CA 2600236A1 · 2006 [cited by applicant]
EP 1006701A2 · 2000 [cited by applicant]
EP 1313290A1 · 2003 [cited by applicant]
EP 1484884A2 · 2004 [cited by applicant]
EP 1677484A2 · 2006 [cited by applicant]
EP 2385676A1 · 2011 [cited by applicant]
EP 2498442A1 · 2012 [cited by applicant]
EP 1864226B1 · 2013 [cited by applicant]
KR 20010079361A · 2001 [cited by applicant]
WO 2005046145A1 · 2005 [cited by applicant]
WO 2006093557A2 · 2006 [cited by applicant]
WO 2006105093A2 · 2006 [cited by applicant]
WO 2007109541A2 · 2007 [cited by applicant]
WO 2011038420A2 · 2011 [cited by applicant]
WO 2012146265A1 · 2012 [cited by applicant]
Greenwald, M., “Designing an Academic Firewall: Policy, Practice, and Experience with SURF”, IEEE, Proceedings of SNDSS (Year: 1996). [cited by examiner]
Jul. 26, 2018 (US) Declaration of Kevin Jeffay, PhD in Support of Second Petition for Inter Partes Review of U.S. Pat. No. 9,137,205—IPR2018-01444. [cited by applicant]
Nichols, et al., “Definition of the Differentiated Services Field (DS Field) in the IPV4 and IPv6 Headers,” Network Working Group RFC 2474, Dec. 1998, 20 pages. [cited by applicant]
Jul. 26, 2018 (US) Declaration of Kevin Jeffay, PhD in Support of First Petition for Inter Partes Review of U.S. Pat. No. 9,137,205—IPR2018-01443. [cited by applicant]
Perkins, “IP Encapsulation with IP,” Network Working Group RFC 2003, Oct. 1996, 14 pages. [cited by applicant]
Jul. 12, 2018 (US) Petition for Inter Partes Review of U.S. Pat. No. 9,565,213—IPR2018-01386. [cited by applicant]
Jul. 20, 2018 (US) Petition for Inter Partes Review of U.S. Pat. No. 9,160,713—IPR2018-01437. [cited by applicant]
Jul. 20, 2018 (US) Petition for Inter Partes Review of U.S. Pat. No. 9,124,552—IPR2018-01436. [cited by applicant]
Blake, et al., “An Architecture for Differentiated Services,” Network Working Group RFC 2475, Dec. 1998, 36 pages. [cited by applicant]
Jul. 27, 2018 (US) Second Petition for Inter Partes Review of U.S. Pat. No. 9,137,205—IPR2018-01444. [cited by applicant]
Jul. 27, 2018 (US) First Petition for Inter Partes Review of U.S. Pat. No. 9,137,205—IPR2018-01443. [cited by applicant]
Aug. 9, 2018 (US) Non-Final Office Action—U.S. Appl. No. 15/413,947. [cited by applicant]
Sep. 4, 2018 (WO) International Search Report and Written Opinion—App. PCT/US2018/041355. [cited by applicant]
Anonymous: “The Distribution of Malicious Domains,” The DomainTools Report, 2016 Edition, Mar. 9, 2016 (Mar. 9, 2016), pp. 1-11, XP055502306, Retrieved from: https://www.domaintools.com/resources/white-papers/the-domain… [cited by applicant]
Sep. 27, 2018 (US) Non-Final Office Action—U.S. Appl. No. 15/614,956. [cited by applicant]
Oct. 4, 2018 (US) Non-Final Office Action—U.S. Appl. No. 16/030,374. [cited by applicant]
Oct. 4, 2018 (US) Notice of Allowance—U.S. Appl. No. 15/827,477. [cited by applicant]
Aug. 20, 2018 (US) Petition for Inter Partes Review of U.S. Pat. No. 9,565,213—IPR2018-01512. [cited by applicant]
Aug. 15, 2018 (US) Declaration of Kevin Jeffay, PhD in Support of Petition for Inter Partes Review of U.S. Pat. No. 9,565,213—IPR2018-01512. [cited by applicant]
“Cisco ACNS Softward Configuration Guide for Centrally Managed Deployments,” Release 5.5. Text Part No. OL-9136-01, Cisco Systems, Inc., 2006, 944 pages. [cited by applicant]
Blake, et al., “An Architecture for Differentiated Services,” also known as the Diffserv architecture, as defined in RFC 2475, Network Working Group, Dec. 1998, 36 pages. [cited by applicant]
Sep. 27, 2018 (WO) International Search Report and Written Opinion—App. PCT/US2018/043367. [cited by applicant]
“Examining SSL-encrypted Communications: Netronome SSL InspectorTM Solution Overview,” Jan. 1, 2008, XP055036015, retrieved from <http://www.infosecurityproductsguide.com/technology/2008/Netronome_Examining_SSL-encrypte… [cited by applicant]
Oct. 12, 2018 (US) Non-Final Office Action—U.S. Appl. No. 16/039,896. [cited by applicant]
Aug. 29, 2018 (CA) Office Action—App. 2,888,935. [cited by applicant]
Nov. 14, 2018 (US) Final Office Action—U.S. Appl. No. 14/745,207. [cited by applicant]
Dec. 18, 2018 (US) Final Office Action—U.S. Appl. No. 15/610,995. [cited by applicant]
Jan. 24, 2019 (US) Notice of Allowance—U.S. Appl. No. 15/610,995. [cited by applicant]
Feb. 6, 2019 (US) Final Office Action—U.S. Appl. No. 15/413,750. [cited by applicant]
Feb. 6, 2019 (US) Notice of Allowance and Fees Due—U.S. Appl. No. 16/039,896. [cited by applicant]
Sep. 17, 2018 (US) Petition for Inter Partes Review of U.S. Pat. No. 9,560,176 (First)—IPR 2018-01654. [cited by applicant]
Sep. 17, 2018 (US) Declaration of Narasimha Reddy Ph.D., in Support of Petition for Inter Partes Review of U.S. Pat. No. 9,560,176 (First)—IRP2018-01654. [cited by applicant]
Sep. 17, 2018 (US) Petition for Inter Partes review of U.S. Pat. No. 9,560,176 (Second)—IPR2018-01655. [cited by applicant]
Sep. 17, 2018 (US) Declaration of Narasimha Reddy Ph.D., in Support of Petition for Inter Partes Review of U.S. Pat. No. 9,560,176 (Second)—IRP2018-01655. [cited by applicant]
Reddy, A.L.(2012) A.L. Narasimha Reddy Curriculum Vitae. Retrieved from https://cesg.tamu.edu/wp-content/uploads/2012/02/res_ext032.pdf, 16 pages. [cited by applicant]
Frahim, et al., “Cisco ASA: All-in-One Firewall, IPS, and VPN Adaptive Security Appliance,” Indiana: Cisco Press: 2006, 54 pages. [cited by applicant]
Mar. 8, 2019 (US) Notice of Allowance and Fees Due—U.S. Appl. No. 16/060,374. [cited by applicant]
Mar. 11, 2019 (US) Final Office Action—U.S. Appl. No. 16/030,354. [cited by applicant]
Feb. 21, 2019 (US) Final Office Action—U.S. Appl. No. 15/382,806. [cited by applicant]
Jan. 24, 2019 (US) Decision—Institution of Inter Partes Review of U.S. Pat. No. 9,160,713 B2—IPR 2018-01437. [cited by applicant]
Mar. 8, 2019 (US) Notice of Allowance and Fees Due—U.S. Appl. No. 16/030,374. [cited by applicant]
Aug. 21, 2018 (US) Petition for Inter Partes Review of U.S. Pat. No. 9,686,193—IPR2018-01559. [cited by applicant]
Aug. 15, 2018 (US) Declaration of Staurt Staniford, PhD in Support of Petition for Inter Partes Review of U.S. Pat. No. 9,686,193—IPR2018-01556. [cited by applicant]
Jan. 24, 2019 (US) Decision—Institution of Inter Partes Review of U.S. Pat. No. 9,124,552 B2—IPR 2018-01436. [cited by applicant]
Mar. 18, 2019 (AU) First Examination Report—App. 2016379156. [cited by applicant]
Apr. 8, 2019 (US) Final Office Action—U.S. Appl. No. 15/413,947. [cited by applicant]
Aug. 10, 2018 (US) Declaration of Kevin Jeffay, PhD in Support of Fourth Petition for Inter Partes Review of U.S. Pat. No. 9,137,205—IPR2018-01506. [cited by applicant]
Aug. 10, 2018 (US) Fourth Petition for Inter Partes Review of U.S. Pat. No. 9,137,205—IPR2018-01506. [cited by applicant]
Aug. 3, 2018 (US) Third Petition for Inter Partes Review of U.S. Pat. No. 9,137,205—IPR2018-01505. [cited by applicant]
Aug. 3, 2018 (US) Declaration of Kevin Jeffay, PhD in Support of Third Petition for Inter Partes Review of U.S. Pat. No. 9,137,205—IPR2018-01505. [cited by applicant]
Aug. 3, 2018 (US) Declaration of Kevin Jeffay, PhD in Support of Third Petition for Inter Partes Review of U.S. Pat. No. 9,560,077—IPR2018-01513. [cited by applicant]
Jun. 24, 2014 (WO) International Search Report—App. PCT/US2014/023286. [cited by applicant]
Mar. 24, 2014 (WO) International Search Report—App. PCT/US2013/072566. [cited by applicant]
Jun. 26, 2014 (WO) International Search Report—App. PCT/US2014/027723. [cited by applicant]
“Control Plane Policing Implementation Best Practices”; Cisco Systems; Mar. 13, 2013; <https://web.archive.org/web/20130313135143/http:www.cisco.com/web/about/security/intelligence/coppwp_gs.html>. [cited by applicant]
Nov. 7, 2013 (WO) International Search Report—App. PCT/US2013/057502. [cited by applicant]
Moore, S, “SBIR Case Study: Centripetal Networks: How CNI Leveraged DHS S&T SBIR Funding to Launch a Successful Cyber Security Company,” 2012 Principal Investigators' Meeting, Cyber Security Division, Oct. 10, 2014. [cited by applicant]
Reumann, John; “Adaptive Packet Filters”; IEEE, 2001, Department of Electrical Engineering and Computer Science, The University of Michigan, Ann Arbor, MI. [cited by applicant]
Greenwald, Michael; “Designing an Academic Firewall: Policy, Practice, and Experience with Surf”; IEEE, Proceedings of SNDSS, 1996. [cited by applicant]
Mizuno et al., A New Remote Configurable Firewall System for Home-use Gateways, Jan. 2005. Second IEEE Consumer Communications and Networking Conference, pp. 599-601. [cited by applicant]
Kindervag, et al. “Build Security Into Your Network's DNA: The Zero Trust Network Architecture,” Forrester Research Inc.; Nov. 5, 2010, pp. 1-26. [cited by applicant]
Palo Alto Networks; “Designing a Zero Trust Network With Next-Generation Firewalls”; pp. 1-10; last viewed on Oct. 21, 2012. [cited by applicant]
Jan. 11, 2016—(US) Non Final Rejection—U.S. Appl. No. 14/698,560. [cited by applicant]
Apr. 27, 2011—(WO) International Search Report and Written Opinion—App PCT/US2010/054520. [cited by applicant]
Mar. 4, 2011—(US) Notice of Allowance—U.S. Appl. No. 11/316,331. [cited by applicant]
Mar. 3, 2011—(EP) Communication Pursuant to Rules 70(2) and 70a(2)—App 06758213.0. [cited by applicant]
Feb. 14, 2011—(EP) Search Report—App 06758213.0. [cited by applicant]
Fulp, Errin: “CV: Errin Fulp,” XP002618346, www.cs.wfu.edu/fulp/ewfPub.html, pp. 1-5 (Copyright 2010). [cited by applicant]
Sep. 30, 2010—(US) Office Action—U.S. Appl. No. 11/390,976. [cited by applicant]
Sep. 10, 2010—(AU) Office Action—App 2006230171. [cited by applicant]
Aug. 20, 2010—(AU) Office Action—App 2005328336. [cited by applicant]
Jun. 23, 2010—(US) Final Rejection—U.S. Appl. No. 11/316,331. [cited by applicant]
Apr. 29, 2010—(US) Interview Summary—U.S. Appl. No. 11/390,976. [cited by applicant]
Mar. 26, 2010—(US) Final Rejection—U.S. Appl. No. 11/390,976. [cited by applicant]
Sep. 14, 2009 (US) Office Action—U.S. Appl. No. 11/316,331. [cited by applicant]
Jun. 24, 2009—(US) Office Action—U.S. Appl. No. 11/390,976. [cited by applicant]
Jul. 3, 2008—(WO) Written Opinion of the International Searching Authority—App PCT/US06/11291. [cited by applicant]
Aug. 31, 2007—(EP) Communication Pursuant to Rules 109 and 110—App 05857614.1. [cited by applicant]
Acharya et al., “Optwall: A Hierarchical Traffic-Aware Firewall,” Department of Computer Science, Telecommunications Program, University of Pittsburgh, pp. 1-11 (2007). [cited by applicant]
Sep. 11, 2006—(WO) Written Opinion of the International Searching Authority—App PCT/US05/47008. [cited by applicant]
Tarsa et al., “Balancing Trie-Based Policy representations for Network Firewalls,” Department of Computer Science, Wake Forest University, pp. 1-6 (2006). [cited by applicant]
Fulp, “Trie-Based Policy Representations for Network Firewalls,” Proceedings of the IEEE International Symposium on Computer Communications (2005). [cited by applicant]
E. Fulp, “Optimization of Network Firewall Policies Using Ordered Sets and Directed Acyclical Graphs”, Technical Report, Computer Scient Department, Wake Forest University, Jan. 2004. [cited by applicant]
E. Fulp et al., “Network Firewall Policy Tries”, Technical Report, Computer Science Department, Wake Forest University, 2004. [cited by applicant]
E. Al-Shaer et al., “Modeling and Management of Firewall Policies”, IEEE Transactions on Network and Service Management, 1(1): 2004. [cited by applicant]
E.W. Fulp, “Firewall Architectures for High Speed Networks”, U.S. Department of Energy Grant Application, Funded Sep. 2003. [cited by applicant]
E. Al-Shaer et al., “Firewall Policy Advisor for Anomaly Discovery and Rule Editing”, Proceedings of the IFIP/IEEE International Symposium on Integrated Network Management, 2003. [cited by applicant]
V.P. Ranganath, “A Set-Based Approach to Packet Classification”, Proceedings of the IASTED International Conference on Parallel and Distributed Computing and Systems, 889-894, 2003. [cited by applicant]
M. Christiansen et al., “Using IDDs for Packet Filtering,” Technical Report, BRICS, Oct. 2002. [cited by applicant]
Lee et al., “Development Framework for Firewall Processors,” IEEE, pp. 352-355 (2002). [cited by applicant]
L. Qui et al., “Fast Firewall Implementations for Software and Hardware-Based Routers”, Proceedings of ACM Sigmetrics, Jun. 2001. [cited by applicant]
D. Eppstein et al., “Internet Packet Filter Management and Rectangle Geometry”, Proceedings of the Symposium on Discrete Algorithms, 827-835, 2001. [cited by applicant]
E. Fulp, “Preventing Denial of Service Attacks on Quality of Service”, Proceedings of the 2001 DARPA Information Survivability Conference and Exposition II, 2001. [cited by applicant]
S. Goddard et al., “An Unavailability Analysis of Firewall Sandwich Configurations”, Proceedings of the 6th IEEE Symposium on High Assurance Systems Engineering, 2001. [cited by applicant]
G.V. Rooij, “Real Stateful TCP Packet Filtering in IP Filter”, Proceedings of the 10th USENIX Security Symposium, 2001. [cited by applicant]
P. Warkhede et al., “Fast Packet Classification for Two-Dimensional Conflict-Free Filters”, Proceedings of IEEE INFOCOM, 1434-1443, 2001. [cited by applicant]
D. Decasper et al., “Router Plugins: A Software Architecture for Next-Generation Routers”, IEEE/ACM Transactions on Networking, 8(1): Feb. 2000. [cited by applicant]
A. Feldmann et al., “Tradeoffs for Packet Classification”, Proceedings of the IEEE INFOCOM, 397-413, 2000. [cited by applicant]
X. Gan et al., “LSMAC vs. LSNAT: Scalable Cluster-based Web servers”, Journal of Networks, Software Tools, and Applications, 3(3): 175-185, 2000. [cited by applicant]
A. Hari et al., “Detecting and Resolving Packet Filter Conflicts”, Proceedings of IEEE Infocom, 1203-1212, 2000. [cited by applicant]
O. Paul et al., “A full Bandwidth ATM Firewall”, Proceedings of the 6th European Symposium on Research in Computer Security ESORICS'2000, 2000. [cited by applicant]