IP Library › Granted Patent US 12,218,959
Granted Patent B2
US 12,218,959 · App. 18/380,016 · Granted Feb 4, 2025

Efficient threat context-aware packet filtering for network protection

Inventors: Sean Moore (Hollis, NH); Jonathan R. Rogers (Hampton Falls, NH); Vincent Mutolo (Portsmouth, NH); Peter P. Geremia (Portsmouth, NH)
Assignee: Centripetal Networks, LLC
H04L63/1416H04L63/0245H04L63/1425H04L63/1466H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,218,959
App. No.
18/380,016
Granted
Feb 4, 2025
Kind
B2
Abstract

A threat intelligence gateway (TIG) may protect TCP/IP networks from network (e.g., Internet) threats by enforcing certain policies on in-transit packets that are crossing network boundaries. The policies may be composed of packet filtering rules with packet-matching criteria derived from cyber threat intelligence (CTI) associated with Internet threats. These CTI-derived packet-filtering rules may be created offline by policy creation and management servers, which may distribute the policies to subscribing TIGs that subsequently enforce the policies on in-transit packets. Each packet filtering rule may specify a disposition that may be applied to a matching in-transit packet, such as deny/block/drop the in-transit packet or pass/allow/forward the in-transit packet, and also may specify directives that may be applied to a matching in-transit packet, such as log, capture, spoof-tcp-rst, etc. Often, however, the selection of a rule's disposition and directives that best protect the associated network may not be optimally determined before a matching in-transit packet is observed by the associated TIG. In such cases, threat context information that may only be available (e.g., computable) at in-transit packet observation and/or filtering time, such as current time-of-day, current TIG/network location, current TIG/network administrator, the in-transit packet being determined to be part of an active attack on the network, etc., may be helpful to determine the disposition and directives that may best protect the network from the threat associated with the in-transit packet. The present disclosure describes examples of methods, systems, and apparatuses that may be used for efficiently determining (e.g., accessing and/or computing), in response to the in-transit packet, threat context information associated with an in-transit packet. The threat context information may be used to efficiently determine the disposition and/or one or more directives to apply to the in-transit packet. This may result in dispositions and/or directives being applied to in-transit packets that better protect the network as compared with solely using dispositions and directives that were predetermined prior to receiving the in-transit packet.

Claims (127)

1. A packet-filtering appliance comprising:

one or more processors; and

memory storing instructions that, when executed by the one or more processors, cause the packet-filtering appliance to:

receive a plurality of packet-filtering rules each indicating one or more packet-matching criteria and one or more actions to be performed, wherein:

the packet-filtering rules were generated based on a plurality of threat indicators that were previously determined based on a plurality of cyber threat intelligence reports from one or more cyber threat intelligence providers, wherein the plurality of cyber threat intelligence reports comprises the plurality of threat indicators, and wherein the plurality of threat indicators comprises a plurality of network addresses, and

a first packet-filtering rule, of the plurality of packet-filtering rules, indicates a first directive and is associated with a disposition that is to be determined after an in-transit packet matching first one or more packet-matching criteria of the first packet-filtering rule is received;

receive, from a first network and at a first time, a first in-transit packet destined to at least one location in a second network;

based on determining that the first in-transit packet matches the first one or more packet-matching criteria of the first packet-filtering rule:

determine first threat context information associated with receipt of the first in-transit packet by the packet-filtering appliance;

determine, based on the first threat context information, a first disposition;

selectively apply, based on the first disposition and to the first in-transit packet, the first directive of the first packet-filtering rule; and

apply the first disposition to the first in-transit packet;

receive, from the first network and at a second time, a second in-transit packet destined to at least one location in the second network; and

based on determining that the second in-transit packet matches the first one or more packet-matching criteria of the first packet-filtering rule:

determine second threat context information associated with receipt of the second in-transit packet by the packet-filtering appliance, wherein the second threat context information has at least one value different from the first threat context information;

determine, based on the second threat context information and independently from the determining the first disposition, a second disposition different from the first disposition; and

selectively apply, based on the second disposition and to the second in-transit packet, the first directive of the first packet-filtering rule; and

apply the second disposition to the second in-transit packet.

2. The packet-filtering appliance of claim 1 , wherein:

the first directive comprises a spoof-tcp-rst directive,

the first disposition comprises an allow disposition, and

the instructions, when executed by the one or more processors, cause the packet-filtering appliance to prevent, based on the first disposition, application of the first directive to the first in-transit packet.

3. The packet-filtering appliance of claim 2 , wherein:

the second disposition comprises a block disposition, and

the instructions, when executed by the one or more processors, cause the packet-filtering appliance to apply, based on the second disposition, the first directive to the second in-transit packet.

4. The packet-filtering appliance of claim 1 , wherein the instructions, when executed by the one or more processors, cause the packet-filtering appliance to selectively apply, based on the first disposition, the first directive to the first in-transit packet by:

selecting between applying the first directive to the first in-transit packet and preventing application of the first directive to the first in-transit packet, based on whether the first disposition is a block disposition or an allow disposition.

5. The packet-filtering appliance of claim 1 , wherein the instructions, when executed by the one or more processors, further cause the packet-filtering appliance to:

determine, based on the first disposition, a second directive; and

apply the second directive to the first in-transit packet.

6. The packet-filtering appliance of claim 1 , wherein the instructions, when executed by the one or more processors, cause the packet-filtering appliance to complete applying the first disposition to the first in-transit packet before the packet-filtering appliance applies the second disposition to the second in-transit packet.

7. The packet-filtering appliance of claim 1 , wherein the instructions, when executed by the one or more processors, cause the packet-filtering appliance to determine the first threat context information based on an observation time of the first in-transit packet.

8. The packet-filtering appliance of claim 1 , wherein the instructions, when executed by the one or more processors, cause the packet-filtering appliance to determine the first threat context information based on whether the first in-transit packet is a member of an attack that is active at a time that the first in-transit packet is received by the packet-filtering appliance.

9. The packet-filtering appliance of claim 1 , wherein the instructions, when executed by the one or more processors, cause the packet-filtering appliance to determine the first threat context information based on whether the first in-transit packet is a member of a multi-packet multi-flow attack that is active at a time that the first in-transit packet is received by the packet-filtering appliance.

10. The packet-filtering appliance of claim 1 , wherein:

the first threat context information comprises a first plurality of elements of information and the second threat context information comprises a second plurality of elements of information;

the packet-filtering appliance further comprises an artificial neural network comprising a plurality of input nodes and a plurality of output nodes;

the instructions, when executed by the one or more processors, cause the packet-filtering appliance to determine the first disposition, by at least:

providing the first plurality of elements of information to at least some of the plurality of input nodes of the artificial neural network; and

receiving, via at least one of the plurality of output nodes of the artificial neural network, an indication of the first disposition;

the instructions, when executed by the one or more processors, cause the packet-filtering appliance to determine the second disposition, by at least:

providing the second plurality of elements of information to at least some of the plurality of input nodes of the artificial neural network; and

receiving, via at least one of the plurality of output nodes of the artificial neural network, an indication of the second disposition; and

the instructions, when executed by the one or more processors, cause the packet-filtering appliance to:

determine, based on the indication of the first disposition from the artificial neural network, whether to implement the first directive for the first in-transit packet; and

determine, based on the indication of the second disposition from the artificial neural network, whether to implement the first directive for the second in-transit packet.

11. A non-transitory computer-readable medium storing instructions that, when executed, configure a packet-filtering appliance to:

receive a plurality of packet-filtering rules each indicating one or more packet-matching criteria and one or more actions to be performed, wherein:

the packet-filtering rules were generated based on a plurality of threat indicators that were previously determined based on a plurality of cyber threat intelligence reports from one or more cyber threat intelligence providers, wherein the plurality of cyber threat intelligence reports comprises the plurality of threat indicators, and wherein the plurality of threat indicators comprises a plurality of network addresses, and

a first packet-filtering rule, of the plurality of packet-filtering rules, indicates a first directive and is associated with a disposition that is to be determined after an in-transit packet matching first one or more packet-matching criteria of the first packet-filtering rule is received;

receive, from a first network and at a first time, a first in-transit packet destined to at least one location in a second network;

based on determining that the first in-transit packet matches the first one or more packet-matching criteria of the first packet-filtering rule:

determine first threat context information associated with receipt of the first in-transit packet by the packet-filtering appliance;

determine, based on the first threat context information, a first disposition;

selectively apply, based on the first disposition and to the first in-transit packet, the first directive of the first packet-filtering rule; and

apply the first disposition to the first in-transit packet;

receive, from the first network and at a second time, a second in-transit packet destined to at least one location in the second network; and

based on determining that the second in-transit packet matches the first one or more packet-matching criteria of the first packet-filtering rule:

determine second threat context information associated with receipt of the second in-transit packet by the packet-filtering appliance, wherein the second threat context information has at least one value different from the first threat context information;

determine, based on the second threat context information and independently from the determining the first disposition, a second disposition different from the first disposition; and

selectively apply, based on the second disposition and to the second in-transit packet, the first directive of the first packet-filtering rule; and

apply the second disposition to the second in-transit packet.

12. The non-transitory computer-readable medium of claim 11 , wherein:

the first directive comprises a spoof-tcp-rst directive,

the first disposition comprises an allow disposition, and

the instructions, when executed, configure the packet-filtering appliance to prevent, based on the first disposition, application of the first directive to the first in-transit packet.

13. The non-transitory computer-readable medium of claim 12 , wherein:

the second disposition comprises a block disposition, and

the instructions, when executed, configure the packet-filtering appliance to apply, based on the second disposition, the first directive to the second in-transit packet.

14. The non-transitory computer-readable medium of claim 11 , wherein the instructions, when executed, configure the packet-filtering appliance to selectively apply, based on the first disposition, the first directive to the first in-transit packet by:

selecting between applying the first directive to the first in-transit packet and preventing application of the first directive to the first in-transit packet, based on whether the first disposition is a block disposition or an allow disposition.

15. The non-transitory computer-readable medium of claim 11 , wherein the instructions, when executed, further configure the packet-filtering appliance to:

determine, based on the first disposition, a second directive; and

apply the second directive to the first in-transit packet.

16. The non-transitory computer-readable medium of claim 11 , wherein the instructions, when executed, configure the packet-filtering appliance to initiate applying the first disposition to the first in-transit packet before processing the second in-transit packet.

17. The non-transitory computer-readable medium of claim 11 , wherein the instructions, when executed, configure the packet-filtering appliance to complete applying the first disposition to the first in-transit packet before applying the second disposition to the second in-transit packet.

18. The non-transitory computer-readable medium of claim 11 , wherein the instructions, when executed, configure the packet-filtering appliance to determine the first threat context information based on whether the first in-transit packet is a member of an attack that is active at a time that the first in-transit packet is received by the packet-filtering appliance.

19. The non-transitory computer-readable medium of claim 11 , wherein the instructions, when executed, configure the packet-filtering appliance to determine the first threat context information based on whether the first in-transit packet is a member of a multi-packet multi-flow attack that is active at a time that the first in-transit packet is received by the packet-filtering appliance.

20. The non-transitory computer-readable medium of claim 11 , wherein:

the first threat context information comprises a first plurality of elements of information and the second threat context information comprises a second plurality of elements of information;

the instructions, when executed, configure the packet-filtering appliance to determine the first disposition, by at least:

providing the first plurality of elements of information to at least some input nodes of a plurality of input nodes of an artificial neural network; and

receiving, via at least one output node of a plurality of output nodes of the artificial neural network, an indication of the first disposition;

the instructions, when executed, configure the packet-filtering appliance to determine the second disposition, by at least:

providing the second plurality of elements of information to at least some of the plurality of input nodes of the artificial neural network; and

receiving, via at least one of the plurality of output nodes of the artificial neural network, an indication of the second disposition; and

the instructions, when executed, configure the packet-filtering appliance to:

determine, based on the indication of the first disposition from the artificial neural network, whether to implement the first directive for the first in-transit packet; and

determine, based on the indication of the second disposition from the artificial neural network, whether to implement the first directive for the second in-transit packet.

21. A method comprising:

receiving, by a packet-filtering appliance, a plurality of packet-filtering rules each indicating one or more packet-matching criteria and one or more actions to be performed, wherein:

the packet-filtering rules were generated based on a plurality of threat indicators that were previously determined based on a plurality of cyber threat intelligence reports from one or more cyber threat intelligence providers, wherein the plurality of cyber threat intelligence reports comprises the plurality of threat indicators, and wherein the plurality of threat indicators comprises a plurality of network addresses, and

a first packet-filtering rule, of the plurality of packet-filtering rules, indicates a first directive and is associated with a disposition that is to be determined after an in-transit packet matching first one or more packet-matching criteria of the first packet-filtering rule is received;

receiving, by the packet-filtering appliance from a first network and at a first time, a first in-transit packet destined to at least one location in a second network;

based on determining that the first in-transit packet matches the first one or more packet-matching criteria of the first packet-filtering rule, the packet-filtering appliance performing:

determining first threat context information associated with the receiving the first in-transit packet;

determining, based on the first threat context information, a first disposition;

selectively applying, based on the first disposition and to the first in-transit packet, the first directive of the first packet-filtering rule; and

applying the first disposition to the first in-transit packet;

receiving, by the packet-filtering appliance from the first network and at a second time, a second in-transit packet destined to at least one location in the second network; and

based on determining that the second in-transit packet matches the first one or more packet-matching criteria of the first packet-filtering rule, the packet-filtering appliance performing:

determining second threat context information associated with the receiving the second in-transit packet, wherein the second threat context information has at least one value different from the first threat context information;

determining, based on the second threat context information and independently from the determining the first disposition, a second disposition different from the first disposition; and

selectively applying, based on the second disposition and to the second in-transit packet, the first directive of the first packet-filtering rule; and

applying the second disposition to the second in-transit packet.

22. The method of claim 21 , wherein the first directive comprises a spoof-tcp-rst directive, the first disposition comprises an allow disposition, and the selectively applying, based on the first disposition, the first directive to the first in-transit packet comprises preventing application of the first directive to the first in-transit packet.

23. The method of claim 22 , wherein the second disposition comprises a block disposition, and the selectively applying, based on the second disposition, the first directive to the second in-transit packet comprises applying the first directive to the second in-transit packet.

24. The method of claim 21 , wherein the selectively applying, based on the first disposition, the first directive to the first in-transit packet comprises selecting between applying the first directive to the first in-transit packet and preventing application of the first directive to the first in-transit packet, based on whether the first disposition is a block disposition or an allow disposition.

25. The method of claim 21 , further comprising:

determining, based on the first disposition, a second directive; and

applying the second directive to the first in-transit packet.

26. The method of claim 21 , wherein the applying the first disposition to the first in-transit packet is completed before the packet-filtering appliance applies the second disposition to the second in-transit packet.

27. The method of claim 21 , wherein the determining the first threat context information comprises determining the first threat context information based on an observation time of the first in-transit packet.

28. The method of claim 21 , wherein the determining the first threat context information comprises determining the first threat context information based on whether the first in-transit packet is a member of an attack that is active at a time that the first in-transit packet is received by the packet-filtering appliance.

29. The method of claim 21 , wherein the determining the first threat context information comprises determining the first threat context information based on whether the first in-transit packet is a member of a multi-packet multi-flow attack that is active at a time that the first in-transit packet is received by the packet-filtering appliance.

30. The method of claim 21 , wherein:

the first threat context information comprises a first plurality of elements of information and the second threat context information comprises a second plurality of elements of information;

the packet-filtering appliance comprises an artificial neural network comprising a plurality of input nodes and a plurality of output nodes;

the determining the first disposition comprises:

providing the first plurality of elements of information to at least some of the plurality of input nodes of the artificial neural network; and

receiving, via at least one of the plurality of output nodes of the artificial neural network, an indication of the first disposition;

the determining the second disposition comprises:

providing the second plurality of elements of information to at least some of the plurality of input nodes of the artificial neural network; and

receiving, via at least one of the plurality of output nodes of the artificial neural network, an indication of the second disposition; and

the packet-filtering appliance comprises logic configured to:

determine, based on the indication of the first disposition from the artificial neural network, whether to implement the first directive for the first in-transit packet; and

determine, based on the indication of the second disposition from the artificial neural network, whether to implement the first directive for the second in-transit packet.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 17, 2023
From: MOORE, SEAN; ROGERS, JONATHAN R.; MUTOLO, VINCENT; GEREMIA, PETER P.
To: CENTRIPETAL NETWORKS, INC.
Reel/Frame 065247/0533 →
CHANGE OF NAME Recorded Oct 17, 2023
From: CENTRIPETAL NETWORKS, INC.
To: CENTRIPETAL NETWORKS, LLC
Reel/Frame 065247/0774 →
Continuity (6)
Continuation 18084366 · Dec 19, 2022
Continuation 17866208 · Jul 15, 2022
Continuation 17695047 · Mar 15, 2022
Continuation 17508596 · Oct 22, 2021
Continuation 17235544 · Apr 20, 2021
Related Publication 20240154977A1 · May 9, 2024
References Cited (325)
US 6098172A · Coss et al. · 2000 [cited by applicant]
US 6147976A · Shand et al. · 2000 [cited by applicant]
US 6226372B1 · Beebe et al. · 2001 [cited by applicant]
US 6279113B1 · Vaidya · 2001 [cited by applicant]
US 6317837B1 · Kenworthy · 2001 [cited by applicant]
US 6484261B1 · Wiegel · 2002 [cited by applicant]
US 6611875B1 · Chopra et al. · 2003 [cited by applicant]
US 6662235B1 · Callis et al. · 2003 [cited by applicant]
US 6826694B1 · Dutta et al. · 2004 [cited by applicant]
US 7089581B1 · Nagai et al. · 2006 [cited by applicant]
US 7095716B1 · Ke et al. · 2006 [cited by applicant]
US 7107613B1 · Chen et al. · 2006 [cited by applicant]
US 7143438B1 · Coss et al. · 2006 [cited by applicant]
US 7152240B1 · Green et al. · 2006 [cited by applicant]
US 7215637B1 · Ferguson et al. · 2007 [cited by applicant]
US 7225269B2 · Watanabe · 2007 [cited by applicant]
US 7227842B1 · Ji et al. · 2007 [cited by applicant]
US 7237267B2 · Rayes et al. · 2007 [cited by applicant]
US 7263099B1 · Woo et al. · 2007 [cited by applicant]
US 7296288B1 · Hill et al. · 2007 [cited by applicant]
US 7299353B2 · Le Pennec et al. · 2007 [cited by applicant]
US 7331061B1 · Ramsey et al. · 2008 [cited by applicant]
US 7478429B2 · Lyon · 2009 [cited by applicant]
US 7539186B2 · Aerrabotu et al. · 2009 [cited by applicant]
US 7610621B2 · Turley et al. · 2009 [cited by applicant]
US 7684400B2 · Govindarajan et al. · 2010 [cited by applicant]
US 7710885B2 · Ilnicki et al. · 2010 [cited by applicant]
US 7721084B2 · Salminen et al. · 2010 [cited by applicant]
US 7792775B2 · Matsuda · 2010 [cited by applicant]
US 7814158B2 · Malik · 2010 [cited by applicant]
US 7814546B1 · Strayer et al. · 2010 [cited by applicant]
US 7818794B2 · Wittman · 2010 [cited by applicant]
US 7913303B1 · Rouland et al. · 2011 [cited by applicant]
US 7954143B2 · Aaron · 2011 [cited by applicant]
US 8004994B1 · Darisi et al. · 2011 [cited by applicant]
US 8009566B2 · Zuk et al. · 2011 [cited by applicant]
US 8037517B2 · Fulp et al. · 2011 [cited by applicant]
US 8042167B2 · Fulp et al. · 2011 [cited by applicant]
US 8117655B2 · Spielman · 2012 [cited by applicant]
US 8176561B1 · Hurst et al. · 2012 [cited by applicant]
US 8209756B1 · Guruswamy · 2012 [cited by examiner]
US 8306994B2 · Kenworthy · 2012 [cited by applicant]
US 8307029B2 · Davis et al. · 2012 [cited by applicant]
US 8495725B2 · Ahn · 2013 [cited by applicant]
US 8510821B1 · Brandwine et al. · 2013 [cited by applicant]
US 8578489B1 · Dubrovsky et al. · 2013 [cited by applicant]
US 8726379B1 · Stiansen et al. · 2014 [cited by applicant]
US 8806638B1 · Mani · 2014 [cited by applicant]
US 8832832B1 · Visbal · 2014 [cited by applicant]
US 8856926B2 · Narayanaswamy et al. · 2014 [cited by applicant]
US 8935785B2 · Pandrangi · 2015 [cited by applicant]
US 9094445B2 · Moore et al. · 2015 [cited by applicant]
US 9124552B2 · Moore · 2015 [cited by applicant]
US 9137205B2 · Rogers et al. · 2015 [cited by applicant]
US 9154446B2 · Gemelli et al. · 2015 [cited by applicant]
US 9160713B2 · Moore · 2015 [cited by applicant]
US 9172627B2 · Kjendal et al. · 2015 [cited by applicant]
US 9419942B1 · Buruganahalli et al. · 2016 [cited by applicant]
US 10333898B1 · Moore et al. · 2019 [cited by applicant]
US 10503899B2 · Moore et al. · 2019 [cited by applicant]
US 10673890B2 · Lee et al. · 2020 [cited by applicant]
US 20010039579A1 · Trcka et al. · 2001 [cited by applicant]
US 20010039624A1 · Kellum · 2001 [cited by applicant]
US 20020016858A1 · Sawada et al. · 2002 [cited by applicant]
US 20020038339A1 · Xu · 2002 [cited by applicant]
US 20020049899A1 · Kenworthy · 2002 [cited by applicant]
US 20020112188A1 · Syvanne · 2002 [cited by applicant]
US 20020164962A1 · Mankins et al. · 2002 [cited by applicant]
US 20020165949A1 · Na et al. · 2002 [cited by applicant]
US 20020186683A1 · Buck et al. · 2002 [cited by applicant]
US 20020198981A1 · Corl et al. · 2002 [cited by applicant]
US 20030018591A1 · Komisky · 2003 [cited by applicant]
US 20030035370A1 · Brustoloni · 2003 [cited by applicant]
US 20030051026A1 · Carter et al. · 2003 [cited by applicant]
US 20030097590A1 · Syvanne · 2003 [cited by applicant]
US 20030105976A1 · Copeland · 2003 [cited by applicant]
US 20030120622A1 · Nurmela et al. · 2003 [cited by applicant]
US 20030123456A1 · Denz et al. · 2003 [cited by applicant]
US 20030142681A1 · Chen et al. · 2003 [cited by applicant]
US 20030145225A1 · Bruton et al. · 2003 [cited by applicant]
US 20030154297A1 · Suzuki et al. · 2003 [cited by applicant]
US 20030154399A1 · Zuk et al. · 2003 [cited by applicant]
US 20030188192A1 · Tang et al. · 2003 [cited by applicant]
US 20030212900A1 · Liu et al. · 2003 [cited by applicant]
US 20030220940A1 · Futoransky et al. · 2003 [cited by applicant]
US 20040010712A1 · Hui et al. · 2004 [cited by applicant]
US 20040015719A1 · Lee et al. · 2004 [cited by applicant]
US 20040073655A1 · Kan et al. · 2004 [cited by applicant]
US 20040088542A1 · Daude et al. · 2004 [cited by applicant]
US 20040093513A1 · Cantrell et al. · 2004 [cited by applicant]
US 20040098511A1 · Lin et al. · 2004 [cited by applicant]
US 20040123220A1 · Johnson et al. · 2004 [cited by applicant]
US 20040151155A1 · Jouppi · 2004 [cited by applicant]
US 20040172529A1 · Culbert · 2004 [cited by applicant]
US 20040172557A1 · Nakae et al. · 2004 [cited by applicant]
US 20040177139A1 · Schuba et al. · 2004 [cited by applicant]
US 20040193943A1 · Angelino et al. · 2004 [cited by applicant]
US 20040199629A1 · Bomer et al. · 2004 [cited by applicant]
US 20040205360A1 · Norton et al. · 2004 [cited by applicant]
US 20040250124A1 · Chesla et al. · 2004 [cited by applicant]
US 20050010765A1 · Swander et al. · 2005 [cited by applicant]
US 20050024189A1 · Weber · 2005 [cited by applicant]
US 20050071650A1 · Jo et al. · 2005 [cited by applicant]
US 20050108557A1 · Kayo et al. · 2005 [cited by applicant]
US 20050114704A1 · Swander · 2005 [cited by applicant]
US 20050117576A1 · McDysan et al. · 2005 [cited by applicant]
US 20050125697A1 · Tahara · 2005 [cited by applicant]
US 20050138204A1 · Iyer et al. · 2005 [cited by applicant]
US 20050138353A1 · Spies et al. · 2005 [cited by applicant]
US 20050141537A1 · Kumar et al. · 2005 [cited by applicant]
US 20050183140A1 · Goddard · 2005 [cited by applicant]
US 20050229246A1 · Rajagopal et al. · 2005 [cited by applicant]
US 20050251570A1 · Heasman et al. · 2005 [cited by applicant]
US 20050283823A1 · Okajo et al. · 2005 [cited by applicant]
US 20050286522A1 · Paddon et al. · 2005 [cited by applicant]
US 20060048142A1 · Roese et al. · 2006 [cited by applicant]
US 20060053491A1 · Khuti et al. · 2006 [cited by applicant]
US 20060070122A1 · Bellovin · 2006 [cited by applicant]
US 20060080733A1 · Khosmood et al. · 2006 [cited by applicant]
US 20060085849A1 · Culbert · 2006 [cited by applicant]
US 20060104202A1 · Reiner · 2006 [cited by applicant]
US 20060114899A1 · Toumura et al. · 2006 [cited by applicant]
US 20060133377A1 · Jain · 2006 [cited by applicant]
US 20060136987A1 · Okuda · 2006 [cited by applicant]
US 20060137009A1 · Chesla · 2006 [cited by applicant]
US 20060146879A1 · Anthias et al. · 2006 [cited by applicant]
US 20060195896A1 · Fulp et al. · 2006 [cited by applicant]
US 20060212572A1 · Afek et al. · 2006 [cited by applicant]
US 20060248580A1 · Fulp et al. · 2006 [cited by applicant]
US 20060262798A1 · Joshi et al. · 2006 [cited by applicant]
US 20070056038A1 · Lok · 2007 [cited by applicant]
US 20070083924A1 · Lu · 2007 [cited by applicant]
US 20070118894A1 · Bhatia · 2007 [cited by applicant]
US 20070211644A1 · Ottamalika et al. · 2007 [cited by applicant]
US 20070240208A1 · Yu et al. · 2007 [cited by applicant]
US 20080005795A1 · Acharya et al. · 2008 [cited by applicant]
US 20080043739A1 · Suh et al. · 2008 [cited by applicant]
US 20080072307A1 · Maes · 2008 [cited by applicant]
US 20080077705A1 · Li et al. · 2008 [cited by applicant]
US 20080163333A1 · Kasralikar · 2008 [cited by applicant]
US 20080201772A1 · Mondaeev et al. · 2008 [cited by applicant]
US 20080229415A1 · Kapoor et al. · 2008 [cited by applicant]
US 20080235755A1 · Blaisdell et al. · 2008 [cited by applicant]
US 20080279196A1 · Friskney et al. · 2008 [cited by applicant]
US 20080301765A1 · Nicol et al. · 2008 [cited by applicant]
US 20080313738A1 · Enderby · 2008 [cited by applicant]
US 20090028160A1 · Eswaran et al. · 2009 [cited by applicant]
US 20090052443A1 · Kolenchery et al. · 2009 [cited by applicant]
US 20090077621A1 · Lang et al. · 2009 [cited by applicant]
US 20090138938A1 · Harrison et al. · 2009 [cited by applicant]
US 20090150996A1 · Haswell · 2009 [cited by applicant]
US 20090172800A1 · Wool · 2009 [cited by applicant]
US 20090222877A1 · Diehl et al. · 2009 [cited by applicant]
US 20090240698A1 · Shukla et al. · 2009 [cited by applicant]
US 20090262741A1 · Jungck et al. · 2009 [cited by applicant]
US 20090328219A1 · Narayanaswamy · 2009 [cited by applicant]
US 20100011433A1 · Harrison et al. · 2010 [cited by applicant]
US 20100011434A1 · Kay · 2010 [cited by applicant]
US 20100082811A1 · Van Der Merwe et al. · 2010 [cited by applicant]
US 20100095367A1 · Narayanaswamy · 2010 [cited by applicant]
US 20100107240A1 · Thaler et al. · 2010 [cited by applicant]
US 20100132027A1 · Ou · 2010 [cited by applicant]
US 20100199346A1 · Ling et al. · 2010 [cited by applicant]
US 20100202299A1 · Strayer et al. · 2010 [cited by applicant]
US 20100211678A1 · McDysan et al. · 2010 [cited by applicant]
US 20100232445A1 · Bellovin · 2010 [cited by applicant]
US 20100242098A1 · Kenworthy · 2010 [cited by applicant]
US 20100268799A1 · Maestas · 2010 [cited by applicant]
US 20100296441A1 · Barkan · 2010 [cited by applicant]
US 20100303240A1 · Beachem et al. · 2010 [cited by applicant]
US 20110055916A1 · Ahn · 2011 [cited by applicant]
US 20110055923A1 · Thomas · 2011 [cited by applicant]
US 20110088092A1 · Nguyen et al. · 2011 [cited by applicant]
US 20110141900A1 · Jayawardena et al. · 2011 [cited by applicant]
US 20110185055A1 · Nappier et al. · 2011 [cited by applicant]
US 20110238855A1 · Korsunsky et al. · 2011 [cited by applicant]
US 20110270956A1 · McDysan et al. · 2011 [cited by applicant]
US 20110277034A1 · Hanson · 2011 [cited by applicant]
US 20120023576A1 · Sorensen et al. · 2012 [cited by applicant]
US 20120106354A1 · Pleshek et al. · 2012 [cited by applicant]
US 20120113987A1 · Riddoch et al. · 2012 [cited by applicant]
US 20120240135A1 · Risbood et al. · 2012 [cited by applicant]
US 20120264443A1 · Ng et al. · 2012 [cited by applicant]
US 20120311692A1 · Ebina · 2012 [cited by examiner]
US 20120314617A1 · Erichsen et al. · 2012 [cited by applicant]
US 20120331543A1 · Bostrom et al. · 2012 [cited by applicant]
US 20130047020A1 · Hershko et al. · 2013 [cited by applicant]
US 20130059527A1 · Hasesaka et al. · 2013 [cited by applicant]
US 20130061294A1 · Kenworthy · 2013 [cited by applicant]
US 20130104236A1 · Ray et al. · 2013 [cited by applicant]
US 20130117852A1 · Stute · 2013 [cited by applicant]
US 20130254766A1 · Zuo et al. · 2013 [cited by applicant]
US 20130291100A1 · Ganapathy et al. · 2013 [cited by applicant]
US 20130305311A1 · Puttaswamy Naga et al. · 2013 [cited by applicant]
US 20140075510A1 · Sonoda et al. · 2014 [cited by applicant]
US 20140115654A1 · Rogers et al. · 2014 [cited by applicant]
US 20140150051A1 · Bharali et al. · 2014 [cited by applicant]
US 20140201123A1 · Ahn et al. · 2014 [cited by applicant]
US 20140215574A1 · Erb et al. · 2014 [cited by applicant]
US 20140247786A1 · Izu et al. · 2014 [cited by applicant]
US 20140259170A1 · Amsler · 2014 [cited by applicant]
US 20140281030A1 · Cui et al. · 2014 [cited by applicant]
US 20140283004A1 · Moore · 2014 [cited by applicant]
US 20140283030A1 · Moore et al. · 2014 [cited by applicant]
US 20140317397A1 · Martini · 2014 [cited by applicant]
US 20140366132A1 · Stiansen et al. · 2014 [cited by applicant]
US 20150007314A1 · Vaughan · 2015 [cited by applicant]
US 20150033336A1 · Wang et al. · 2015 [cited by applicant]
US 20150106930A1 · Honda et al. · 2015 [cited by applicant]
US 20150135325A1 · Stevens · 2015 [cited by examiner]
US 20150237012A1 · Moore · 2015 [cited by applicant]
US 20150244734A1 · Olson et al. · 2015 [cited by applicant]
US 20150304354A1 · Rogers et al. · 2015 [cited by applicant]
US 20150334125A1 · Bartos et al. · 2015 [cited by applicant]
US 20150341389A1 · Kurakami · 2015 [cited by applicant]
US 20150350229A1 · Mitchell · 2015 [cited by applicant]
US 20150372977A1 · Yin · 2015 [cited by applicant]
US 20150373043A1 · Wang et al. · 2015 [cited by applicant]
US 20160020968A1 · Aumann et al. · 2016 [cited by applicant]
US 20160065611A1 · Fakeri-Tabrizi et al. · 2016 [cited by applicant]
US 20160112443A1 · Grossman et al. · 2016 [cited by applicant]
US 20160119365A1 · Barel · 2016 [cited by applicant]
US 20160191558A1 · Davison · 2016 [cited by applicant]
US 20160205069A1 · Blocher et al. · 2016 [cited by applicant]
US 20160212171A1 · Senanayake et al. · 2016 [cited by applicant]
US 20160218933A1 · Porras et al. · 2016 [cited by applicant]
US 20160219065A1 · Dasgupta et al. · 2016 [cited by applicant]
US 20160285706A1 · Rao · 2016 [cited by applicant]
US 20160294870A1 · Banerjee et al. · 2016 [cited by applicant]
US 20160366099A1 · Jordan · 2016 [cited by applicant]
US 20170099310A1 · Di Pietro et al. · 2017 [cited by applicant]
US 20170223046A1 · Singh · 2017 [cited by applicant]
US 20180159883A1 · Ahn et al. · 2018 [cited by applicant]
US 20190007454A1 · Nimmagadda · 2019 [cited by examiner]
US 20200267176A1 · Asher et al. · 2020 [cited by applicant]
US 20200351244A1 · Moore et al. · 2020 [cited by applicant]
US 20210112091A1 · Compton · 2021 [cited by applicant]
US 20220060448A1 · White · 2022 [cited by applicant]
US 20220159036A1 · Tsirkin · 2022 [cited by examiner]
AU 2005328336B2 · 2011 [cited by applicant]
AU 2006230171B2 · 2012 [cited by applicant]
CA 2600236A1 · 2006 [cited by applicant]
EP 1006701A2 · 2000 [cited by applicant]
EP 1313290A1 · 2003 [cited by applicant]
EP 1484884A2 · 2004 [cited by applicant]
EP 1677484A2 · 2006 [cited by applicant]
EP 2385676A1 · 2011 [cited by applicant]
EP 2498442A1 · 2012 [cited by applicant]
EP 1864226B1 · 2013 [cited by applicant]
EP 3284238A1 · 2018 [cited by applicant]
KR 20010079361A · 2001 [cited by applicant]
WO 2005046145A1 · 2005 [cited by applicant]
WO 2006093557A2 · 2006 [cited by applicant]
WO 2006105093A2 · 2006 [cited by applicant]
WO 2007109541A2 · 2007 [cited by applicant]
WO 2011038420A2 · 2011 [cited by applicant]
WO 2012146265A1 · 2012 [cited by applicant]
WO 2015160357A1 · 2015 [cited by applicant]
WO 2017120051A1 · 2017 [cited by applicant]
WO 2019092711A1 · 2019 [cited by applicant]
WO 2021003014A1 · 2021 [cited by applicant]
W. Meng, W. Li and L. F. Kwok, “Towards Effective Trust-Based Packet Filtering in Collaborative Network Environments,” in IEEE Transactions on Network and Service Management, vol. 14, No. 1, pp. 233-245, Mar. 2017, doi:… [cited by examiner]
U. Ellermann et al., “Firewalls for ATM Networks”, Proceedings of INFOSEC'COM, 1998. [cited by applicant]
V. Srinivasan et al., “Fast and Scalable Layer Four Switching”, Proceedings of ACM SIGCOMM, 191-202, 1998. [cited by applicant]
V.P. Ranganath, “A Set-Based Approach to Packet Classification”, Proceedings of the IASTED International Conference on Parallel and Distributed Computing and Systems, 889-894, 2003. [cited by applicant]
W.E. Leland et al., “On the Self-Similar Nature of Ethernet Traffic”, IEEE Transactions on Networking, 2(1); 15, 1994. [cited by applicant]
W.E. Smith, “Various Optimizers for Single-Stage Productions”, Naval Research Logistics Quarterly, 3: 59-66, 1956. [cited by applicant]
X. Gan et al., “LSMAC vs. LSNAT: Scalable Cluster-based Web servers”, Journal of Networks, Software Tools, and Applications, 3(3): 175-185, 2000. [cited by applicant]
Ylonen, et al., “The Secure Shell (SSH) Transport Layer Protocol,” SSH Communication Security Corp, Network Working Group RFC 4253, Jan. 2006, 32 pages. [cited by applicant]
Sommer, et al., “Enhancing byte-level network intrusion detection signatures with context,” Proceedings of the 10th ACM conference on Computer and communications security, 2003. [cited by applicant]
Jul. 22, 2022—(WO) International Search Report and Written Opinion—App PCT/US2022/025375, 26 pages. [cited by applicant]
Juniper, “Example: Using Firewall Filter Chains”, Jan. 26, 2021, Retrieved from the Internet: <<https://web.archive.org/web/20210516174320/https://www.juniper.net/documentation/us/en/software/junos/routing-policy/topics… [cited by applicant]
Meng, et al., “Towards Effective Trust-Based Packet Filtering in Collaborative Network Environments,” IEEE Transactions on Network and Service Management, vol. 14, No. 1, Mar. 2017, pp. 233-245, 13 pages. [cited by applicant]
Aug. 26, 2022 (EP) Communication with European Search Report, App EP22169106, 8 pages. [cited by applicant]
Feb. 15, 2024 (EP)—Communication with European Search Report—App EP23193876, 11 pages. [cited by applicant]
Popa, et al., “Building Extensible Networks with Rule-Based Forwarding,” OSDI, 2010, 14 pages. [cited by applicant]
Jun. 23, 2021 (US)—Notice of Allowance—U.S. Appl. No. 17/235,544. [cited by applicant]
“Control Plane Policing Implementation Best Practices”; Cisco Systems; Mar. 13, 2013; <https://web.archive.org/web/20130313135143/http:www.cisco.com/web/about/security/intelligence/coppwp_gs.html>. [cited by applicant]
A. Feldmann et al., “Tradeoffs for Packet Classification”, Proceedings of the IEEE Infocom, 397-413, 2000. [cited by applicant]
A. Hari et al., “Detecting and Resolving Packet Filter Conflicts”, Proceedings of IEEE Infocom, 1203-1212, 2000. [cited by applicant]
Acharya et al., “Optwall: A Hierarchical Traffic-Aware Firewall,” Department of Computer Science, Telecommunications Program, University of Pittsburgh, pp. 1-11 (2007). [cited by applicant]
Bellion, “High Performance Packet Classification”, http://www.hipac.org (available as of Jul. 12, 2018, however exact publication date unknown). [cited by applicant]
Blake, et al., “An Architecture for Differentiated Services,” Network Working Group RFC 2475, Dec. 1998, 36 pages. [cited by applicant]
C. Benecke, “A Parallel Packet Screen for High Speed Networks”, Proceedings of the 15th Annual Computer Security Applications Conference, 1999. [cited by applicant]
Chen, et al., “Research on the Anomaly Discovering Algorithm of the Packet Filtering Rule Sets,” Sep. 2010, First International Confererence on Pervasive Computing, Signal Processing and Applications, pp. 362-366. [cited by applicant]
D. Comer, “Analysis of a Heuristic for Full Trie Minimization”, ACM Transactions on Database Systems, 6(3): 513-537, Sep. 1981. [cited by applicant]
D. Decasper et al., “Router Plugins: A Software Architecture for Next-Generation Routers”, IEEE/ACM Transactions on Networking, 8(1): Feb. 2000. [cited by applicant]
D. Eppstein et al., “Internet Packet Filter Management and Rectangle Geometry”, Proceedings of the Symposium on Discrete Algorithms, 827-835, 2001. [cited by applicant]
E. Al-Shaer et al., “Firewall Policy Advisor for Anomaly Discovery and Rule Editing”, Proceedings of the IFIP/IEEE International Symposium on Integrated Network Management, 2003. [cited by applicant]
E. Al-Shaer et al., “Modeling and Management of Firewall Policies”, IEEE Transactions on Network and Service Management, 1(1): 2004. [cited by applicant]
E. Fulp et al., “Network Firewall Policy Tries”, Technical Report, Computer Science Department, Wake Forest University, 2004. [cited by applicant]
E. Fulp, “Optimization of Network Firewall Policies Using Ordered Sets and Directed Acyclical Graphs”, Technical Report, Computer Scient Department, Wake Forest University, Jan. 2004. [cited by applicant]
E. Fulp, “Preventing Denial of Service Attacks on Quality of Service”, Proceedings of the 2001 DARPA Information Survivability Conference and Exposition II, 2001. [cited by applicant]
E.L. Lawler, “Sequencing Jobs to Minimize Total Weighted Completion Time Subject to Precedence Constraints”, Annals of Discrete Mathematics, 2: 75-90, 1978. [cited by applicant]
E.W. Fulp, “Firewall Architectures for High Speed Networks”, U.S. Department of Energy Grant Application, Funded Sep. 2003. [cited by applicant]
Fulp, “Trie-Based Policy Representations for Network Firewalls,” Proceedings of the IEEE International Symposium on Computer Communications (2005). [cited by applicant]
Fulp, Errin: “CV: Errin Fulp,” XP002618346, www.cs.wfu.edu/fulp/ewfPub.html, pp. 1-5 (Copyright 2010). [cited by applicant]
G. Brightwell et al., “Counting Linear Extensions is #P-Complete”, Proceedings of the Twenty-Third Annual ACM Symposium on Theory of Computing, 1991. [cited by applicant]
G.V. Rooij, “Real Stateful TCP Packet Filtering in IP Filter”, Proceedings of the 10th USENIX Security Symposium, 2001. [cited by applicant]
Greenwald, Michael; “Designing an Academic Firewall: Policy, Practice, and Experience with SURF”; IEEE, Proceedings of SNDSS, 1996. [cited by applicant]
J. Xu et al., “Design and Evaluation of a High-Performance ATM Firewall Switch and Its Applications”, IEEE Journal on Selected Areas in Communications, 17(6): 1190-1200, Jun. 1999. [cited by applicant]
J.K. Lenstra et al., “Complexity of Scheduling Under Precedence Constraints”, Operations Research, 26(1): 22-35, 1978. [cited by applicant]
Kindervag, et al. “Build Security Into Your Network's DNA: The Zero Trust Network Architecture,” Forrester Research Inc.; Nov. 5, 2010, pp. 1-26. [cited by applicant]
L. Qui et al., “Fast Firewall Implementations for Software and Hardware-Based Routers”, Proceedings of ACM Sigmetrics, Jun. 2001. [cited by applicant]
Lee et al., “Development Framework for Firewall Processors,” IEEE, pp. 352-355 (2002). [cited by applicant]
M. Al-Suwaiyel et al., “Algorithms for Trie Compaction”, ACM Transactions on Database Systems, 9(2): 243-263, Jun. 1984. [cited by applicant]
M. Christiansen et al., “Using IDDs for Packet Filtering,” Technical Report, BRICS, Oct. 2002. [cited by applicant]
M. Degermark et al., “Small Forwarding Tables for Fast Routing Lookups”, Proceedings of ACM SIGCOMM, 4-13, 1997. [cited by applicant]
Mizuno et al., A New Remote Configurable Firewall System for Home-use Gateways, Jan. 2005. Second IEEE Consumer Communications and Networking Conference, pp. 599-601. [cited by applicant]
Moore, S, “SBIR Case Study: Centripetal Networks: How CNI Leveraged DHS S&T SBIR Funding to Launch a Successful Cyber Security Company,” 2012 Principal Investigators' Meeting, Cyber Security Division, Oct. 10, 2014. [cited by applicant]
Nichols, et al., “Definition of the Differentiated Services Field (DS Field) in the IPv4 and IPv6 Headers,” Network Working Group RFC 2474, Dec. 1998, 20 pages. [cited by applicant]
O. Paul et al., “A full Bandwidth ATM Firewall”, Proceedings of the 6th European Symposium on Research in Computer Security ESORICS'2000, 2000. [cited by applicant]
P. Warkhede et al., “Fast Packet Classification for Two-Dimensional Conflict-Free Filters”, Proceedings of IEEE Infocom, 1434-1443, 2001. [cited by applicant]
Palo Alto Networks; “Designing a Zero Trust Network With Next-Generation Firewalls”; pp. 1-10; last viewed on Oct. 21, 2012. [cited by applicant]
Perkins, “IP Encapsulation with IP,” Network Working Group RFC 2003, Oct. 1996, 14 pages. [cited by applicant]
R. Funke et al., “Performance Evaluation of Firewalls in Gigabit-Networks”, Proceedings of the Symposium on Performance Evaluation of Computer and Telecommunication Systems, 1999. [cited by applicant]
R. Rivest, “On Self-Organizing Sequential Search Heuristics”, Communications of the ACM, 19(2): 1976. [cited by applicant]
R.L. Graham et al., “Optimization and Approximation in Deterministic Sequencing and Scheduling: A Survey”, Annals of Discrete Mathematics, 5: 287-326, 1979. [cited by applicant]
Reumann, John; “Adaptive Packet Filters”; IEEE, 2001, Department of Electrical Engineering and Computer Science, The University of Michigan, Ann Arbor, MI. [cited by applicant]
S,M. Bellovin et al., “Network Firewalls”, IEEE Communications Magazine, 50-57, 1994. [cited by applicant]
S. Goddard et al., “An Unavailability Analysis of Firewall Sandwich Configurations”, Proceedings of the 6th IEEE Symposium on High Assurance Systems Engineering, 2001. [cited by applicant]
S. Suri et al., “Packet Filtering in High Speed Networks”, Proceedings of the Symposium on Discrete Algorithms, 969-970, 1999. [cited by applicant]
Singh, Rajeev et al. “Detecting and Reducing the Denial of Service attacks in WLANs”, Dec. 2011, World Congress on Information and Communication TEchnologies, pp. 968-973. [cited by applicant]
Sourcefire 3D System User Guide, Version 4.10, Mar. 16, 2011, 2123 pages. [cited by applicant]
Tarsa et al., “Balancing Trie-Based Policy representations for Network Firewalls,” Department of Computer Science, Wake Forest University, pp. 1-6 (2006). [cited by applicant]
Cited By (1)
US 12,574,350