IP Library Granted Patent US 12,513,175
Granted Patent B2
US 12,513,175 · App. 18/430,878 · Granted Dec 30, 2025

Rule-based network-threat detection for encrypted communications

Inventors: David K. Ahn (Winston-Salem, NC); Sean Moore (Hollis, NH); Douglas M. Disabello (Leesburg, VA)
Assignee: Centripetal Networks, LLC
H04L63/1425H04L61/4511H04L63/0227H04L63/0263H04L63/0281H04L63/1416H04L63/20H04L69/22H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,513,175
App. No.
18/430,878
Granted
Dec 30, 2025
Kind
B2
Abstract

A packet-filtering system configured to filter packets in accordance with packet-filtering rules may receive data indicating network-threat indicators and may configure the packet-filtering rules to cause the packet-filtering system to identify packets comprising unencrypted data, and packets comprising encrypted data. A portion of the unencrypted data may correspond to one or more of the network-threat indicators, and the packet-filtering rules may be configured to cause the packet-filtering system to determine, based on the portion of the unencrypted data, that the packets comprising encrypted data correspond to the one or more network-threat indicators.

Claims (201)

1 . A method of filtering encrypted packets by a packet-filtering system comprising at least one processor and memory and configured to filter packets traversing a communications link between a first network and a second network in accordance with a plurality of packet-filtering rules, the method comprising:

receiving, from a rule provider device, the plurality of packet-filtering rules, wherein the plurality of packet-filtering rules were generated based on a plurality of network-threat indicators received from a plurality of different third-party network threat-intelligence providers located external to a network comprising the packet-filtering system, wherein the plurality of packet-filtering rules comprises a first packet-filtering rule configured to identify packets comprising data corresponding to a first network-threat indicator of the plurality of network-threat indicators, and wherein the first network-threat indicator comprises domain name criteria associated with a potential network threat;

receiving, by the packet-filtering system, a plurality of first packets, wherein the plurality of first packets traverse the communications link and comprise first unencrypted data;

determining, by the packet-filtering system, that the plurality of first packets are associated with the potential network threat corresponding to the first packet-filtering rule of the plurality of packet-filtering rules by determining whether a domain name in the first unencrypted data matches the domain name criteria;

generating, by the packet-filtering system and based on the determining that the plurality of first packets are associated with the potential network threat corresponding to the first packet-filtering rule, log data indicating:

an indication of one or more actions; and

an Internet Protocol (IP) address corresponding to the domain name;

receiving, by the packet-filtering system and after the generating the log data, a plurality of second packets of an encrypted communication session, wherein the plurality of second packets traverse the communications link and comprise:

encrypted data, and

respective packet headers comprising second unencrypted data;

determining, by the packet-filtering system and without decrypting the encrypted data, whether the plurality of second packets are associated with the potential network threat corresponding to the first packet-filtering rule by determining that the second unencrypted data corresponds to the logged IP address corresponding to the domain name;

based on determining that the plurality of second packets are associated with the potential network threat corresponding to the first packet-filtering rule, filtering the plurality of second packets based on the first packet-filtering rule;

determining, based on the logged indication of the one or more actions, to apply a first action corresponding to the first packet-filtering rule; and

sending at least a portion of the filtered plurality of second packets to a proxy configured to perform the determined first action corresponding to the first packet-filtering rule.

2 . The method of claim 1 , wherein the determining to apply the first action comprises selecting, from the one or more actions, the first action.

3 . The method of claim 1 , wherein the first action comprises dropping, by the proxy, the at least the portion of the filtered plurality of second packets.

4 . The method of claim 1 , wherein the plurality of first packets comprises the IP address.

5 . The method of claim 1 , wherein the plurality of first packets comprises a Domain Name System (DNS) query comprising the domain name.

6 . The method of claim 5 , wherein the DNS query comprises the IP address corresponding to the domain name.

7 . The method of claim 1 , wherein the plurality of first packets comprise a certificate message for the encrypted communication session, and wherein the first action comprises:

at least one of dropping or logging one or more of the plurality of second packets based on a determination that the certificate message comprises data indicating at least one of:

a serial number indicated by the first packet-filtering rule,

an issuer indicated by the first packet-filtering rule,

a validity time-range indicated by the first packet-filtering rule,

a key indicated by the first packet-filtering rule, or

a signing authority indicated by the first packet-filtering rule.

8 . The method of claim 1 , wherein the first action is based on at least one of:

a uniform resource identifier (URI), domain name, or network address specified by the first packet-filtering rule,

data indicating a protocol version specified by the first packet-filtering rule,

data indicating a method specified by the first packet-filtering rule,

data indicating a request specified by the first packet-filtering rule, or

data indicating a command specified by the first packet-filtering rule.

9 . The method of claim 1 , wherein the plurality of first packets comprise one or more packets comprising one or more handshake messages configured to establish the encrypted communication session.

10 . One or more non-transitory computer-readable media comprising instructions that, when executed by at least one processor of a packet-filtering system configured to filter packets traversing a communications link between a first network and a second network in accordance with a plurality of packet-filtering rules, cause the packet-filtering system to:

receive, from a rule provider device, the plurality of packet-filtering rules, wherein the plurality of packet-filtering rules were generated based on a plurality of network-threat indicators received from a plurality of different third-party network threat-intelligence providers located external to a network comprising the packet-filtering system, wherein the plurality of packet-filtering rules comprises a first packet-filtering rule configured to identify packets comprising data corresponding to a first network-threat indicator of the plurality of network-threat indicators, and wherein the first network-threat indicator comprises domain name criteria associated with a potential network threat;

receive a plurality of first packets, wherein the plurality of first packets traverse the communications link and comprise first unencrypted data;

determine that the plurality of first packets are associated with the potential network threat corresponding to the first packet-filtering rule of the plurality of packet-filtering rules by determining whether a domain name in the first unencrypted data matches the domain name criteria;

generate, based on the determining that the plurality of first packets are associated with the potential network threat corresponding to the first packet-filtering rule, log data indicating:

an indication of one or more actions; and

an Internet Protocol (IP) address corresponding to the domain name;

receive, after the generating the log data, a plurality of second packets of an encrypted communication session, wherein the plurality of second packets traverse the communications link and comprise:

encrypted data, and

respective packet headers comprising second unencrypted data;

determine, without decrypting the encrypted data, whether the plurality of second packets are associated with the potential network threat corresponding to the first packet-filtering rule by determining that the second unencrypted data corresponds to the logged IP address corresponding to the domain name;

based on determining that the plurality of second packets are associated with the potential network threat corresponding to the first packet-filtering rule, filter the plurality of second packets based on the first packet-filtering rule;

determine, based on the logged indication of the one or more actions, to apply a first action corresponding to the first packet-filtering rule; and

send at least a portion of the filtered plurality of second packets to a proxy configured to perform the determined first action corresponding to the first packet-filtering rule.

11 . The one or more non-transitory computer-readable media of claim 10 , wherein the instructions, when executed by the at least one processor, cause the packet-filtering system to determine to apply the first action by causing the packet-filtering system to select, from the one or more actions, the first action.

12 . The one or more non-transitory computer-readable media of claim 10 , wherein the first action comprises dropping, by the proxy, the at least the portion of the filtered plurality of second packets.

13 . The one or more non-transitory computer-readable media of claim 10 , wherein the plurality of first packets comprises the IP address.

14 . The one or more non-transitory computer-readable media of claim 10 , wherein the plurality of first packets comprises a Domain Name System (DNS) query comprising the domain name.

15 . The one or more non-transitory computer-readable media of claim 14 , wherein the DNS query comprises the IP address corresponding to the domain name.

16 . The one or more non-transitory computer-readable media of claim 10 , wherein the plurality of first packets comprise a certificate message for the encrypted communication session, and wherein the first action comprises:

at least one of dropping or logging one or more of the plurality of second packets based on a determination that the certificate message comprises data indicating at least one of:

a serial number indicated by the first packet-filtering rule,

an issuer indicated by the first packet-filtering rule,

a validity time-range indicated by the first packet-filtering rule,

a key indicated by the first packet-filtering rule, or

a signing authority indicated by the first packet-filtering rule.

17 . The one or more non-transitory computer-readable media of claim 10 , wherein the first action is based on at least one of:

a uniform resource identifier (URI), domain name, or network address specified by the first packet-filtering rule,

data indicating a protocol version specified by the first packet-filtering rule,

data indicating a method specified by the first packet-filtering rule,

data indicating a request specified by the first packet-filtering rule, or

data indicating a command specified by the first packet-filtering rule.

18 . A packet-filtering apparatus comprising:

at least one processor configured to filter packets traversing a communications link between a first network and a second network in accordance with a plurality of packet-filtering rules; and

memory storing instructions that when executed by the at least one processor cause the packet-filtering apparatus to:

receive, from a rule provider device, the plurality of packet-filtering rules, wherein the plurality of packet-filtering rules were generated based on a plurality of network-threat indicators received from a plurality of different third-party network threat-intelligence providers located external to a network comprising the packet-filtering system, wherein the plurality of packet-filtering rules comprises a first packet-filtering rule configured to identify packets comprising data corresponding to a first network-threat indicator of the plurality of network-threat indicators, and wherein the first network-threat indicator comprises domain name criteria associated with a potential network threat;

receive a plurality of first packets, wherein the plurality of first packets traverse the communications link and comprise first unencrypted data;

determine that the plurality of first packets are associated with the potential network threat corresponding to the first packet-filtering rule of the plurality of packet-filtering rules by determining whether a domain name in the first unencrypted data matches the domain name criteria;

generate, based on the determining that the plurality of first packets are associated with the potential network threat corresponding to the first packet-filtering rule, log data indicating:

an indication of one or more actions; and

an Internet Protocol (IP) address corresponding to the domain name;

receive, after the generating the log data, a plurality of second packets of an encrypted communication session, wherein the plurality of second packets traverse the communications link and comprise:

encrypted data, and

respective packet headers comprising second unencrypted data;

determine, without decrypting the encrypted data, whether the plurality of second packets are associated with the potential network threat corresponding to the first packet-filtering rule by determining that the second unencrypted data corresponds to the logged IP address corresponding to the domain name;

based on determining that the plurality of second packets are associated with the potential network threat corresponding to the first packet-filtering rule, filter the plurality of second packets based on the first packet-filtering rule;

determine, based on the logged indication of the one or more actions, to apply a first action corresponding to the first packet-filtering rule; and

send at least a portion of the filtered plurality of second packets to a proxy configured to perform the determined first action corresponding to the first packet-filtering rule.

19 . The packet-filtering apparatus of claim 18 , wherein the instructions, when executed by the at least one processor, cause the packet-filtering apparatus to determine to apply the first action by causing the packet-filtering apparatus to select, from the one or more actions, the first action.

20 . The packet-filtering apparatus of claim 18 , wherein the first action comprises dropping, by the proxy, the at least the portion of the filtered plurality of second packets.

21 . The packet-filtering apparatus of claim 18 , wherein the plurality of first packets comprises the IP address.

22 . The packet-filtering apparatus of claim 18 , wherein the plurality of first packets comprises a Domain Name System (DNS) query comprising the domain name.

23 . The packet-filtering apparatus of claim 22 , wherein the DNS query comprises the IP address corresponding to the domain name.

24 . The packet-filtering apparatus of claim 18 , wherein the plurality of first packets comprise a certificate message for the encrypted communication session, and wherein the first action comprises:

at least one of dropping or logging one or more of the plurality of second packets based on a determination that the certificate message comprises data indicating at least one of:

a serial number indicated by the first packet-filtering rule,

an issuer indicated by the first packet-filtering rule,

a validity time-range indicated by the first packet-filtering rule,

a key indicated by the first packet-filtering rule, or

a signing authority indicated by the first packet-filtering rule.

25 . The packet-filtering apparatus of claim 18 , wherein the first action is based on at least one of:

a uniform resource identifier (URI), domain name, or network address specified by the first packet-filtering rule,

data indicating a protocol version specified by the first packet-filtering rule,

data indicating a method specified by the first packet-filtering rule,

data indicating a request specified by the first packet-filtering rule, or

data indicating a command specified by the first packet-filtering rule.

26 . A method of filtering encrypted packets by a packet-filtering system comprising at least one processor and memory and configured to filter packets traversing a communications link between a first network and a second network in accordance with a plurality of packet-filtering rules, the method comprising:

receiving, from a rule provider device, the plurality of packet-filtering rules, wherein the plurality of packet-filtering rules were generated based on a plurality of network-threat indicators received from a plurality of different third-party network threat-intelligence providers located external to a network comprising the packet-filtering system, wherein the plurality of packet-filtering rules comprises a first packet-filtering rule configured to identify packets comprising data corresponding to a first network-threat indicator of the plurality of network-threat indicators, and wherein the first network-threat indicator comprises domain name criteria associated with a potential network threat;

receiving, by the packet-filtering system, a plurality of first packets, wherein the plurality of first packets traverse the communications link and comprise first unencrypted data;

determining, by the packet-filtering system, that the plurality of first packets are associated with the potential network threat corresponding to the first packet-filtering rule of the plurality of packet-filtering rules by determining whether a domain name in the first unencrypted data matches the domain name criteria;

generating, by the packet-filtering system and based on the determining that the plurality of first packets are associated with the potential network threat corresponding to the first packet-filtering rule, log data indicating:

an indication of the first packet-filtering rule; and

an Internet Protocol (IP) address corresponding to the domain name;

receiving, by the packet-filtering system and after the generating the log data, a plurality of second packets of an encrypted communication session, wherein the plurality of second packets traverse the communications link and comprise:

encrypted data, and

respective packet headers comprising second unencrypted data;

determining, by the packet-filtering system and without decrypting the encrypted data, whether the plurality of second packets are associated with the potential network threat corresponding to the first packet-filtering rule by determining that the second unencrypted data corresponds to the logged IP address corresponding to the domain name;

based on determining that the plurality of second packets are associated with the potential network threat corresponding to the first packet-filtering rule, filtering the plurality of second packets based on the first packet-filtering rule;

determining, based on the logged indication of the first packet-filtering rule, to apply a first action corresponding to the first packet-filtering rule; and

sending at least a portion of the filtered plurality of second packets to a proxy configured to perform the determined first action corresponding to the first packet-filtering rule.

27 . The method of claim 26 , wherein the determining to apply the first action comprises selecting, from the one or more actions, the first action.

28 . The method of claim 26 , wherein the determining to apply the first action comprises determining, based on the logged indication of the first packet-filtering rule, the first action.

29 . The method of claim 26 , wherein the first action comprises dropping, by the proxy, the at least the portion of the filtered plurality of second packets.

30 . The method of claim 26 , wherein the plurality of first packets comprises the IP address.

31 . The method of claim 26 , wherein the plurality of first packets comprises a Domain Name System (DNS) query comprising the domain name.

32 . The method of claim 31 , wherein the DNS query comprises the IP address corresponding to the domain name.

33 . The method of claim 26 , wherein the plurality of first packets comprise a certificate message for the encrypted communication session, and wherein the first action comprises:

at least one of dropping or logging one or more of the plurality of second packets based on a determination that the certificate message comprises data indicating at least one of:

a serial number indicated by the first packet-filtering rule,

an issuer indicated by the first packet-filtering rule,

a validity time-range indicated by the first packet-filtering rule,

a key indicated by the first packet-filtering rule, or

a signing authority indicated by the first packet-filtering rule.

34 . The method of claim 26 , wherein the first action is based on at least one of:

a uniform resource identifier (URI), domain name, or network address specified by the first packet-filtering rule,

data indicating a protocol version specified by the first packet-filtering rule,

data indicating a method specified by the first packet-filtering rule,

data indicating a request specified by the first packet-filtering rule, or

data indicating a command specified by the first packet-filtering rule.

35 . The method of claim 26 , wherein the plurality of first packets comprise one or more packets comprising one or more handshake messages configured to establish the encrypted communication session.

36 . One or more non-transitory computer-readable media comprising instructions that, when executed by at least one processor of a packet-filtering system configured to filter packets traversing a communications link between a first network and a second network in accordance with a plurality of packet-filtering rules, cause the packet-filtering system to:

receive, from a rule provider device, the plurality of packet-filtering rules, wherein the plurality of packet-filtering rules were generated based on a plurality of network-threat indicators received from a plurality of different third-party network threat-intelligence providers located external to a network comprising the packet-filtering system, wherein the plurality of packet-filtering rules comprises a first packet-filtering rule configured to identify packets comprising data corresponding to a first network-threat indicator of the plurality of network-threat indicators, and wherein the first network-threat indicator comprises domain name criteria associated with a potential network threat;

receive a plurality of first packets, wherein the plurality of first packets traverse the communications link and comprise first unencrypted data;

determine that the plurality of first packets are associated with the potential network threat corresponding to the first packet-filtering rule of the plurality of packet-filtering rules by determining whether a domain name in the first unencrypted data matches the domain name criteria;

generate, based on the determining that the plurality of first packets are associated with the potential network threat corresponding to the first packet-filtering rule, log data indicating:

an indication of the first packet-filtering rule; and

an Internet Protocol (IP) address corresponding to the domain name;

receive, after the generating the log data, a plurality of second packets of an encrypted communication session, wherein the plurality of second packets traverse the communications link and comprise:

encrypted data, and

respective packet headers comprising second unencrypted data;

determine, without decrypting the encrypted data, whether the plurality of second packets are associated with the potential network threat corresponding to the first packet-filtering rule by determining that the second unencrypted data corresponds to the logged IP address corresponding to the domain name;

based on determining that the plurality of second packets are associated with the potential network threat corresponding to the first packet-filtering rule, filter the plurality of second packets based on the first packet-filtering rule;

determine, based on the logged indication of the first packet-filtering rule, to apply a first action corresponding to the first packet-filtering rule; and

send at least a portion of the filtered plurality of second packets to a proxy configured to perform the determined first action corresponding to the first packet-filtering rule.

37 . The one or more non-transitory computer-readable media of claim 36 , wherein the instructions, when executed by the at least one processor, cause the packet-filtering system to determine to apply the first action by causing the packet-filtering system to select, from the one or more actions, the first action.

38 . The one or more non-transitory computer-readable media of claim 36 , wherein the instructions, when executed by the at least one processor, cause the packet-filtering system to determine, based on the logged indication of the first packet-filtering rule, the first action.

39 . The one or more non-transitory computer-readable media of claim 36 , wherein the first action comprises dropping, by the proxy, the at least the portion of the filtered plurality of second packets.

40 . The one or more non-transitory computer-readable media of claim 36 , wherein the plurality of first packets comprises the IP address.

41 . The one or more non-transitory computer-readable media of claim 36 , wherein the plurality of first packets comprises a Domain Name System (DNS) query comprising the domain name.

42 . The one or more non-transitory computer-readable media of claim 41 , wherein the DNS query comprises the IP address corresponding to the domain name.

43 . The one or more non-transitory computer-readable media of claim 36 , wherein the plurality of first packets comprise a certificate message for the encrypted communication session, and wherein the first action comprises:

at least one of dropping or logging one or more of the plurality of second packets based on a determination that the certificate message comprises data indicating at least one of:

a serial number indicated by the first packet-filtering rule,

an issuer indicated by the first packet-filtering rule,

a validity time-range indicated by the first packet-filtering rule,

a key indicated by the first packet-filtering rule, or

a signing authority indicated by the first packet-filtering rule.

44 . The one or more non-transitory computer-readable media of claim 36 , wherein the first action is based on at least one of:

a uniform resource identifier (URI), domain name, or network address specified by the first packet-filtering rule,

data indicating a protocol version specified by the first packet-filtering rule,

data indicating a method specified by the first packet-filtering rule,

data indicating a request specified by the first packet-filtering rule, or

data indicating a command specified by the first packet-filtering rule.

45 . A packet-filtering apparatus comprising:

at least one processor configured to filter packets traversing a communications link between a first network and a second network in accordance with a plurality of packet-filtering rules; and

memory storing instructions that when executed by the at least one processor cause the packet-filtering apparatus to:

receive, from a rule provider device, the plurality of packet-filtering rules, wherein the plurality of packet-filtering rules were generated based on a plurality of network-threat indicators received from a plurality of different third-party network threat-intelligence providers located external to a network comprising the packet-filtering system, wherein the plurality of packet-filtering rules comprises a first packet-filtering rule configured to identify packets comprising data corresponding to a first network-threat indicator of the plurality of network-threat indicators, and wherein the first network-threat indicator comprises domain name criteria associated with a potential network threat;

receive a plurality of first packets, wherein the plurality of first packets traverse the communications link and comprise first unencrypted data;

determine that the plurality of first packets are associated with the potential network threat corresponding to the first packet-filtering rule of the plurality of packet-filtering rules by determining whether a domain name in the first unencrypted data matches the domain name criteria;

generate, based on the determining that the plurality of first packets are associated with the potential network threat corresponding to the first packet-filtering rule, log data indicating:

an indication of the first packet-filtering rule; and

an Internet Protocol (IP) address corresponding to the domain name;

receive, after the generating the log data, a plurality of second packets of an encrypted communication session, wherein the plurality of second packets traverse the communications link and comprise:

encrypted data, and

respective packet headers comprising second unencrypted data;

determine, without decrypting the encrypted data, whether the plurality of second packets are associated with the potential network threat corresponding to the first packet-filtering rule by determining that the second unencrypted data corresponds to the logged IP address corresponding to the domain name;

based on determining that the plurality of second packets are associated with the potential network threat corresponding to the first packet-filtering rule, filter the plurality of second packets based on the first packet-filtering rule;

determine, based on the logged indication of the first packet-filtering rule, to apply a first action corresponding to the first packet-filtering rule; and

send at least a portion of the filtered plurality of second packets to a proxy configured to perform the determined first action corresponding to the first packet-filtering rule.

46 . The packet-filtering apparatus of claim 45 , wherein the instructions, when executed by the at least one processor, cause the packet-filtering apparatus to determine to apply the first action by causing the packet-filtering apparatus to select, from the one or more actions, the first action.

47 . The packet-filtering apparatus of claim 45 , wherein the instructions, when executed by the at least one processor, cause the packet-filtering apparatus to determine, based on the logged indication of the first packet-filtering rule, the first action.

48 . The packet-filtering apparatus of claim 45 , wherein the first action comprises dropping, by the proxy, the at least the portion of the filtered plurality of second packets.

49 . The packet-filtering apparatus of claim 45 , wherein the plurality of first packets comprises the IP address.

50 . The packet-filtering apparatus of claim 45 , wherein the plurality of first packets comprises a Domain Name System (DNS) query comprising the domain name.

51 . The packet-filtering apparatus of claim 50 , wherein the DNS query comprises the IP address corresponding to the domain name.

52 . The packet-filtering apparatus of claim 45 , wherein the plurality of first packets comprise a certificate message for the encrypted communication session, and wherein the first action comprises:

at least one of dropping or logging one or more of the plurality of second packets based on a determination that the certificate message comprises data indicating at least one of:

a serial number indicated by the first packet-filtering rule,

an issuer indicated by the first packet-filtering rule,

a validity time-range indicated by the first packet-filtering rule,

a key indicated by the first packet-filtering rule, or

a signing authority indicated by the first packet-filtering rule.

53 . The packet-filtering apparatus of claim 45 , wherein the first action is based on at least one of:

a uniform resource identifier (URI), domain name, or network address specified by the first packet-filtering rule,

data indicating a protocol version specified by the first packet-filtering rule,

data indicating a method specified by the first packet-filtering rule,

data indicating a request specified by the first packet-filtering rule, or

data indicating a command specified by the first packet-filtering rule.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 8, 2024
From: AHN, DAVID K.; MOORE, SEAN; DISABELLO, DOUGLAS M.
To: CENTRIPETAL NETWORKS, INC.
Reel/Frame 066421/0918 →
CHANGE OF NAME Recorded Feb 8, 2024
From: CENTRIPETAL NETWORKS, INC.
To: CENTRIPETAL NETWORKS, LLC
Reel/Frame 066541/0761 →
Continuity (5)
Continuation 18370073 · Sep 19, 2023
Continuation 17482894 · Sep 23, 2021
Continuation 15877608 · Jan 23, 2018
Continuation 14757638 · Dec 23, 2015
Related Publication 20240348631A1 · Oct 17, 2024
References Cited (400)
US 5878231A · Baehr et al. · 1999 [cited by applicant]
US 6098172A · Coss et al. · 2000 [cited by applicant]
US 6147976A · Shand et al. · 2000 [cited by applicant]
US 6226372B1 · Beebe et al. · 2001 [cited by applicant]
US 6279113B1 · Vaidya · 2001 [cited by applicant]
US 6317837B1 · Kenworthy · 2001 [cited by applicant]
US 6389532B1 · Gupta et al. · 2002 [cited by applicant]
US 6484261B1 · Wiegel · 2002 [cited by applicant]
US 6611875B1 · Chopra et al. · 2003 [cited by applicant]
US 6662235B1 · Callis et al. · 2003 [cited by applicant]
US 6678827B1 · Rothermel et al. · 2004 [cited by applicant]
US 6826694B1 · Dutta et al. · 2004 [cited by applicant]
US 6907042B1 · Oguchi · 2005 [cited by applicant]
US 6971028B1 · Lyle et al. · 2005 [cited by applicant]
US 7032031B2 · Jungck et al. · 2006 [cited by applicant]
US 7089581B1 · Nagai et al. · 2006 [cited by applicant]
US 7095716B1 · Ke et al. · 2006 [cited by applicant]
US 7107613B1 · Chen et al. · 2006 [cited by applicant]
US 7143438B1 · Coss et al. · 2006 [cited by applicant]
US 7152240B1 · Green et al. · 2006 [cited by applicant]
US 7185368B2 · Copeland, III · 2007 [cited by applicant]
US 7215637B1 · Ferguson et al. · 2007 [cited by applicant]
US 7225269B2 · Watanabe · 2007 [cited by applicant]
US 7227842B1 · Ji et al. · 2007 [cited by applicant]
US 7237267B2 · Rayes et al. · 2007 [cited by applicant]
US 7263099B1 · Woo et al. · 2007 [cited by applicant]
US 7296288B1 · Hill et al. · 2007 [cited by applicant]
US 7299353B2 · Le Pennec et al. · 2007 [cited by applicant]
US 7331061B1 · Ramsey et al. · 2008 [cited by applicant]
US 7437362B1 · Ben-Natan · 2008 [cited by applicant]
US 7478429B2 · Lyon · 2009 [cited by applicant]
US 7499412B2 · Matityahu et al. · 2009 [cited by applicant]
US 7539186B2 · Aerrabotu et al. · 2009 [cited by applicant]
US 7584352B2 · Boivie et al. · 2009 [cited by applicant]
US 7610621B2 · Turley et al. · 2009 [cited by applicant]
US 7684400B2 · Govindarajan et al. · 2010 [cited by applicant]
US 7710885B2 · Ilnicki et al. · 2010 [cited by applicant]
US 7721084B2 · Salminen et al. · 2010 [cited by applicant]
US 7778194B1 · Yung · 2010 [cited by applicant]
US 7792775B2 · Matsuda · 2010 [cited by applicant]
US 7793342B1 · Ebrahimi et al. · 2010 [cited by applicant]
US 7814158B2 · Malik · 2010 [cited by applicant]
US 7814546B1 · Strayer et al. · 2010 [cited by applicant]
US 7818794B2 · Wittman · 2010 [cited by applicant]
US 7849502B1 · Bloch et al. · 2010 [cited by applicant]
US 7913303B1 · Rouland et al. · 2011 [cited by applicant]
US 7954143B2 · Aaron · 2011 [cited by applicant]
US 8004994B1 · Darisi et al. · 2011 [cited by applicant]
US 8009566B2 · Zuk et al. · 2011 [cited by applicant]
US 8037517B2 · Fulp et al. · 2011 [cited by applicant]
US 8042167B2 · Fulp et al. · 2011 [cited by applicant]
US 8117655B2 · Spielman · 2012 [cited by applicant]
US 8156206B2 · Kiley et al. · 2012 [cited by applicant]
US 8161547B1 · Jennings et al. · 2012 [cited by applicant]
US 8176561B1 · Hurst et al. · 2012 [cited by applicant]
US 8219675B2 · Ivershen · 2012 [cited by applicant]
US 8271645B2 · Rajan et al. · 2012 [cited by applicant]
US 8306994B2 · Kenworthy · 2012 [cited by applicant]
US 8307029B2 · Davis et al. · 2012 [cited by applicant]
US 8331234B1 · Newton et al. · 2012 [cited by applicant]
US 8370936B2 · Zuk et al. · 2013 [cited by applicant]
US 8422391B2 · Zhu · 2013 [cited by applicant]
US 8495725B2 · Ahn · 2013 [cited by applicant]
US 8504822B2 · Wang et al. · 2013 [cited by applicant]
US 8510821B1 · Brandwine et al. · 2013 [cited by applicant]
US 8578486B2 · Lifliand et al. · 2013 [cited by applicant]
US 8726379B1 · Stiansen et al. · 2014 [cited by applicant]
US 8789135B1 · Pani · 2014 [cited by applicant]
US 8806638B1 · Mani · 2014 [cited by applicant]
US 8813228B2 · Magee et al. · 2014 [cited by applicant]
US 8832832B1 · Visbal · 2014 [cited by applicant]
US 8856926B2 · Narayanaswamy et al. · 2014 [cited by applicant]
US 8892665B1 · Rostami-Hesarsorkh et al. · 2014 [cited by applicant]
US 8935785B2 · Pandrangi · 2015 [cited by applicant]
US 9077692B1 · Burns et al. · 2015 [cited by applicant]
US 9094445B2 · Moore et al. · 2015 [cited by applicant]
US 9124552B2 · Moore · 2015 [cited by applicant]
US 9137205B2 · Rogers et al. · 2015 [cited by applicant]
US 9154446B2 · Gemelli et al. · 2015 [cited by applicant]
US 9160713B2 · Moore · 2015 [cited by applicant]
US 9172627B2 · Kjendal et al. · 2015 [cited by applicant]
US 9253068B1 · Wu et al. · 2016 [cited by applicant]
US 9258218B2 · Hampel et al. · 2016 [cited by applicant]
US 9419942B1 · Buruganahalli et al. · 2016 [cited by applicant]
US 9531672B1 · Li et al. · 2016 [cited by applicant]
US 9634911B2 · Meloche · 2017 [cited by applicant]
US 9680795B2 · Buruganahalli et al. · 2017 [cited by applicant]
US 9686193B2 · Moore · 2017 [cited by applicant]
US 9875355B1 · Williams · 2018 [cited by applicant]
US 9917852B1 · Xu et al. · 2018 [cited by applicant]
US 9917856B2 · Ahn et al. · 2018 [cited by applicant]
US 10951583B1 · Chandrasekhar · 2021 [cited by examiner]
US 20010039579A1 · Trcka et al. · 2001 [cited by applicant]
US 20010039624A1 · Kellum · 2001 [cited by applicant]
US 20020016858A1 · Sawada et al. · 2002 [cited by applicant]
US 20020038339A1 · Xu · 2002 [cited by applicant]
US 20020049899A1 · Kenworthy · 2002 [cited by applicant]
US 20020083345A1 · Halliday et al. · 2002 [cited by applicant]
US 20020112188A1 · Syvanne · 2002 [cited by applicant]
US 20020152209A1 · Merugu et al. · 2002 [cited by applicant]
US 20020164962A1 · Mankins et al. · 2002 [cited by applicant]
US 20020165949A1 · Na et al. · 2002 [cited by applicant]
US 20020186683A1 · Buck et al. · 2002 [cited by applicant]
US 20020198981A1 · Corl et al. · 2002 [cited by applicant]
US 20030005122A1 · Freimuth et al. · 2003 [cited by applicant]
US 20030014665A1 · Anderson et al. · 2003 [cited by applicant]
US 20030018591A1 · Komisky · 2003 [cited by applicant]
US 20030035370A1 · Brustoloni · 2003 [cited by applicant]
US 20030051026A1 · Carter et al. · 2003 [cited by applicant]
US 20030088787A1 · Egevang · 2003 [cited by applicant]
US 20030097590A1 · Syvanne · 2003 [cited by applicant]
US 20030105976A1 · Copeland · 2003 [cited by applicant]
US 20030120622A1 · Nurmela et al. · 2003 [cited by applicant]
US 20030123456A1 · Denz et al. · 2003 [cited by applicant]
US 20030142681A1 · Chen et al. · 2003 [cited by applicant]
US 20030145225A1 · Bruton et al. · 2003 [cited by applicant]
US 20030154297A1 · Suzuki et al. · 2003 [cited by applicant]
US 20030154399A1 · Zuk et al. · 2003 [cited by applicant]
US 20030188192A1 · Tang et al. · 2003 [cited by applicant]
US 20030212900A1 · Liu et al. · 2003 [cited by applicant]
US 20030220940A1 · Futoransky et al. · 2003 [cited by applicant]
US 20040010712A1 · Hui et al. · 2004 [cited by applicant]
US 20040015719A1 · Lee et al. · 2004 [cited by applicant]
US 20040073655A1 · Kan et al. · 2004 [cited by applicant]
US 20040088542A1 · Daude et al. · 2004 [cited by applicant]
US 20040093513A1 · Cantrell et al. · 2004 [cited by applicant]
US 20040098511A1 · Lin et al. · 2004 [cited by applicant]
US 20040114518A1 · MacFaden et al. · 2004 [cited by applicant]
US 20040123220A1 · Johnson et al. · 2004 [cited by applicant]
US 20040131056A1 · Dark · 2004 [cited by applicant]
US 20040148520A1 · Talpade et al. · 2004 [cited by applicant]
US 20040151155A1 · Jouppi · 2004 [cited by applicant]
US 20040172529A1 · Culbert · 2004 [cited by applicant]
US 20040172557A1 · Nakae et al. · 2004 [cited by applicant]
US 20040177139A1 · Schuba et al. · 2004 [cited by applicant]
US 20040181690A1 · Rothermel et al. · 2004 [cited by applicant]
US 20040193943A1 · Angelino et al. · 2004 [cited by applicant]
US 20040199629A1 · Bomer et al. · 2004 [cited by applicant]
US 20040205360A1 · Norton et al. · 2004 [cited by applicant]
US 20040250124A1 · Chesla et al. · 2004 [cited by applicant]
US 20050010765A1 · Swander et al. · 2005 [cited by applicant]
US 20050024189A1 · Weber · 2005 [cited by applicant]
US 20050071650A1 · Jo et al. · 2005 [cited by applicant]
US 20050076227A1 · Kang et al. · 2005 [cited by applicant]
US 20050102525A1 · Akimoto · 2005 [cited by applicant]
US 20050108557A1 · Kayo et al. · 2005 [cited by applicant]
US 20050114704A1 · Swander · 2005 [cited by applicant]
US 20050117576A1 · McDysan et al. · 2005 [cited by applicant]
US 20050125697A1 · Tahara · 2005 [cited by applicant]
US 20050138204A1 · Iyer et al. · 2005 [cited by applicant]
US 20050138353A1 · Spies et al. · 2005 [cited by applicant]
US 20050138426A1 · Styslinger · 2005 [cited by applicant]
US 20050141537A1 · Kumar et al. · 2005 [cited by applicant]
US 20050183140A1 · Goddard · 2005 [cited by applicant]
US 20050229246A1 · Rajagopal et al. · 2005 [cited by applicant]
US 20050249214A1 · Peng · 2005 [cited by applicant]
US 20050251570A1 · Heasman et al. · 2005 [cited by applicant]
US 20050283823A1 · Okajo et al. · 2005 [cited by applicant]
US 20050286522A1 · Paddon et al. · 2005 [cited by applicant]
US 20060031928A1 · Conley et al. · 2006 [cited by applicant]
US 20060048142A1 · Roese et al. · 2006 [cited by applicant]
US 20060053491A1 · Khuti et al. · 2006 [cited by applicant]
US 20060070122A1 · Bellovin · 2006 [cited by applicant]
US 20060080733A1 · Khosmood et al. · 2006 [cited by applicant]
US 20060085849A1 · Culbert · 2006 [cited by applicant]
US 20060104202A1 · Reiner · 2006 [cited by applicant]
US 20060114899A1 · Toumura et al. · 2006 [cited by applicant]
US 20060133377A1 · Jain · 2006 [cited by applicant]
US 20060136987A1 · Okuda · 2006 [cited by applicant]
US 20060137009A1 · Chesla · 2006 [cited by applicant]
US 20060146879A1 · Anthias et al. · 2006 [cited by applicant]
US 20060159028A1 · Curran-Gray et al. · 2006 [cited by applicant]
US 20060195896A1 · Fulp et al. · 2006 [cited by applicant]
US 20060212572A1 · Afek et al. · 2006 [cited by applicant]
US 20060248580A1 · Fulp et al. · 2006 [cited by applicant]
US 20060262798A1 · Joshi et al. · 2006 [cited by applicant]
US 20070056038A1 · Lok · 2007 [cited by applicant]
US 20070083924A1 · Lu · 2007 [cited by applicant]
US 20070118894A1 · Bhatia · 2007 [cited by applicant]
US 20070147380A1 · Ormazabal et al. · 2007 [cited by applicant]
US 20070180510A1 · Long et al. · 2007 [cited by applicant]
US 20070211644A1 · Ottamalika et al. · 2007 [cited by applicant]
US 20070240208A1 · Yu et al. · 2007 [cited by applicant]
US 20070266241A1 · Wu et al. · 2007 [cited by applicant]
US 20070271605A1 · Le Pennec et al. · 2007 [cited by applicant]
US 20070291789A1 · Kutt et al. · 2007 [cited by applicant]
US 20080005795A1 · Acharya et al. · 2008 [cited by applicant]
US 20080028467A1 · Kommareddy et al. · 2008 [cited by applicant]
US 20080043739A1 · Suh et al. · 2008 [cited by applicant]
US 20080072307A1 · Maes · 2008 [cited by applicant]
US 20080077705A1 · Li et al. · 2008 [cited by applicant]
US 20080080493A1 · Weintraub et al. · 2008 [cited by applicant]
US 20080086435A1 · Chesla · 2008 [cited by applicant]
US 20080101234A1 · Nakil et al. · 2008 [cited by applicant]
US 20080163333A1 · Kasralikar · 2008 [cited by applicant]
US 20080201772A1 · Mondaeev et al. · 2008 [cited by applicant]
US 20080229415A1 · Kapoor et al. · 2008 [cited by applicant]
US 20080235755A1 · Blaisdell et al. · 2008 [cited by applicant]
US 20080279196A1 · Friskney et al. · 2008 [cited by applicant]
US 20080301765A1 · Nicol et al. · 2008 [cited by applicant]
US 20080313738A1 · Enderby · 2008 [cited by applicant]
US 20080320116A1 · Briggs · 2008 [cited by applicant]
US 20090028160A1 · Eswaran et al. · 2009 [cited by applicant]
US 20090138938A1 · Harrison et al. · 2009 [cited by applicant]
US 20090144819A1 · Babbar et al. · 2009 [cited by applicant]
US 20090150972A1 · Moon et al. · 2009 [cited by applicant]
US 20090172800A1 · Wool · 2009 [cited by applicant]
US 20090222877A1 · Diehl et al. · 2009 [cited by applicant]
US 20090240698A1 · Shukla et al. · 2009 [cited by applicant]
US 20090262723A1 · Pelletier et al. · 2009 [cited by applicant]
US 20090262741A1 · Jungck et al. · 2009 [cited by applicant]
US 20090300759A1 · Wang et al. · 2009 [cited by applicant]
US 20090320106A1 · Jones et al. · 2009 [cited by applicant]
US 20090328219A1 · Narayanaswamy · 2009 [cited by applicant]
US 20100011433A1 · Harrison et al. · 2010 [cited by applicant]
US 20100011434A1 · Kay · 2010 [cited by applicant]
US 20100037311A1 · He et al. · 2010 [cited by applicant]
US 20100082811A1 · Van Der Merwe et al. · 2010 [cited by applicant]
US 20100095367A1 · Narayanaswamy · 2010 [cited by applicant]
US 20100107240A1 · Thaler et al. · 2010 [cited by applicant]
US 20100115621A1 · Staniford et al. · 2010 [cited by applicant]
US 20100132027A1 · Ou · 2010 [cited by applicant]
US 20100138910A1 · Aldor et al. · 2010 [cited by applicant]
US 20100195503A1 · Raleigh · 2010 [cited by applicant]
US 20100199346A1 · Ling et al. · 2010 [cited by applicant]
US 20100202299A1 · Strayer et al. · 2010 [cited by applicant]
US 20100211678A1 · McDysan et al. · 2010 [cited by applicant]
US 20100232445A1 · Bellovin · 2010 [cited by applicant]
US 20100242098A1 · Kenworthy · 2010 [cited by applicant]
US 20100250731A1 · Xiao · 2010 [cited by applicant]
US 20100250918A1 · Tremblay et al. · 2010 [cited by applicant]
US 20100268799A1 · Maestas · 2010 [cited by applicant]
US 20100296441A1 · Barkan · 2010 [cited by applicant]
US 20100303240A1 · Beachem et al. · 2010 [cited by applicant]
US 20110055916A1 · Ahn · 2011 [cited by applicant]
US 20110055923A1 · Thomas · 2011 [cited by applicant]
US 20110088092A1 · Nguyen et al. · 2011 [cited by applicant]
US 20110141900A1 · Jayawardena et al. · 2011 [cited by applicant]
US 20110154470A1 · Grimes et al. · 2011 [cited by applicant]
US 20110185055A1 · Nappier et al. · 2011 [cited by applicant]
US 20110214157A1 · Korsunsky et al. · 2011 [cited by applicant]
US 20110270956A1 · McDysan et al. · 2011 [cited by applicant]
US 20110277034A1 · Hanson · 2011 [cited by applicant]
US 20110296186A1 · Wong et al. · 2011 [cited by applicant]
US 20110314270A1 · Lifliand · 2011 [cited by examiner]
US 20120005743A1 · Kitazawa et al. · 2012 [cited by applicant]
US 20120023576A1 · Sorensen et al. · 2012 [cited by applicant]
US 20120084866A1 · Stolfo · 2012 [cited by applicant]
US 20120106354A1 · Pleshek et al. · 2012 [cited by applicant]
US 20120110656A1 · Santos et al. · 2012 [cited by applicant]
US 20120113987A1 · Riddoch et al. · 2012 [cited by applicant]
US 20120124645A1 · Ratica et al. · 2012 [cited by applicant]
US 20120240135A1 · Risbood et al. · 2012 [cited by applicant]
US 20120240185A1 · Kapoor et al. · 2012 [cited by applicant]
US 20120264443A1 · Ng et al. · 2012 [cited by applicant]
US 20120290829A1 · Altman · 2012 [cited by applicant]
US 20120314617A1 · Erichsen et al. · 2012 [cited by applicant]
US 20120331543A1 · Bostrom et al. · 2012 [cited by applicant]
US 20130007257A1 · Ramaraj et al. · 2013 [cited by applicant]
US 20130047020A1 · Hershko et al. · 2013 [cited by applicant]
US 20130059527A1 · Hasesaka et al. · 2013 [cited by applicant]
US 20130061294A1 · Kenworthy · 2013 [cited by applicant]
US 20130104236A1 · Ray et al. · 2013 [cited by applicant]
US 20130117852A1 · Stute · 2013 [cited by applicant]
US 20130139236A1 · Rubinstein et al. · 2013 [cited by applicant]
US 20130254766A1 · Zuo et al. · 2013 [cited by applicant]
US 20130291100A1 · Ganapathy et al. · 2013 [cited by applicant]
US 20130305311A1 · Puttaswamy Naga et al. · 2013 [cited by applicant]
US 20130312054A1 · Wang et al. · 2013 [cited by applicant]
US 20140075510A1 · Sonoda et al. · 2014 [cited by applicant]
US 20140082204A1 · Shankar et al. · 2014 [cited by applicant]
US 20140082730A1 · Vashist et al. · 2014 [cited by applicant]
US 20140089661A1 · Mahadik et al. · 2014 [cited by applicant]
US 20140115654A1 · Rogers et al. · 2014 [cited by applicant]
US 20140150051A1 · Bharali et al. · 2014 [cited by applicant]
US 20140165189A1 · Foley et al. · 2014 [cited by applicant]
US 20140201123A1 · Ahn et al. · 2014 [cited by applicant]
US 20140215561A1 · Roberson et al. · 2014 [cited by applicant]
US 20140215574A1 · Erb et al. · 2014 [cited by applicant]
US 20140245423A1 · Lee · 2014 [cited by applicant]
US 20140259170A1 · Amsler · 2014 [cited by applicant]
US 20140281030A1 · Cui et al. · 2014 [cited by applicant]
US 20140283004A1 · Moore · 2014 [cited by applicant]
US 20140283030A1 · Moore et al. · 2014 [cited by applicant]
US 20140310396A1 · Christodorescu et al. · 2014 [cited by applicant]
US 20140317397A1 · Martini · 2014 [cited by applicant]
US 20140317737A1 · Shin et al. · 2014 [cited by applicant]
US 20140337613A1 · Martini · 2014 [cited by applicant]
US 20140365372A1 · Ross et al. · 2014 [cited by applicant]
US 20140366132A1 · Stiansen et al. · 2014 [cited by applicant]
US 20140373156A1 · Dubrovsky et al. · 2014 [cited by applicant]
US 20150033336A1 · Wang et al. · 2015 [cited by applicant]
US 20150052345A1 · Martini · 2015 [cited by applicant]
US 20150052601A1 · White et al. · 2015 [cited by applicant]
US 20150106930A1 · Honda et al. · 2015 [cited by applicant]
US 20150121449A1 · Cp et al. · 2015 [cited by applicant]
US 20150128274A1 · Giokas · 2015 [cited by applicant]
US 20150135325A1 · Stevens et al. · 2015 [cited by applicant]
US 20150207809A1 · Macaulay · 2015 [cited by applicant]
US 20150207813A1 · Reybok et al. · 2015 [cited by applicant]
US 20150237012A1 · Moore · 2015 [cited by applicant]
US 20150244734A1 · Olson et al. · 2015 [cited by applicant]
US 20150256431A1 · Buchanan et al. · 2015 [cited by applicant]
US 20150304354A1 · Rogers et al. · 2015 [cited by applicant]
US 20150334125A1 · Bartos et al. · 2015 [cited by applicant]
US 20150341389A1 · Kurakami · 2015 [cited by applicant]
US 20150347246A1 · Matsui et al. · 2015 [cited by applicant]
US 20150350229A1 · Mitchell · 2015 [cited by applicant]
US 20150372977A1 · Mn · 2015 [cited by applicant]
US 20150373043A1 · Wang et al. · 2015 [cited by applicant]
US 20160020968A1 · Aumann et al. · 2016 [cited by applicant]
US 20160028751A1 · Cruz Mota et al. · 2016 [cited by applicant]
US 20160065611A1 · Fakeri-Tabrizi et al. · 2016 [cited by applicant]
US 20160112443A1 · Grossman et al. · 2016 [cited by applicant]
US 20160119365A1 · Barel · 2016 [cited by applicant]
US 20160127417A1 · Janssen · 2016 [cited by applicant]
US 20160180022A1 · Paixao · 2016 [cited by applicant]
US 20160191558A1 · Davison · 2016 [cited by applicant]
US 20160205069A1 · Blocher et al. · 2016 [cited by applicant]
US 20160219065A1 · Dasgupta et al. · 2016 [cited by applicant]
US 20160285706A1 · Rao · 2016 [cited by applicant]
US 20160294870A1 · Banerjee et al. · 2016 [cited by applicant]
US 20160359807A1 · Buruganahalli et al. · 2016 [cited by applicant]
US 20160366099A1 · Jordan · 2016 [cited by applicant]
US 20170171232A1 · Graham-Cumming · 2017 [cited by applicant]
US 20170223046A1 · Singh · 2017 [cited by applicant]
US 20170272469A1 · Kraemer et al. · 2017 [cited by applicant]
AU 2005328336B2 · 2011 [cited by applicant]
AU 2006230171B2 · 2012 [cited by applicant]
CA 2600236A1 · 2006 [cited by applicant]
EP 1006701A2 · 2000 [cited by applicant]
EP 1313290A1 · 2003 [cited by applicant]
EP 1484884A2 · 2004 [cited by applicant]
EP 1677484A2 · 2006 [cited by applicant]
EP 2385676A1 · 2011 [cited by applicant]
EP 2498442A1 · 2012 [cited by applicant]
EP 1864226B1 · 2013 [cited by applicant]
KR 20010079361A · 2001 [cited by applicant]
KR 1020090076556A · 2009 [cited by applicant]
WO 2005046145A1 · 2005 [cited by applicant]
WO 2006093557A2 · 2006 [cited by applicant]
WO 2006105093A2 · 2006 [cited by applicant]
WO 2007109541A2 · 2007 [cited by applicant]
WO 2011038420A2 · 2011 [cited by applicant]
WO 2012146265A1 · 2012 [cited by applicant]
WO 2017112535A1 · 2017 [cited by applicant]
R.L. Graham et al., “Optimization and Approximation in Deterministic Sequencing and Scheduling: A Survey”, Annals of Discrete Mathematics, 5: 287-326, 1979. [cited by applicant]
Reumann, John; “Adaptive Packet Filters”; IEEE, 2001, Department of Electrical Engineering and Computer Science, The University of Michigan, Ann Arbor, MI. [cited by applicant]
S,M. Bellovin et al., “Network Firewalls”, IEEE Communications Magazine, 50-57, 1994. [cited by applicant]
S. Goddard et al., “An Unavailability Analysis of Firewall Sandwich Configurations”, Proceedings of the 6th IEEE Symposium on High Assurance Systems Engineering, 2001. [cited by applicant]
S. Suri et al., “Packet Filtering in High Speed Networks”, Proceedings of the Symposium on Discrete Algorithms, 969-970, 1999. [cited by applicant]
Singh, Rajeev et al. “Detecting and Reducing the Denial of Service attacks in WLANs”, Dec. 2011, World Congress on Information and Communication TEchnologies, pp. 968-973. [cited by applicant]
Statement Re: Related Application, dated Jul. 24, 2015. [cited by applicant]
Tarsa et al., “Balancing Trie-Based Policy representations for Network Firewalls,” Department of Computer Science, Wake Forest University, pp. 1-6 (2006). [cited by applicant]
U. Ellermann et al., “Firewalls for ATM Networks”, Proceedings of INFOSEC'COM, 1998. [cited by applicant]
V. Srinivasan et al., “Fast and Scalable Layer Four Switching”, Proceedings of ACM SIGCOMM, 191-202, 1998. [cited by applicant]
V.P. Ranganath, “A Set-Based Approach to Packet Classification”, Proceedings of the IASTED International Conference on Parallel and Distributed Computing and Systems, 889-894, 2003. [cited by applicant]
W.E. Leland et al., “On the Self-Similar Nature of Ethernet Traffic”, IEEE Transactions on Networking, 2(1); 15, 1994. [cited by applicant]
W.E. Smith, “Various Optimizers for Single-Stage Productions”, Naval Research Logistics Quarterly, 3: 59-66, 1956. [cited by applicant]
X. Gan et al., “LSMAC vs. LSNAT: Scalable Cluster-based Web servers”, Journal of Networks, Software Tools, and Applications, 3(3): 175-185, 2000. [cited by applicant]
Ylonen, et al, “The Secure Shell (SSH) Transport Layer Protocol,” SSH Communication Security Corp, Newtork Working Group RFC 4253, Jan. 2006, 32 pages. [cited by applicant]
Aug. 10, 2018 (US) Declaration of Kevin Jeffay, PhD in Support of Fourth Petition for Inter Partes Review of U.S. Pat. No. 9,137,205—IPR2018-01506. [cited by applicant]
Aug. 10, 2018 (US) Fourth Petition for Inter Partes Review of U.S. Pat. No. 9,137,205—IPR2018-01506. [cited by applicant]
Aug. 3, 2018 (US) Third Petition for Inter Partes Review of U.S. Pat. No. 9,137,205—IPR2018-01505. [cited by applicant]
Aug. 3, 2018 (US) Declaration of Kevin Jeffay, PhD in Support of Third Petition for Inter Partes Review of U.S. Pat. No. 9,137,205—IPR2018-01505. [cited by applicant]
Aug. 3, 2018 (US) Declaration of Kevin Jeffay, PhD in Support of Third Petition for Inter Partes Review of U.S. Pat. No. 9,560,077—IPR2018-01513. [cited by applicant]
Apr. 2, 2019 (US) Decision—Institution of Inter Partes Review of U.S. Pat. No. 9,560,077—IPR 2018-01513. [cited by applicant]
Aug. 10, 2018 (US) Petition for Inter Partes Review of Claims 1-20 of U.S. Pat. No. 9,560,077—IPR2018-01513. [cited by applicant]
Jun. 3, 2019 (US) Final Office Action—U.S. Appl. No. 15/614,956. [cited by applicant]
May 23, 2019 (US) Non-Final Office Action—U.S. Appl. No. 14/745,207. [cited by applicant]
May 24, 2019 (US) Non-Final Office Action—U.S. Appl. No. 16/111,524. [cited by applicant]
Jun. 3, 2019 (EP) Communication pursuant to Article 94(3) EPC—Third Examination Report—App. 13765547.8. [cited by applicant]
Aug. 2, 2018 (US) Notice of Allowance and Fees Due—U.S. Appl. No. 16/030,254. [cited by applicant]
Jul. 5, 2019 (EP) Extended European Search Report—App. 19179539.2. [cited by applicant]
Aug. 2, 2019 (CA) Office Action—App. 2,888,935. [cited by applicant]
Aug. 2, 2019 (US) Non-Final Office Action—U.S. Appl. No. 16/448,969. [cited by applicant]
Aug. 16, 2019 (EP) Extended Search Report—App. 19170936.9. [cited by applicant]
Sep. 18, 2018 (US) Petition for Inter Partes Review of U.S. Pat. No. 9,413,722—IPR 2018-01760. [cited by applicant]
Sep. 18, 2018 (US) Declaration of Dr. Stuart Staniford in Support of Petition for Inter Partes Review of U.S. Pat. No. 9,413,722—IPR 2018-01760. [cited by applicant]
Sep. 3, 2019 (US) Notice of Allowance and Fees Due—U.S. Appl. No. 16/518,190. [cited by applicant]
Aug. 19, 2019 (EP) Communication pursuant to Article 94(3) EPC—Examination Report—App. 14719415.3. [cited by applicant]
Oct. 11, 2019—(US) Non-Final Office Action—U.S. Appl. No. 16/554,293. [cited by applicant]
Oct. 10, 2019—(US) Notice of Allowance—U.S. Appl. No. 16/448,997. [cited by applicant]
Sep. 30, 2019 (WO) International Search Report and Written Opinion of International Searching Authority—Application No. PCT/US2019/040830. [cited by applicant]
Exhibit 1022—“Transmission Control Protocol,” IETF RFC 793. J. Postel, ed., Sep. 1981. [cited by applicant]
Exhibit 1023—“Internet Protocol,” IETF RFC 791, J. Postel, ed., Sep. 1981. [cited by applicant]
Exhibit 1024—“File Transfer Protocol,” IETF RFC 765, J. Postel, ed., Jun. 1980. [cited by applicant]
May 20, 2019 (US) Decision—Institution of Inter Partes Review of U.S. Pat. No. 9,413,722 B1—IPR 2018-01760. [cited by applicant]
Aug. 20, 2019 (US) Declaration of Dr. Alessandro Orso in Support of Patent Owner's Response of U.S. Pat. No. 9,413,722—IPR 2018-01760. [cited by applicant]
Feb. 21, 2019 (US) Patent Owner's Preliminary Response of U.S. Pat. No. 9,413,722—IPR 2018-01760. [cited by applicant]
Aug. 20, 2019 (US) Patent Owner's Response of U.S. Pat. No. 9,413,722—IPR 2018-01760. [cited by applicant]
Jan. 15, 2020 (US) Patent Owner's Sur-Reply to Petitioner's Reply—IPR 2018-01760. [cited by applicant]
Jan. 8, 2020 (US) Deposition of Jacob H. Baugher, III—IPR 2018-01760. [cited by applicant]
Nov. 4, 2020—(US) Non-Final Office Action—U.S. Appl. No. 15/877,608. [cited by applicant]
Apr. 13, 2020—(US) Final Office Action—U.S. Appl. No. 15/877,608. [cited by applicant]
Dec. 2, 2019—(US) Non-Final Office Action—U.S. Appl. No. 15/877,608. [cited by applicant]
Sep. 4, 2018 (WO) International Search Report and Written Opinion—App. PCT/US2018/041355. [cited by applicant]
Sep. 27, 2010 (US) Non-Final Office Action—U.S. Appl. No. 15/614,956. [cited by applicant]
Apr. 8, 2019 (US) Final Office Action—U.S. Appl. No. 15/413,947. [cited by applicant]
Feb. 21, 2019 (US) Final Office Action—U.S. Appl. No. 15/382,806. [cited by applicant]