IP Library Granted Patent US 12,299,117
Granted Patent B2
US 12,299,117 · App. 17/589,868 · Granted May 13, 2025

Method and system of monitoring and controlling exfiltration of enterprise data on cloud

Inventors: Krishna Narayanaswamy (Saratoga, CA); Steve Malmskog (San Jose, CA); Arjun Sambamoorthy (San Jose, CA)
Assignee: Netskope, Inc.
G06F21/554G06F21/602G06F21/6209G06F21/6218H04L9/083H04L9/0861H04L9/0866H04L9/0869H04L9/0872H04L9/3236H04L63/0281H04L63/0435H04L63/062H04L63/123H04L63/1416H04L63/145H04L63/1458H04L67/1097H04W12/088H04L2463/061
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,299,117
App. No.
17/589,868
Granted
May 13, 2025
Kind
B2
Abstract

The technology disclosed relates to method and system of monitoring and controlling exfiltration of enterprise data stored on the cloud computing service (CCS). The method and system includes using a cross-application monitor to detect a could service application programming interface (API) in use and a function or activity being performed via the CCS API. The method and system determines the function or activity by parsing a data stream based on the CCS API and identifies a content of the enterprise data subject to content control by the application of a content inspection rule data subject to content control. The method and system selects a security action being applied to the enterprise data to prevent exfiltration based on the classification of the inspected data and policies applicable to the content subject to content control.

Claims (55)

1. A computer-implemented method of monitoring and controlling exfiltration of enterprise data, the method comprising:

using a cross-application monitor to detect:

a cloud computing service (CCS) application programming interface (API) in use, and

a function or an activity being performed via the CCS API on a file,

wherein the cross-application monitor is hosted from a computing system communicatively coupled to a network to which the CCS and an endpoint requesting the function or the activity are communicatively coupled;

determining, by the cross-application monitor, the function or the activity being performed by parsing a data stream based on the CCS API and identifying content in the file;

applying, by the cross-application monitor, a content inspection rule to find strings and interrelated strings in the content that are subject to content control, wherein the content inspection rule comprises a multi-part string search pattern that matches two or more non-contiguous strings;

in response to finding a threshold number of strings and interrelated strings in the content, classifying, by the cross-application monitor, the content into a content type of a plurality of content types based on the threshold number of strings and interrelated strings, wherein the content type indicates a specific type of confidential data;

selecting, by the cross-application monitor, a security action from a plurality of security actions based on the content type of the content; and

performing, by the cross-application monitor, the security action on the file.

2. The computer-implemented method of claim 1 , wherein the security action is selected by one or more security engines of the cross-application monitor that access one or more content policies to select the security action based on the content type.

3. The computer-implemented method of claim 2 , wherein the one or more security engines include a block sub-engine, a bypass sub-engine, a remediate sub-engine, a justification sub-engine, a quarantine sub-engine, and/or an encryption sub-engine.

4. The computer-implemented method of claim 1 , wherein the performing the security action comprises:

encrypting the file stored on the CCS using a per-document key derived by applying a key derivation function (KDF) to a triplet-key, a document identifier (ID), and a salt.

5. The computer-implemented method of claim 4 , wherein the performing the security action further comprises:

authorizing a user for decryption based on a plurality of condition variables, including at least one data classification tag.

6. The computer-implemented method of claim 1 , wherein the security action comprises requiring justification of using the CCS API in use for the content in the parsed stream as a condition of completing the function or the activity being performed.

7. The computer-implemented method of claim 1 , wherein the security action comprises generating one or more coaching messages that identify a more secure alternative to the CCS API in use.

8. The computer-implemented method of claim 7 , further comprising:

identifying the more secure alternative using a cloud confidence index™ (CCI) that is determined based on at least one of data encryption policies of a CCS, disaster management policies of the CCS, number of data centers supporting the CCS, and compliance certifications of the data centers.

9. A system that monitors and controls exfiltration of enterprise data, the system comprising:

a processor and a non-transitory computer readable storage medium storing computer instructions configured to cause the processor to execute a method including:

using a cross-application monitor to detect:

a cloud computing service (CCS) application programming interface (API) in use, and

a function or an activity being performed via the CCS API on a file,

wherein the system is communicatively coupled to a network to which the CCS and an endpoint requesting the function or the activity are communicatively coupled;

determining the function or the activity being performed by parsing a data stream based on the CCS API and identifying content in the file;

applying a content inspection rule to find strings and interrelated strings in the content that are subject to content control, wherein the content inspection rule comprises a multi-part string search pattern that matches two or more non-contiguous strings;

in response to finding a threshold number of strings and interrelated strings in the content, classifying the content into a content type of a plurality of content types based on the threshold number of strings and interrelated strings, wherein the content type indicates a specific type of confidential data;

selecting a security action from a plurality of security actions based on the content type of the content; and

performing the security action on the file.

10. The system of claim 9 , wherein the security action is selected by one or more security engines of the cross-application monitor that access one or more content policies to select the security action based on the content type.

11. The system of claim 10 , wherein the one or more security engines include a block sub-engine, a bypass sub-engine, a remediate sub-engine, a justification sub-engine, a quarantine sub-engine, and/or an encryption sub-engine.

12. The system of claim 10 , wherein the computer instructions to perform the security action comprise further computer instructions configured to cause the processor to execute the method further including:

encrypting the file stored on the CCS using a per-document key derived by applying a key derivation function (KDF) to a triplet-key, a document identifier (ID), and a salt.

13. The system of claim 12 , wherein the computer instructions to perform the security action comprise further computer instructions configured to cause the processor to execute the method further including:

authorizing a user for decryption based on a plurality of condition variables, including at least one data classification tag.

14. The system of claim 9 , wherein the security action comprises requiring justification of using the CCS API in use for the content in the parsed stream as a condition of completing the function or the activity being performed.

15. The system of claim 9 , wherein the security action comprises generating one or more coaching messages that identify a more secure alternative to the CCS API in use.

16. A tangible non-transitory computer readable storage medium, having program instructions loaded into memory that, when executed on processors, cause the processors to implement steps of monitoring and controlling exfiltration of enterprise data, the steps including:

using a cross-application monitor to detect:

a cloud computing service (CCS) application programming interface (API) in use, and

a function or an activity being performed via the CCS API on a file,

wherein the cross-application monitor is hosted from a computing system communicatively coupled to a network to which the CCS and an endpoint requesting the function or the activity are communicatively coupled;

determining, by the cross-application monitor, the function or the activity being performed via the CCS API by parsing a data stream based on the CCS API and identifying content in the file;

applying, by the cross-application monitor, a content inspection rule to find strings and interrelated strings in the content that are subject to content control, wherein the content inspection rule comprises a multi-part string search pattern that matches two or more non-contiguous strings;

in response to finding a threshold number of strings and interrelated strings in the content, classifying, by the cross-application monitor, the content into a content type of a plurality of content types based on the threshold number of strings and interrelated strings, wherein the content type indicates a specific type of confidential data;

selecting, by the cross-application monitor, a security action from a plurality of security actions based on the content type of the content; and

performing, by the cross-application monitor, the security action on the file.

17. The non-transitory computer readable storage medium of claim 16 , wherein the security action is selected by one or more security engines of the cross-application monitor that access one or more content policies to select the security action based on the content type.

18. The non-transitory computer readable storage medium of claim 16 , wherein the program instructions to perform the security action comprise further program instructions that, when executed on the processors, cause the processors to implement the steps further including:

encrypting the file using a per-document key derived by applying a key derivation function (KDF) to a triplet-key, a document identifier (ID), and a salt.

19. The non-transitory computer readable storage medium of claim 16 , wherein the security action comprises generating one or more coaching messages that identify a more secure alternative to the CCS API in use.

20. The non-transitory computer readable storage medium of claim 16 , wherein the program instructions comprise further program instructions that, when executed on the processors, cause the processors to implement the steps further including:

identifying the more secure alternative using a cloud confidence index™ (CCI) that is determined based on at least one of data encryption policies of a CCS, disaster management policies of the CCS, number of data centers supporting the CCS, and compliance certifications of the data centers.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2022
From: NARAYANASWAMY, KRISHNA; MALMSKOG, STEVE; SAMBAMOORTHY, ARJUN
To: NETSKOPE, INC.
Reel/Frame 058852/0536 →
Continuity (4)
Continuation 16128015 · Sep 11, 2018
Continuation 14835632 · Aug 25, 2015
Provisional Application 62135656 · Mar 19, 2015
Related Publication 20220156369A1 · May 19, 2022
References Cited (242)
US 5440723A · Arnold et al. · 1995 [cited by applicant]
US 5452460A · Distelberg et al. · 1995 [cited by applicant]
US 6513122B1 · Magdych et al. · 2003 [cited by applicant]
US 6622248B1 · Hirai · 2003 [cited by applicant]
US 7080408B1 · Pak et al. · 2006 [cited by applicant]
US 7272646B2 · Cooper et al. · 2007 [cited by applicant]
US 7298864B2 · Jones · 2007 [cited by applicant]
US 7376719B1 · Shafer et al. · 2008 [cited by applicant]
US 7478434B1 · Hinton et al. · 2009 [cited by applicant]
US 7735116B1 · Gauvin · 2010 [cited by applicant]
US 7966654B2 · Crawford · 2011 [cited by applicant]
US 8000329B2 · Fendick et al. · 2011 [cited by applicant]
US 8296178B2 · Hudis et al. · 2012 [cited by applicant]
US 8346580B2 · Nakfoor · 2013 [cited by applicant]
US 8365243B1 · Lu et al. · 2013 [cited by applicant]
US 8572757B1 · Stamos et al. · 2013 [cited by applicant]
US 8677448B1 · Kauffman et al. · 2014 [cited by applicant]
US 8793151B2 · DelZoppo et al. · 2014 [cited by applicant]
US 8839417B1 · Jordan · 2014 [cited by applicant]
US 8856869B1 · Brinskelle · 2014 [cited by applicant]
US 9069955B2 · Dolph et al. · 2015 [cited by applicant]
US 9137131B1 · Sarukkai et al. · 2015 [cited by applicant]
US 9197601B2 · Pasdar · 2015 [cited by applicant]
US 9197628B1 · Hastings · 2015 [cited by applicant]
US 9225734B1 · Hastings · 2015 [cited by applicant]
US 9231968B2 · Fang et al. · 2016 [cited by applicant]
US 9246944B1 · Chen · 2016 [cited by applicant]
US 9280678B2 · Redberg · 2016 [cited by applicant]
US 9565202B1 · Kindlund et al. · 2017 [cited by applicant]
US 9692759B1 · Chandrasekhar · 2017 [cited by applicant]
US 9697349B2 · Li et al. · 2017 [cited by applicant]
US 9716724B1 · Chennuru et al. · 2017 [cited by applicant]
US 9811662B2 · Sharpe et al. · 2017 [cited by applicant]
US 9917817B1 · Lad · 2018 [cited by examiner]
US 10084825B1 · Xu · 2018 [cited by applicant]
US 10162767B2 · Spurlock et al. · 2018 [cited by applicant]
US 10237282B2 · Nelson et al. · 2019 [cited by applicant]
US 10248797B1 · Shinde et al. · 2019 [cited by applicant]
US 10334442B2 · Vaughn et al. · 2019 [cited by applicant]
US 10382468B2 · Dods · 2019 [cited by applicant]
US 10462165B1 · Salour · 2019 [cited by applicant]
US 10484334B1 · Lee et al. · 2019 [cited by applicant]
US 10757090B2 · Kahol et al. · 2020 [cited by applicant]
US 10826941B2 · Jain et al. · 2020 [cited by applicant]
US 10855671B2 · Kahol et al. · 2020 [cited by applicant]
US 10860730B1 · Weaver et al. · 2020 [cited by applicant]
US 11032301B2 · Mandrychenko et al. · 2021 [cited by applicant]
US 11036856B2 · Graun et al. · 2021 [cited by applicant]
US 11089064B1 · Sarukkai et al. · 2021 [cited by applicant]
US 11281775B2 · Burdett et al. · 2022 [cited by applicant]
US 20020099666A1 · Dryer et al. · 2002 [cited by applicant]
US 20030055994A1 · Herrmann et al. · 2003 [cited by applicant]
US 20030063321A1 · Inoue et al. · 2003 [cited by applicant]
US 20030135465A1 · Lee et al. · 2003 [cited by applicant]
US 20030172292A1 · Judge · 2003 [cited by applicant]
US 20030204632A1 · Willebeek-Lemair et al. · 2003 [cited by applicant]
US 20040015719A1 · Lee et al. · 2004 [cited by applicant]
US 20040205360A1 · Norton et al. · 2004 [cited by applicant]
US 20050010593A1 · Fellenstein et al. · 2005 [cited by applicant]
US 20050060535A1 · Bartas · 2005 [cited by applicant]
US 20050271246A1 · Sharma et al. · 2005 [cited by applicant]
US 20060004818A1 · Claudatos · 2006 [cited by examiner]
US 20060075481A1 · Ross et al. · 2006 [cited by applicant]
US 20060156401A1 · Newstadt et al. · 2006 [cited by applicant]
US 20070006293A1 · Balakrishnan et al. · 2007 [cited by applicant]
US 20070204018A1 · Chandra et al. · 2007 [cited by applicant]
US 20070237147A1 · Quinn et al. · 2007 [cited by applicant]
US 20080069480A1 · Aarabi et al. · 2008 [cited by applicant]
US 20080134332A1 · Keohane et al. · 2008 [cited by applicant]
US 20080189778A1 · Rowley · 2008 [cited by applicant]
US 20090022319A1 · Shahaf et al. · 2009 [cited by applicant]
US 20090044260A1 · Niglio et al. · 2009 [cited by applicant]
US 20090144818A1 · Kumar et al. · 2009 [cited by applicant]
US 20090232300A1 · Zucker et al. · 2009 [cited by applicant]
US 20090249470A1 · Litvin et al. · 2009 [cited by applicant]
US 20090296926A1 · Perlman · 2009 [cited by applicant]
US 20090300351A1 · Lei et al. · 2009 [cited by applicant]
US 20100017436A1 · Wolge · 2010 [cited by applicant]
US 20100175136A1 · Frumer et al. · 2010 [cited by applicant]
US 20100251369A1 · Grant · 2010 [cited by applicant]
US 20110119481A1 · Auradkar et al. · 2011 [cited by applicant]
US 20110145594A1 · Jho et al. · 2011 [cited by applicant]
US 20110264906A1 · Pourzandi et al. · 2011 [cited by applicant]
US 20110277027A1 · Hayton et al. · 2011 [cited by applicant]
US 20110321170A1 · Onodera et al. · 2011 [cited by applicant]
US 20120008786A1 · Cronk et al. · 2012 [cited by applicant]
US 20120023323A1 · Kent, Jr. et al. · 2012 [cited by applicant]
US 20120106366A1 · Gauvin · 2012 [cited by applicant]
US 20120144189A1 · Zhong · 2012 [cited by applicant]
US 20120151551A1 · Readshaw et al. · 2012 [cited by applicant]
US 20120204260A1 · Cecil et al. · 2012 [cited by applicant]
US 20120278872A1 · Woelfel et al. · 2012 [cited by applicant]
US 20120278896A1 · Fang et al. · 2012 [cited by applicant]
US 20130006865A1 · Spates · 2013 [cited by applicant]
US 20130024942A1 · Wiegenstein et al. · 2013 [cited by applicant]
US 20130055342A1 · Choi et al. · 2013 [cited by applicant]
US 20130145483A1 · DiMuro et al. · 2013 [cited by applicant]
US 20130159694A1 · Chiueh et al. · 2013 [cited by applicant]
US 20130298190A1 · Sikka et al. · 2013 [cited by applicant]
US 20130347085A1 · Hawthorn et al. · 2013 [cited by applicant]
US 20140007182A1 · Qureshi et al. · 2014 [cited by applicant]
US 20140013112A1 · Cidon et al. · 2014 [cited by applicant]
US 20140026182A1 · Pearl et al. · 2014 [cited by applicant]
US 20140068030A1 · Chambers et al. · 2014 [cited by applicant]
US 20140068705A1 · Chambers et al. · 2014 [cited by applicant]
US 20140259093A1 · Narayanaswamy et al. · 2014 [cited by applicant]
US 20140259190A1 · Kiang et al. · 2014 [cited by applicant]
US 20140269279A1 · Ismail et al. · 2014 [cited by applicant]
US 20140282843A1 · Buruganahalli et al. · 2014 [cited by applicant]
US 20140317681A1 · Shende · 2014 [cited by applicant]
US 20140337862A1 · Valencia et al. · 2014 [cited by applicant]
US 20140344573A1 · Tsai et al. · 2014 [cited by applicant]
US 20140359282A1 · Shikfa et al. · 2014 [cited by applicant]
US 20140366079A1 · Pasdar · 2014 [cited by applicant]
US 20140380491A1 · Abuelsaad et al. · 2014 [cited by applicant]
US 20150019870A1 · Patnala et al. · 2015 [cited by applicant]
US 20150074744A1 · McLean et al. · 2015 [cited by applicant]
US 20150100357A1 · Seese et al. · 2015 [cited by applicant]
US 20150135302A1 · Cohen et al. · 2015 [cited by applicant]
US 20150142986A1 · Reznik et al. · 2015 [cited by applicant]
US 20150200924A1 · Parla et al. · 2015 [cited by applicant]
US 20150271207A1 · Jaiswal et al. · 2015 [cited by applicant]
US 20150312227A1 · Follis et al. · 2015 [cited by applicant]
US 20150319156A1 · Guccione et al. · 2015 [cited by applicant]
US 20160044035A1 · Huang · 2016 [cited by applicant]
US 20160050227A1 · Desai · 2016 [cited by examiner]
US 20160087970A1 · Kahol et al. · 2016 [cited by applicant]
US 20160094483A1 · Johnston et al. · 2016 [cited by applicant]
US 20160275577A1 · Kolluri Venkata Sesha et al. · 2016 [cited by applicant]
US 20160323318A1 · Terrill et al. · 2016 [cited by applicant]
US 20160344758A1 · Cohen · 2016 [cited by examiner]
US 20160350145A1 · Botzer et al. · 2016 [cited by applicant]
US 20170064005A1 · Lee · 2017 [cited by applicant]
US 20170093917A1 · Chandra et al. · 2017 [cited by applicant]
US 20170250951A1 · Wang et al. · 2017 [cited by applicant]
US 20170353496A1 · Pai et al. · 2017 [cited by applicant]
US 20180324204A1 · McClory et al. · 2018 [cited by applicant]
US 20200050686A1 · Kamalapuram et al. · 2020 [cited by applicant]
US 20200372040A1 · Boehmann et al. · 2020 [cited by applicant]
US 20210367976A1 · Khurshid et al. · 2021 [cited by applicant]
CN 103430504A · 2013 [cited by examiner]
EP 1063833A2 · 2000 [cited by applicant]
EP 2378455A2 · 2011 [cited by applicant]
EP 2544117A1 · 2013 [cited by examiner]
JP 2011234178A · 2011 [cited by applicant]
WO 2005069823A2 · 2005 [cited by applicant]
WO 2014093613A1 · 2014 [cited by applicant]
WO 2014141045A1 · 2014 [cited by applicant]
WO 2015002875A1 · 2015 [cited by applicant]
Netskope, “Repave the Cloud-Data Breach Collision Course,” netSkope, Inc., 2014, 6 pgs. [cited by applicant]
Akana, “API Gateway: Key Security Features”, Mar. 10, 2015, 2 pages, XP055312562, Retrieved from the Internet: http://resource.akana.com/datasheets/api-gateway-security-features. [cited by applicant]
Akana, “API Security: A Guide to Securing Your Digital Channels”, Mar. 15, 2015, XP055312513, Sections 2 and 3, Retrieved from the Internet: <http://resource.akana.com/white-papers/api-security-a-guide-to-securing-your-… [cited by applicant]
Axway, Comprehensive API and SOA 1-25 Security, Mar. 18, 2015, XP055310645, 3 Pages, Retrieved from the Internet: http://www.axway.com/sites/default/files/brief_files/axway_solutionbrief_api_soa security_en.pdf>. [cited by applicant]
Berg et al, “Issue Sep./Oct. API Governance and Management by Longji Tang, Mark Little LXXXVI Security and Identity Management Applied to SOA—Part II a Look at Service-Driven Industry Models Contents”, Service Technolog… [cited by applicant]
EP 16763347.8—Response to Rule 71(3) EPC Communication (Notice of Allowance) dated Jun. 1, 2018, as filed Oct. 11, 2018, 20 pages. [cited by applicant]
EP 16763347.8—Rule 71(3) EPC Communication (Notice of Allowance) dated Jun. 1, 2018, 89 pages. [cited by applicant]
EP 18201903.4—Extended European Search Report dated Jan. 31, 2019, 13 pages. [cited by applicant]
Jill Gemmill et al., Cross-domain authorization for feder-ated virtual organizations using the myVocs collaboration environment, 21 Concurrency & Computation: Prac-tice and Experience 509 (2008). [cited by applicant]
JP 2018-160069—Notice of Allowance dated Jan. 8, 2019, 8 pages. [cited by applicant]
JP 2018-160069—Voluntary Amendments filed Oct. 3, 2018, 82 pages. [cited by applicant]
JP 2018-500266—First Office Action dated Mar. 20, 2018, 8 pages. [cited by applicant]
JP 2018-500266—Notice of Allowance dated Jul. 31, 2018, 9 pages. [cited by applicant]
JP 2018-500266—Request for Examination and PCT-PPH Request, along with amendments filed on Jan. 25, 2018, 22 pages. [cited by applicant]
JP 2018-500266—Response to First Office Action dated Mar. 20, 2018 filed Jul. 20, 2018 , 6 pages. [cited by applicant]
Netskope, “Data Loss Prevention and Monitoring in the Cloud”, Nov. 2014, 18 pages. [cited by applicant]
Netskope, “Netskope Active Cloud DLP”, 2015, 4 pages. [cited by applicant]
Netskope, “Netskope Cloud Confidence Index™”, netSkope, Inc., 2015, 4 pages, downloaded from http://go.netskope.com/rs/netskope/images/NS-Cloud-Confidence-Index-DS-00.pdf. [cited by applicant]
Netskope, “The 5 Steps to Cloud Confidence” comparison between Sep. 11, 2014 version 4 and Jan. 29, 2014 version 2, Aug. 15, 2017, 12 pages. [cited by applicant]
Netskope, “The 5 Steps to Cloud Confidence”, Version 1, Oct. 3, 2013, 8 pages. [cited by applicant]
Netskope, “The 5 Steps to Cloud Confidence”, Version 3, Jun. 17, 2014, 10 pages. [cited by applicant]
Netskope, “The 5 Steps to Cloud Confidence,” netSkope Inc., 2014, 11 pgs. [cited by applicant]
Netskope, “The 5 Steps to Cloud Confindence”, Jan. 1, 2014, XP055312652, 12 pages, Retrieved from the Internet: <URL:http://www.dgcompany.nl/downloads/The> 5 Steps to Cloud Confidence.pdf. [cited by applicant]
Office 365 Team, “Office 365—Our Latest Innovations in Security and Compliance,” Microsoft Inc., Oct. 28, 2014, 6 pages, Retrieved from the Internet: <http://blogs.office.com/2014/10/28/office-365-latest-innovations-sec… [cited by applicant]
PCT/US2016/014197—International Preliminary Report on Patentability dated Sep. 28, 2017, 15 pages. [cited by applicant]
PCT/US2016/014197—International Search Report and Written Opinion dated Mar. 24, 2017, 22 pages. [cited by applicant]
PTAB Case No. IPR2021-01045, Petition for Inter Partes Review of U.S. Pat. No. 10,757,090, [cited by applicant]
PTAB Case No. IPR2021-01046, Petition for Inter Partes Review of U.S. Pat. No. 10,757,090, [cited by applicant]
PTAB Case No. PGR2021-00091, Petition for Post-Grant Review of U.S. Pat. No. 10,855,671, [cited by applicant]
PTAB Case No. PGR2021-00092, Petition for Post-Grant Review of U.S. Pat. No. 10,855,671, [cited by applicant]
Screen capture of https://www.bitglass.com/blog/how-topatent-a-phishing-attack, dated Oct. 1, 2015. [cited by applicant]
Netskope, “The 5 Steps to Cloud Confidence”, Versoin 2, Jan. 29, 2014, 10 pages. [cited by applicant]
Dasis, Key Management Interoperability Protocols Use Cases Version 1.2, dated Mar. 18, 2013, 132 pages. [cited by applicant]
Kark et al, “Trends: Calculating the Cost of a Security Breach”, Forrester Research, Inc. Apr. 10, 2007, 7 pgs. [cited by applicant]
“Data Breach: The Cloud Multiplier Effect”, Ponemon Institute, Jun. 4, 2014, 27 pages. [cited by applicant]
Liu et al., Data Loss Prevention, IT Professional, vol. 12, Issue 2, IEEE, Mar. 29, 2010, pp. 10-13. [cited by applicant]
Pandire et al., Attack Detection in Cloud Virtual Environment and Prevention using Honeypot, International Conference on Inventive Research in Computing Applications (ICIRCA), IEEE, Jul. 11-12, 2018, pp. 515-520. [cited by applicant]
Cheng et al., “Cloud Security for Dummies, Netskope Special Edition,” John Wiley & Sons, Inc., dated 2015, 53 pages. [cited by applicant]
“The Netskope Active Platform Enabling Safe Migration to the Cloud”, Apr. 2015, DS-1-8, Netskope, Inc., 6 pages. [cited by applicant]
“The Netskope Advantage: Three “Must-Have” Requirements for Cloud Access Security Brokers”, Jul. 2015, WP-12-2, 4 pages. [cited by applicant]
“Netskope Introspection,” netSkope, Inc., 2015, 3 pgs. [cited by applicant]
“Cloud Data Loss Prevention Reference Architecture”, Netskope, Sep. 2015, WP-88-1, 2 pages. [cited by applicant]
“Netskope the 15 Critical CASB Use Cases”, Netskope Inc., EB-141-1, dated 2015, 19 pages. [cited by applicant]
U.S. Appl. No. 14/835,640, filed Aug. 25, 2015, U.S. Pat. No. 9,928,377, Mar. 27, 2018, Issued. [cited by applicant]
U.S. Appl. No. 15/936,269, filed Mar. 26, 2018, 2018-0218167, Aug. 2, 2018, Pending. [cited by applicant]
U.S. Appl. No. 16/411,039, filed May 13, 2019, US-2019-0327272-A1, Oct. 24, 2019, Allowed. [cited by applicant]
U.S. Appl. No. 16/257,027, filed Jan. 25, 2020, 2020-0242269, Jul. 30, 2020, Allowed. [cited by applicant]
U.S. Appl. No. 15/936,269, Final Office Action, dated Apr. 6, 2022, 21 pages. [cited by applicant]
U.S. Appl. No. 15/936,269, Final Office Action, dated Mar. 20, 2023, 17 pages. [cited by applicant]
U.S. Appl. No. 15/936,269, Non-Final Office Action, dated Sep. 8, 2021, 17 pages. [cited by applicant]
U.S. Appl. No. 15/936,269, Non-Final Office Action, dated Sep. 29, 2022, 22 pages. [cited by applicant]
Martin, Victoria “Cooperative Security Fabric, The Fortinet Cookbook, Jun. 8, 2016, 6 pgs., archived Jul. 28, 2016 at https://web.archive.org/web/20160728170025/http://cookbook.fortinet.com/cooperative-security-fabric-5… [cited by applicant]
Huckaby, Jeff “Ending Clear Text Protocols,” Rackaid.com, Dec. 9, 2008, 3 pgs. [cited by applicant]
Newton, Harry “fabric,” Newton's Telecom Dictionary, 30th Updated, Expanded, Anniversary Edition, 2016, 3 pgs. [cited by applicant]
Fortinet, “Fortinet Security Fabric Earns 100% Detection Scores Across Several Attack Vectors in NSS Labs' Latest Breach Detection Group Test [press release]”, Aug. 2, 2016, 4 pgs, available at https://www.fortinet.com/… [cited by applicant]
Fortinet, “Fortinet Security Fabric Named 2016 CRN Network Security Product of the Year [press release]”, Dec. 5, 2016, 4 pgs, available at https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2016/fortin… [cited by applicant]
McCullagh, Declan, “How safe is instant messaging? A security and privacy survey,” CNET, Jun. 9, 2008, 14 pgs. [cited by applicant]
Beck et al., “IBM and Cisco: Together for a World Class Data Center,” IBM Redbooks, Jul. 2013, 654 pgs. [cited by applicant]
Martin, Victoria “Installing internal FortiGates and enabling a security fabric, The Fortinet Cookbook, Jun. 8, 2016, 11 pgs, archived Aug. 28, 2016 at https://web.archive.org/web/20160828235831/http://cookbook.fortinet… [cited by applicant]
Zetter, Kim, “Revealed: The Internet's Biggest Security Hole,” Wired, Aug. 26, 2008, 13 pgs. [cited by applicant]
Adya et al., “Farsite: Federated, available, and reliable storage for an incompletely trusted environment,” SIGOPS Oper. Syst. Rev. 36, SI, Dec. 2002, pp. 1-14. [cited by applicant]
Agrawal et al., “Order preserving encryption for numeric data,” in Proceedings of the 2004 ACM SIGMOD international conference on Management of data, Jun. 2004, pp. 563-574. [cited by applicant]
Balakrishnan et al., “A layered naming architecture for the Internet,” ACM SIGCOMM Computer Communication Review, 34(4), 2004, pp. 343-352. [cited by applicant]
Downing et al., Naming Dictionary of Computer and Internet Terms, (11th Ed.) Barron's, 2013, 6 pgs. [cited by applicant]
Downing et al., Dictionary of Computer and Internet Terms, (10th Ed.) Barron's, 2009, 4 pgs. [cited by applicant]
Zoho Mail, “Email Protocols: What they are & their different types,” 2006, 7 pgs. available at https://www.zoho.com/mail/glossary/email-protocols.html#:˜:text=mode of communication.-,What are the different email protoco… [cited by applicant]
NIIT, Special Edition Using Storage Area Networks, Que, 2002, 6 pgs. [cited by applicant]
Chapple, Mike, “Firewall redundancy: Deployment scenarios and benefits,” TechTarget, 2005, 5 pgs. available at https://www.techtarget.com/searchsecurity/tip/Firewall-redundancy-Deployment-scenarios-and-benefits?Offer=ab… [cited by applicant]
Fortinet, FortiGate—3600 User Manual (vol. 1, Version 2.50 MR2) Sep. 5, 2003, 329 pgs. [cited by applicant]
Fortinet, FortiGate SOHO and SMB Configuration Example, (Version 3.0 MR5), Aug. 24, 2007, 54 pgs. [cited by applicant]
Fortinet, FortiSandbox—Administration Guide, (Version 2.3.2), Nov. 9, 2016, 191 pgs. [cited by applicant]
Fortinet, FortiSandbox Administration Guide, (Version 4.2.4) Jun. 12, 2023, 245 pgs. available at https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/fba32b46-b7c0-11ed-8e6d-fa163e15d75b/FortiSandbox-4… [cited by applicant]
Fortinet, FortiOS—Administration Guide, (Versions 6.4.0), Jun. 3, 2021, 1638 pgs. [cited by applicant]
Heady et al., “The Architecture of a Network Level Intrusion Detection System,” University of New Mexico, Aug. 15, 1990, 21 pgs. [cited by applicant]
Kephart et al., “Fighting Computer Viruses,” Scientific American (vol. 277, No. 5) Nov. 1997, pp. 88-93. [cited by applicant]
Wang, L., Chapter 5: Cooperative Security in D2D Communications, “Physical Layer Security in Wireless Cooperative Networks,” 41 pgs. first online on Sep. 1, 2017 at https://link.springer.com/chapter/10.1007/978-3-319-61… [cited by applicant]
Lee et al., “A Data Mining Framework for Building Intrusion Detection Models,” Columbia University, n.d. 13 pgs. [cited by applicant]
Merriam-Webster Dictionary, 2004, 5 pgs. [cited by applicant]
Microsoft Computer Dictionary, (5th Ed.), Microsoft Press, 2002, 8 pgs. [cited by applicant]
Microsoft Computer Dictionary, (4th Ed.), Microsoft Press, 1999, 5 pgs. [cited by applicant]
Mika et al., “Metadata Statistics for a Large Web Corpus,” LDOW2012, Apr. 16, 2012, 6 pgs. [cited by applicant]
Oxford Dictionary of Computing (6th Ed.), 2008, 5 pgs. [cited by applicant]
Paxson, Vern, “Bro: a System for Detecting Network Intruders in Real-Time,” Proceedings of the 7th USENIX Security Symposium, Jan. 1998, 22 pgs. [cited by applicant]
Fortinet Inc.,U.S. Appl. No. 62/503,252, “Building a Cooperative Security Fabric of Hierarchically Interconnected Network Security Devices.” n.d., 87 pgs. [cited by applicant]
Song et al., “Practical techniques for searches on encrypted data,” in Proceeding 2000 IEEE symposium on security and privacy. S&P 2000, May 2000, pp. 44-55. [cited by applicant]
Dean, Tamara, Guide to Telecommunications Technology, Course Technology, 2003, 5 pgs. [cited by applicant]
U.S. Appl. No. 60/520,577, “Device, System, and Method for Defending a Computer Network,” filed Nov. 17, 2003, 21 pgs. [cited by applicant]
U.S. Appl. No. 60/552,457, “Fortinet Security Update Technology,” filed Mar. 2004, 6 pgs. [cited by applicant]
Tittel, Ed, Unified Threat Management for Dummies, John Wiley & Sons, Inc., 2012, 76 pgs. [cited by applicant]
Fortinet, FortiOS Handbook: UTM Guide (Version 2), Oct. 15, 2010, 188 pgs. [cited by applicant]
Full Definition of Security, Wayback Machine Archive of Merriam-Webster on Nov. 17, 2016, 1 pg. [cited by applicant]
Definition of Cooperative, Wayback Machine Archive of Merriam-Webster on Nov. 26, 2016, 1 pg. [cited by applicant]
Pfaffenberger, Bryan, Webster's New World Computer Dictionary, (10th Ed.), 2003, 5 pgs. [cited by applicant]