IP Library Granted Patent US 12,401,626
Granted Patent B2
US 12,401,626 · App. 18/457,557 · Granted Aug 26, 2025

Multi-factor network segmentation

Inventors: Kaushal Bansal (Pleasanton, CA); Fiaz Hossain (San Francisco, CA); Prabhat Singh (San Jose, CA)
Assignee: Salesforce, Inc.
H04L63/0414H04L63/0236H04L63/0823H04L63/20H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,401,626
App. No.
18/457,557
Granted
Aug 26, 2025
Kind
B2
Abstract

Implementation(s) for multi-factor network segmentation are described. A plurality of packets at a higher layer of a network stack is processed, where at least one packet of the plurality of packets was previously determined, as part of processing the at least one packet at lower layers of the network stack, to be authorized to be processed by the higher layer. Specifically, responsive to successful authentication of a cryptographic certificate received during the handshake process, a second service is identified from the cryptographic certificate. It is determined, based on a security policy, that the second service is authorized to access the first service. Responsive to the determination, a configuration is caused such that packets sent using the source address are now authorized to be processed by the higher layer.

Claims (59)

1. A non-transitory machine-readable storage medium that provides instructions that, if executed by a set of one or more processors in one or more electronic devices, are configurable to cause the performance of operations, comprising:

processing a plurality of packets at a higher layer of a network stack,

wherein at least one packet of the plurality of packets was previously determined, as part of processing the at least one packet at lower layers of the network stack, to be authorized to be processed by the higher layer based on a determination that the at least one packet is associated with a handshake process to establish an encrypted connection, wherein the at least one packet is destined for a destination address associated with an instance of a first service, wherein the at least one packet was sent using a source address, wherein packets sent using the source address are otherwise configured to be unauthorized to be processed by the higher layer, and

wherein the processing at the higher layer includes:

responsive to successful authentication of a cryptographic certificate received during the handshake process, identifying from the cryptographic certificate a second service, wherein an instance of the second service is associated with the source address; and

determining, based on a security policy that defines the first and second service as being respectively within a first and second segment of a network, that the second service is authorized to access the first service; and

responsive to the determination, causing a configuration such that packets sent using the source address are now authorized to be processed by the higher layer.

2. The non-transitory machine-readable storage medium of claim 1 , wherein the lower layers and higher layer of the network stack are implemented on one electronic device within the first segment of the network.

3. The non-transitory machine-readable storage medium of claim 1 , wherein the lower layers of the network stack are implemented on a first electronic device within the first segment of the network, wherein a part of the higher layer of the network stack is implemented on a second electronic device within the first segment of the network, and wherein the configuration is implemented on the first electronic device.

4. The non-transitory machine-readable storage medium of claim 1 , the operations further comprising:

receiving a subsequent packet sent using the source address; and

responsive to the subsequent packet, authorizing, based on the configuration, the subsequent packet to be processed by the higher layer.

5. The non-transitory machine-readable storage medium of claim 1 , wherein the determination that the at least one packet being associated with a handshake process includes determining that the at least one packet is a first packet of the handshake process, and wherein the operations further comprising:

responsive to the determination that the at least one packet is the first packet of the handshake process, storing a data record for the network connection associated with the handshake process; and

responsive to receiving a first subsequent packet sent using the source address, determining that the stored data record exists and, in response, authorizing the first subsequent packet to move further in the lower layers of the network stack.

6. The non-transitory machine-readable storage medium of claim 5 , the operations further comprising:

responsive to determining that the handshake process fails, removing the stored data record; and

responsive to receiving a second subsequent packet sent using the source address, determining that there is no data record for an existing network connection associated with the handshake process and, in response, denying the second subsequent packet further movement in the lower layers of the network stack.

7. The non-transitory machine-readable storage medium of claim 1 , wherein the handshake process uses mutual authentication.

8. A method for network segmentation, implemented by one or more electronic devices, the method comprising:

processing a plurality of packets at a higher layer of a network stack,

wherein at least one packet of the plurality of packets was previously determined, as part of processing the at least one packet at lower layers of the network stack, to be authorized to be processed by the higher layer based on a determination that the at least one packet is associated with a handshake process to establish an encrypted connection, wherein the at least one packet is destined for a destination address associated with an instance of a first service, wherein the at least one packet was sent using a source address, wherein packets sent using the source address are otherwise configured to be unauthorized to be processed by the higher layer, and

wherein the processing at the higher layer includes:

responsive to successful authentication of a cryptographic certificate received during the handshake process, identifying from the cryptographic certificate a second service, wherein an instance of the second service is associated with the source address; and

determining, based on a security policy that defines the first and second service as being respectively within a first and second segment of a network, that the second service is authorized to access the first service; and

responsive to the determination, causing a configuration such that packets sent using the source address are now authorized to be processed by the higher layer.

9. The method of claim 8 , wherein the lower layers and higher layer of the network stack are implemented on one electronic device within the first segment of the network.

10. The method of claim 8 , wherein the lower layers of the network stack are implemented on a first electronic device within the first segment of the network, wherein a part of the higher layer of the network stack is implemented on a second electronic device within the first segment of the network, and wherein the configuration is implemented on the first electronic device.

11. The method of claim 8 , the method further comprising:

receiving a subsequent packet sent using the source address; and

responsive to the subsequent packet, authorizing, based on the configuration, the subsequent packet to be processed by the higher layer.

12. The method of claim 8 , wherein the determination that the at least one packet being associated with a handshake process includes determining that the at least one packet is a first packet of the handshake process, and wherein the method further comprising:

responsive to the determination that the at least one packet is the first packet of the handshake process, storing a data record for the network connection associated with the handshake process; and

responsive to receiving a first subsequent packet sent using the source address, determining that the stored data record exists and, in response, authorizing the first subsequent packet to move further in the lower layers of the network stack.

13. The method of claim 12 , the method further comprising:

responsive to determining that the handshake process fails, removing the stored data record; and

responsive to receiving a second subsequent packet sent using the source address, determining that there is no data record for an existing network connection associated with the handshake process and, in response, denying the second subsequent packet further movement in the lower layers of the network stack.

14. The method of claim 8 , wherein the handshake process uses mutual authentication.

15. A set of one or more electronic devices configured for network segmentation, the set of electronic devices comprising:

a set of one or more processors; and

a set of one or more non-transitory machine-readable storage mediums that provide instructions that, if executed by the set of processors, are configurable to cause the set of electronic devices to perform operations comprising:

processing a plurality of packets at a higher layer of a network stack,

wherein at least one packet of the plurality of packets was previously determined, as part of processing the at least one packet at lower layers of the network stack, to be authorized to be processed by the higher layer based on a determination that the at least one packet is associated with a handshake process to establish an encrypted connection, wherein the at least one packet is destined for a destination address associated with an instance of a first service, wherein the at least one packet was sent using a source address, wherein packets sent using the source address are otherwise configured to be unauthorized to be processed by the higher layer, and

wherein the processing at the higher layer includes:

responsive to successful authentication of a cryptographic certificate received during the handshake process, identifying from the cryptographic certificate a second service, wherein an instance of the second service is associated with the source address; and

determining, based on a security policy that defines the first and second service as being respectively within a first and second segment of a network, that the second service is authorized to access the first service; and

responsive to the determination, causing a configuration such that packets sent using the source address are now authorized to be processed by the higher layer.

16. The set of electronic devices of claim 15 , wherein the lower layers and higher layer of the network stack are implemented on one electronic device within the first segment of the network.

17. The set of electronic devices of claim 15 , wherein the lower layers of the network stack are implemented on a first electronic device within the first segment of the network, wherein a part of the higher layer of the network stack is implemented on a second electronic device within the first segment of the network, and wherein the configuration is implemented on the first electronic device.

18. The set of electronic devices of claim 15 , the operations further comprising:

receiving a subsequent packet sent using the source address; and

responsive to the subsequent packet, authorizing, based on the configuration, the subsequent packet to be processed by the higher layer.

19. The set of electronic devices of claim 15 , wherein the determination that the at least one packet being associated with a handshake process includes determining that the at least one packet is a first packet of the handshake process, and wherein the operations further comprising:

responsive to the determination that the at least one packet is the first packet of the handshake process, storing a data record for the network connection associated with the handshake process; and

responsive to receiving a first subsequent packet sent using the source address, determining that the stored data record exists and, in response, authorizing the first subsequent packet to move further in the lower layers of the network stack.

20. The set of electronic devices of claim 19 , the operations further comprising:

responsive to determining that the handshake process fails, removing the stored data record; and

responsive to receiving a second subsequent packet sent using the source address, determining that there is no data record for an existing network connection associated with the handshake process and, in response, denying the second subsequent packet further movement in the lower layers of the network stack.

21. The set of electronic devices of claim 15 , wherein the handshake process uses mutual authentication.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2023
From: BANSAL, KAUSHAL; HOSSAIN, FIAZ; SINGH, PRABHAT
To: SALESFORCE, INC.
Reel/Frame 064734/0879 →
Continuity (2)
Provisional Application 63516454 · Jul 28, 2023
Related Publication 20250039155A1 · Jan 30, 2025
References Cited (229)
US 5577188A · Zhu · 1996 [cited by applicant]
US 5608872A · Schwartz et al. · 1997 [cited by applicant]
US 5649104A · Carleton et al. · 1997 [cited by applicant]
US 5715450A · Ambrose et al. · 1998 [cited by applicant]
US 5761419A · Schwartz et al. · 1998 [cited by applicant]
US 5819038A · Carleton et al. · 1998 [cited by applicant]
US 5821937A · Tonelli et al. · 1998 [cited by applicant]
US 5831610A · Tonelli et al. · 1998 [cited by applicant]
US 5873096A · Lim et al. · 1999 [cited by applicant]
US 5918159A · Fomukong et al. · 1999 [cited by applicant]
US 5963953A · Cram et al. · 1999 [cited by applicant]
US 5983227A · Nazem et al. · 1999 [cited by applicant]
US 6092083A · Brodersen et al. · 2000 [cited by applicant]
US 6161149A · Achacoso et al. · 2000 [cited by applicant]
US 6169534B1 · Raffel et al. · 2001 [cited by applicant]
US 6178425B1 · Brodersen et al. · 2001 [cited by applicant]
US 6189011B1 · Lim et al. · 2001 [cited by applicant]
US 6216133B1 · Masthoff · 2001 [cited by applicant]
US 6216135B1 · Brodersen et al. · 2001 [cited by applicant]
US 6233617B1 · Rothwein et al. · 2001 [cited by applicant]
US 6236978B1 · Tuzhilin · 2001 [cited by applicant]
US 6266669B1 · Brodersen et al. · 2001 [cited by applicant]
US 6288717B1 · Dunkle · 2001 [cited by applicant]
US 6295530B1 · Ritchie et al. · 2001 [cited by applicant]
US 6324568B1 · Diec · 2001 [cited by applicant]
US 6324693B1 · Brodersen et al. · 2001 [cited by applicant]
US 6336137B1 · Lee et al. · 2002 [cited by applicant]
US D454139S · Feldcamp · 2002 [cited by applicant]
US 6367077B1 · Brodersen et al. · 2002 [cited by applicant]
US 6393605B1 · Loomans · 2002 [cited by applicant]
US 6405220B1 · Brodersen et al. · 2002 [cited by applicant]
US 6411949B1 · Schaffer · 2002 [cited by applicant]
US 6434550B1 · Warner et al. · 2002 [cited by applicant]
US 6446089B1 · Brodersen et al. · 2002 [cited by applicant]
US 6535909B1 · Rust · 2003 [cited by applicant]
US 6549908B1 · Loomans · 2003 [cited by applicant]
US 6553563B2 · Ambrose et al. · 2003 [cited by applicant]
US 6560461B1 · Fomukong et al. · 2003 [cited by applicant]
US 6574635B2 · Stauber et al. · 2003 [cited by applicant]
US 6577726B1 · Huang et al. · 2003 [cited by applicant]
US 6601087B1 · Zhu et al. · 2003 [cited by applicant]
US 6604117B2 · Lim et al. · 2003 [cited by applicant]
US 6604128B2 · Diec · 2003 [cited by applicant]
US 6609150B2 · Lee et al. · 2003 [cited by applicant]
US 6621834B1 · Scherpbier et al. · 2003 [cited by applicant]
US 6654032B1 · Zhu et al. · 2003 [cited by applicant]
US 6665648B2 · Brodersen et al. · 2003 [cited by applicant]
US 6665655B1 · Warner et al. · 2003 [cited by applicant]
US 6684438B2 · Brodersen et al. · 2004 [cited by applicant]
US 6711565B1 · Subramaniam et al. · 2004 [cited by applicant]
US 6724399B1 · Katchour et al. · 2004 [cited by applicant]
US 6728702B1 · Subramaniam et al. · 2004 [cited by applicant]
US 6728960B1 · Loomans · 2004 [cited by applicant]
US 6732095B1 · Warshavsky et al. · 2004 [cited by applicant]
US 6732100B1 · Brodersen et al. · 2004 [cited by applicant]
US 6732111B2 · Brodersen et al. · 2004 [cited by applicant]
US 6754681B2 · Brodersen et al. · 2004 [cited by applicant]
US 6763351B1 · Subramaniam et al. · 2004 [cited by applicant]
US 6763501B1 · Zhu et al. · 2004 [cited by applicant]
US 6768904B2 · Kim · 2004 [cited by applicant]
US 6772229B1 · Achacoso et al. · 2004 [cited by applicant]
US 6782383B2 · Subramaniam et al. · 2004 [cited by applicant]
US 6804330B1 · Jones et al. · 2004 [cited by applicant]
US 6826565B2 · Ritchie et al. · 2004 [cited by applicant]
US 6826582B1 · Chatterjee et al. · 2004 [cited by applicant]
US 6826745B2 · Coker et al. · 2004 [cited by applicant]
US 6829655B1 · Huang et al. · 2004 [cited by applicant]
US 6842748B1 · Warner et al. · 2005 [cited by applicant]
US 6850895B2 · Brodersen et al. · 2005 [cited by applicant]
US 6850949B2 · Warner et al. · 2005 [cited by applicant]
US 6907566B1 · McElfresh et al. · 2005 [cited by applicant]
US 7062502B1 · Kesler · 2006 [cited by applicant]
US 7069231B1 · Cinarkaya et al. · 2006 [cited by applicant]
US 7069497B1 · Desai · 2006 [cited by applicant]
US 7100111B2 · McElfresh et al. · 2006 [cited by applicant]
US 7181758B1 · Chan · 2007 [cited by applicant]
US 7269590B2 · Hull et al. · 2007 [cited by applicant]
US 7289976B2 · Kihneman et al. · 2007 [cited by applicant]
US 7340411B2 · Cook · 2008 [cited by applicant]
US 7356482B2 · Frankland et al. · 2008 [cited by applicant]
US 7373599B2 · McElfresh et al. · 2008 [cited by applicant]
US 7401094B1 · Kesler · 2008 [cited by applicant]
US 7406501B2 · Szeto et al. · 2008 [cited by applicant]
US 7412455B2 · Dillon · 2008 [cited by applicant]
US 7454509B2 · Boulter et al. · 2008 [cited by applicant]
US 7508789B2 · Chan · 2009 [cited by applicant]
US 7599935B2 · La et al. · 2009 [cited by applicant]
US 7603331B2 · Tuzhilin et al. · 2009 [cited by applicant]
US 7603483B2 · Psounis et al. · 2009 [cited by applicant]
US 7620655B2 · Larsson et al. · 2009 [cited by applicant]
US 7644122B2 · Weyer et al. · 2010 [cited by applicant]
US 7668861B2 · Stephan · 2010 [cited by applicant]
US 7698160B2 · Beaven et al. · 2010 [cited by applicant]
US 7730478B2 · Weissman · 2010 [cited by applicant]
US 7747648B1 · Kraft et al. · 2010 [cited by applicant]
US 7779039B2 · Weissman et al. · 2010 [cited by applicant]
US 7779475B2 · Jakobson et al. · 2010 [cited by applicant]
US 7827208B2 · Bosworth et al. · 2010 [cited by applicant]
US 7853881B1 · Aly et al. · 2010 [cited by applicant]
US 7945653B2 · Zuckerberg et al. · 2011 [cited by applicant]
US 8005896B2 · Cheah · 2011 [cited by applicant]
US 8014943B2 · Jakobson · 2011 [cited by applicant]
US 8015495B2 · Achacoso et al. · 2011 [cited by applicant]
US 8032297B2 · Jakobson · 2011 [cited by applicant]
US 8073850B1 · Hubbard et al. · 2011 [cited by applicant]
US 8082301B2 · Ahlgren et al. · 2011 [cited by applicant]
US 8095413B1 · Beaven · 2012 [cited by applicant]
US 8095531B2 · Weissman et al. · 2012 [cited by applicant]
US 8095594B2 · Beaven et al. · 2012 [cited by applicant]
US 8103611B2 · Tuzhilin et al. · 2012 [cited by applicant]
US 8150913B2 · Cheah · 2012 [cited by applicant]
US 8209308B2 · Rueben et al. · 2012 [cited by applicant]
US 8209333B2 · Hubbard et al. · 2012 [cited by applicant]
US 8275836B2 · Beaven et al. · 2012 [cited by applicant]
US 8457545B2 · Chan · 2013 [cited by applicant]
US 8484111B2 · Frankland et al. · 2013 [cited by applicant]
US 8490025B2 · Jakobson et al. · 2013 [cited by applicant]
US 8504945B2 · Jakobson et al. · 2013 [cited by applicant]
US 8510045B2 · Rueben et al. · 2013 [cited by applicant]
US 8510664B2 · Rueben et al. · 2013 [cited by applicant]
US 8554793B2 · Unger et al. · 2013 [cited by applicant]
US 8566301B2 · Rueben et al. · 2013 [cited by applicant]
US 8583964B2 · Chen et al. · 2013 [cited by applicant]
US 8646103B2 · Jakobson et al. · 2014 [cited by applicant]
US 8707264B2 · Hossain et al. · 2014 [cited by applicant]
US 8726240B2 · Gallagher et al. · 2014 [cited by applicant]
US 8752017B2 · Hossain et al. · 2014 [cited by applicant]
US 8839209B2 · Gallagher et al. · 2014 [cited by applicant]
US 8893093B2 · Hossain et al. · 2014 [cited by applicant]
US 8930327B2 · Hossain et al. · 2015 [cited by applicant]
US 9405896B2 · Simone · 2016 [cited by examiner]
US 10810233B2 · Bansal et al. · 2020 [cited by applicant]
US 10838962B2 · Bansal et al. · 2020 [cited by applicant]
US 11392419B2 · Sridharan et al. · 2022 [cited by applicant]
US 11552802B2 · Bansal et al. · 2023 [cited by applicant]
US 11651291B2 · Karanth et al. · 2023 [cited by applicant]
US 20010044791A1 · Richter et al. · 2001 [cited by applicant]
US 20020072951A1 · Lee et al. · 2002 [cited by applicant]
US 20020082892A1 · Raffel et al. · 2002 [cited by applicant]
US 20020129352A1 · Brodersen et al. · 2002 [cited by applicant]
US 20020140731A1 · Subramaniam et al. · 2002 [cited by applicant]
US 20020143997A1 · Huang et al. · 2002 [cited by applicant]
US 20020162090A1 · Parnell et al. · 2002 [cited by applicant]
US 20020165742A1 · Robins · 2002 [cited by applicant]
US 20030004971A1 · Gong et al. · 2003 [cited by applicant]
US 20030018705A1 · Chen et al. · 2003 [cited by applicant]
US 20030018830A1 · Chen et al. · 2003 [cited by applicant]
US 20030066031A1 · Laane · 2003 [cited by applicant]
US 20030066032A1 · Ramachandran et al. · 2003 [cited by applicant]
US 20030069936A1 · Warner et al. · 2003 [cited by applicant]
US 20030070000A1 · Coker et al. · 2003 [cited by applicant]
US 20030070004A1 · Mukundan et al. · 2003 [cited by applicant]
US 20030070005A1 · Mukundan et al. · 2003 [cited by applicant]
US 20030074418A1 · Coker · 2003 [cited by applicant]
US 20030120675A1 · Stauber et al. · 2003 [cited by applicant]
US 20030151633A1 · George et al. · 2003 [cited by applicant]
US 20030159136A1 · Huang et al. · 2003 [cited by applicant]
US 20030187921A1 · Diec · 2003 [cited by applicant]
US 20030189600A1 · Gune et al. · 2003 [cited by applicant]
US 20030204427A1 · Gune et al. · 2003 [cited by applicant]
US 20030206192A1 · Chen et al. · 2003 [cited by applicant]
US 20030225730A1 · Warner et al. · 2003 [cited by applicant]
US 20040001092A1 · Rothwein et al. · 2004 [cited by applicant]
US 20040010489A1 · Rio · 2004 [cited by applicant]
US 20040015981A1 · Coker et al. · 2004 [cited by applicant]
US 20040027388A1 · Berg et al. · 2004 [cited by applicant]
US 20040128001A1 · Levin et al. · 2004 [cited by applicant]
US 20040186860A1 · Lee et al. · 2004 [cited by applicant]
US 20040193510A1 · Catahan et al. · 2004 [cited by applicant]
US 20040199489A1 · Barnes-Leon et al. · 2004 [cited by applicant]
US 20040199536A1 · Barnes et al. · 2004 [cited by applicant]
US 20040199543A1 · Braud et al. · 2004 [cited by applicant]
US 20040249854A1 · Barnes-Leon et al. · 2004 [cited by applicant]
US 20040260534A1 · Pak et al. · 2004 [cited by applicant]
US 20040260659A1 · Chan et al. · 2004 [cited by applicant]
US 20040268299A1 · Lei et al. · 2004 [cited by applicant]
US 20050050555A1 · Exley et al. · 2005 [cited by applicant]
US 20050091098A1 · Brodersen et al. · 2005 [cited by applicant]
US 20080249972A1 · Dillon · 2008 [cited by applicant]
US 20090063415A1 · Chatfield et al. · 2009 [cited by applicant]
US 20090100342A1 · Jakobson · 2009 [cited by applicant]
US 20090177744A1 · Marlow et al. · 2009 [cited by applicant]
US 20110218958A1 · Warshavsky et al. · 2011 [cited by applicant]
US 20110247051A1 · Bulumulla et al. · 2011 [cited by applicant]
US 20120042218A1 · Cinarkaya et al. · 2012 [cited by applicant]
US 20120233137A1 · Jakobson et al. · 2012 [cited by applicant]
US 20120290407A1 · Hubbard et al. · 2012 [cited by applicant]
US 20130212497A1 · Zelenko et al. · 2013 [cited by applicant]
US 20130218948A1 · Jakobson · 2013 [cited by applicant]
US 20130218949A1 · Jakobson · 2013 [cited by applicant]
US 20130218966A1 · Jakobson · 2013 [cited by applicant]
US 20130247216A1 · Cinarkaya et al. · 2013 [cited by applicant]
US 20140359537A1 · Jackobson et al. · 2014 [cited by applicant]
US 20150006289A1 · Jakobson et al. · 2015 [cited by applicant]
US 20150007050A1 · Jakobson et al. · 2015 [cited by applicant]
US 20150095162A1 · Jakobson et al. · 2015 [cited by applicant]
US 20150142596A1 · Jakobson et al. · 2015 [cited by applicant]
US 20150172563A1 · Jakobson et al. · 2015 [cited by applicant]
US 20180241775A1 · Vera-Schockner · 2018 [cited by examiner]
US 20190312909A1 · Kulkarni et al. · 2019 [cited by applicant]
US 20200059420A1 · Abraham · 2020 [cited by examiner]
US 20200097481A1 · Cosentino et al. · 2020 [cited by applicant]
US 20210234890A1 · Bansal et al. · 2021 [cited by applicant]
US 20210241047A1 · Karanth et al. · 2021 [cited by applicant]
US 20210263663A1 · Bansal et al. · 2021 [cited by applicant]
US 20220086189A1 · Nguyen et al. · 2022 [cited by applicant]
US 20220086190A1 · Nguyen · 2022 [cited by applicant]
US 20220086193A1 · Nguyen et al. · 2022 [cited by applicant]
US 20220329584A1 · Sharma · 2022 [cited by examiner]
US 20230039162A1 · Salter et al. · 2023 [cited by applicant]
US 20230244594A1 · Bansal et al. · 2023 [cited by applicant]
US 20230259831A1 · Karanth et al. · 2023 [cited by applicant]
CN 104506487B · 2017 [cited by applicant]
EP 3611619A1 · 2020 [cited by applicant]
WO 2017138944A1 · 2017 [cited by applicant]
WO 2022060609A1 · 2022 [cited by applicant]
“All Data Breaches in 2019 & 2020—An Alarming Timeline” SelfKey Blog, Jul. 5, 2020. [cited by applicant]
“BPF maps”, the kernel development community, available online at <http://web.archive.org/web/20230604211709/https://docs.kernel.org/bpf/maps.html>, Jun. 4, 2023, 2 pages. [cited by applicant]
“Google Plus Users”, Google+Ripples, Oct. 31, 2011 [retrieved on Feb. 21, 2012 from Internet at http://www.googleplusers.com/google-ripples.html], 3 pages. [cited by applicant]
“Rightscale 2019 State of the Cloud Report” Flexera, 2019. [cited by applicant]
Bertrone, et al., “Toward an eBPF-based clone of Iptables”, Jul. 2018, pp. 1-5. [cited by applicant]
Di Pietro, G., “How to observe your network with eBPF”, available online at <https://isitobservable.io/observability/kubernetes/how-to-observe-your-network-with-ebpf>, Oct. 14, 2022, pp. 1-7. [cited by applicant]
Final Office Action, U.S. Appl. No. 16/948,399, Jul. 6, 2023, 10 pages. [cited by applicant]
International Preliminary Report on Patentability, PCT App. No. PCT/US21/49484, Mar. 30, 2023, 8 pages. [cited by applicant]
International Search Report and Written Opinion dated Dec. 3, 2021, in Application No. PCT/US2021/049484 [SLFCP322WO], 13 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/948,399, Jan. 23, 2023, 12 pages. [cited by applicant]
Shahin, Mojtaba, Muhammad Ali Babar, and Liming Zhu. “Continuous integration, delivery and deployment: a systematic review on approaches, tools, challenges and practices.” IEEE Access 5 (2017): 3909-3943. [cited by applicant]
Spinnaker: Cloud Native Continuous Delivery: Fast, safe, repeatable deployments for every Enterprise, Webpage, Accessed: Jan. 20, 2021. [cited by applicant]
Wikipedia, “Netfilter”, available online at <https://en.wikipedia.org/wiki/Netfilter>, last edited Apr. 21, 2023, 8 pages. [cited by applicant]