IP Library Granted Patent US 12,425,464
Granted Patent B2
US 12,425,464 · App. 18/396,581 · Granted Sep 23, 2025

Elastic service instance provisioning in a dynamic service chain

Inventors: Umesh Bangalore Muniyappa (Bangalore, IN); Ravi Ithal (Los Altos, CA)
Assignee: NETSKOPE, INC.
H04L65/613H04L9/3242H04L43/0876H04L45/7453H04L61/2503H04L65/80H04L67/1001H04L69/16H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,425,464
App. No.
18/396,581
Filed
Dec 26, 2023
Granted
Sep 23, 2025
Kind
B2
Art Unit
2439
USPC
713/170
Abstract

Disclosed is increasing available bandwidth for processing of packets by a security service in a dynamic service chain, monitoring available bandwidth of the security service, taking into account a number of instances of the security service currently running, detecting a traffic volume that has exceeded a configurable threshold, provisioning a new instance to increase the available bandwidth of the security service, putting the new instance into service including updating a constant hash table (CHT) used to implement distributed routing and load balancing and distributing the updated CHT to instances of an other service that is upstream in the dynamic service chain from the security service. The method can include assigning new streams to use the new instance.

Claims (39)

1. A computer-implemented method of increasing available bandwidth for processing of packets by a security service in a dynamic service chain of services running on one or more servers, including:

a controller monitoring available bandwidth of the security service, taking into account a number of instances of the security service currently running;

the controller detecting a traffic volume through a data center and being processed by the security service that has exceeded a configurable threshold and responsively signaling a workload orchestrator to provision a new instance of the security service, thereby increasing the available bandwidth of the security service;

upon successful provisioning of the new instance, the controller putting the new instance into service including updating a consistent hash table (CHT) used to implement distributed routing and load balancing over multiple instances of the security service in the dynamic service chain;

the controller distributing the updated CHT to instances of an other service that is upstream in the dynamic service chain from the security service; and

a first instance of the other service routing at least one new stream to be processed by the security service downstream of the other service, by using the updated CHT to assign an instance of the security service based on an affinity code of packets in the new stream, thereby selecting an affinity-based route that includes an instance of the security service for the new stream.

2. The computer-implemented method of claim 1 , wherein the dynamic service chain is a security service chain for a subscriber.

3. The computer-implemented method of claim 1 , wherein the affinity code for the new stream is included in an added header as an added IP header as IP source and destination.

4. The computer-implemented method of claim 1 , further including a packet in the new stream carrying a service chain for a subscriber in an added packet header and the security service being among services specified in the service chain.

5. The computer-implemented method of claim 1 , wherein instances of the security service in the dynamic service chain run in containers and the containers are hosted in pods.

6. The computer-implemented method of claim 1 , wherein instances of the security service in the dynamic service chain are implemented on virtual machines, bare metal servers or custom hardware.

7. The computer-implemented method of claim 1 , wherein failure of a particular service instance of the security service is detected by the controller, and performing actions further including:

monitoring the particular service instance for packet processing activity; and

causing updating of the CHT for the security service to remove the particular service instance from availability, should it be inactive for a configurable predetermined amount of time.

8. The computer-implemented method of claim 1 , further including actions of processing a plurality of packets in a stream through the dynamic service chain and directing the plurality of packets for processing, as a document, to a cloud access security broker (abbreviated CASB) in the dynamic service chain that controls exfiltration of sensitive content in documents stored on cloud-based services in use by users of an organization.

9. A tangible non-transitory computer readable storage media, including program instructions loaded into memory that, when executed on processors, cause the processors to implement a computer-implemented method of increasing available bandwidth for processing of packets by a security service in a dynamic service chain of services running on one or more servers, including:

a controller monitoring available bandwidth of the security service, taking into account a number of instances of the security service currently running;

the controller detecting a traffic volume through a data center and being processed by the security service that has exceeded a configurable threshold and responsively signaling a workload orchestrator to provision a new instance of the security service, thereby increasing the available bandwidth of the security service;

upon successful provisioning of the new instance, the controller putting the new instance into service including updating a consistent hash table (CHT) used to implement distributed routing and load balancing over multiple instances of the security service in the dynamic service chain;

the controller distributing the updated CHT to instances of an other service that is upstream in the dynamic service chain from the security service; and

a first instance of the other service routing at least one new stream to be processed by the security service downstream of the other service, by using the updated CHT to assign an instance of the security service based on an affinity code of packets in the new stream, thereby selecting an affinity-based route that includes an instance of the security service for the new stream.

10. The tangible non-transitory computer readable storage media of claim 9 , wherein the affinity code for the new stream is included in an added header as an added IP header as IP source and destination.

11. The tangible non-transitory computer readable storage media of claim 9 , further including a packet in the new stream carrying a service chain for a subscriber in an added packet header and the security service being among services specified in the dynamic service chain.

12. The tangible non-transitory computer readable storage media of claim 9 , wherein instances of the security service in the dynamic service chain run in containers and the containers are hosted in pods.

13. The tangible non-transitory computer readable storage media of claim 9 , wherein instances of the security service in the dynamic service chain are implemented on virtual machines, bare metal servers or custom hardware.

14. The tangible non-transitory computer readable storage media of claim 9 , further including actions of processing a plurality of packets in a stream through the dynamic service chain of services and directing the plurality of packets for processing, as a document, to a cloud access security broker (abbreviated CASB) that controls exfiltration of sensitive content in documents stored on cloud-based services in use by users of an organization, by monitoring manipulation of the documents.

15. A system including program instructions loaded into non-transitory memory that, when executed on processors, cause the processors to implement a computer-implemented method of increasing available bandwidth for processing of packets by a security service in a dynamic service chain of services running on one or more servers, including:

a controller monitoring available bandwidth of the security service, taking into account a number of instances of the security service currently running;

the controller detecting a traffic volume through a data center and being processed by the security service that has exceeded a configurable threshold and responsively signaling a workload orchestrator to provision a new instance of the security service, thereby increasing the available bandwidth of the security service;

upon successful provisioning of the new instance, the controller putting the new instance into service including updating a consistent hash table (CHT) used to implement distributed routing and load balancing over multiple instances of the security service in the dynamic service chain;

the controller distributing the updated CHT to instances of an other service that is upstream in the dynamic service chain from the security service; and

a first instance of the other service routing at least one new stream to be processed by the security service downstream of the other service, by using the updated CHT to assign an instance of the security service based on an affinity code of packets in the new stream, thereby selecting an affinity-based route that includes an instance of the security service for the new stream.

16. The system of claim 15 , wherein the affinity code for the new stream is included in an added header as an added IP header as IP source and destination.

17. The system of claim 15 , further including a packet in the new stream carrying a service chain for a subscriber in an added packet header and the security service being among services specified in the dynamic service chain.

18. The system of claim 15 , wherein instances of the security service in the dynamic service chain run in containers and the containers are hosted in pods.

19. The system of claim 15 , wherein failure of a particular service instance of the security service is detected by the controller, and performing actions further including:

monitoring the particular service instance for packet processing activity; and

causing updating of the CHT for the security service to remove the particular service instance from availability, should it be inactive for a configurable predetermined amount of time.

20. The system of claim 15 , further including actions of processing a plurality of packets in a stream through the dynamic service chain of services and directing the plurality of packets for processing, as a document, to a cloud access security broker (abbreviated CASB) that controls exfiltration of sensitive content in documents stored on cloud-based services in use by users of an organization, by monitoring manipulation of the documents.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2025
From: ITHAL, RAVI; MUNIYAPPA, UMESH BANGALORE
To: NETSKOPE, INC.
Reel/Frame 070265/0727 →
Continuity (5)
Continuation 17231366 · Apr 15, 2021
Continuation 16807128 · Mar 2, 2020
Provisional Application 62812791 · Mar 1, 2019
Provisional Application 62812760 · Mar 1, 2019
Related Publication 20240372908A1 · Nov 7, 2024
References Cited (163)
US 5440723A · Arnold et al. · 1995 [cited by applicant]
US 6513122B1 · Magdych et al. · 2003 [cited by applicant]
US 6622248B1 · Hirai · 2003 [cited by applicant]
US 7080408B1 · Pak et al. · 2006 [cited by applicant]
US 7298864B2 · Jones · 2007 [cited by applicant]
US 7376719B1 · Shafer et al. · 2008 [cited by applicant]
US 7735116B1 · Gauvin · 2010 [cited by applicant]
US 7966654B2 · Crawford · 2011 [cited by applicant]
US 8000329B2 · Fendick et al. · 2011 [cited by applicant]
US 8296178B2 · Hudis et al. · 2012 [cited by applicant]
US 8793151B2 · DelZoppo et al. · 2014 [cited by applicant]
US 8839417B1 · Jordan · 2014 [cited by applicant]
US 9197601B2 · Pasdar · 2015 [cited by applicant]
US 9225734B1 · Hastings · 2015 [cited by applicant]
US 9231968B2 · Fang et al. · 2016 [cited by applicant]
US 9280678B2 · Redberg · 2016 [cited by applicant]
US 9363180B2 · Beliveau · 2016 [cited by examiner]
US 9811662B2 · Sharpe et al. · 2017 [cited by applicant]
US 10084825B1 · Xu · 2018 [cited by applicant]
US 10237282B2 · Nelson et al. · 2019 [cited by applicant]
US 10243946B2 · Sridhar et al. · 2019 [cited by applicant]
US 10270711B2 · Chen et al. · 2019 [cited by applicant]
US 10282277B2 · Cao et al. · 2019 [cited by applicant]
US 10333846B2 · Singhal · 2019 [cited by examiner]
US 10334442B2 · Vaughn et al. · 2019 [cited by applicant]
US 10382468B2 · Dods · 2019 [cited by applicant]
US 10412008B2 · Tan et al. · 2019 [cited by applicant]
US 10452422B2 · Lou et al. · 2019 [cited by applicant]
US 10469391B2 · Sipra et al. · 2019 [cited by applicant]
US 10469525B2 · Hittel et al. · 2019 [cited by applicant]
US 10484334B1 · Lee et al. · 2019 [cited by applicant]
US 10567180B2 · Rumyankov et al. · 2020 [cited by applicant]
US 10616321B2 · Abhigyan · 2020 [cited by examiner]
US 10616339B2 · Nagalla et al. · 2020 [cited by applicant]
US 10623309B1 · Gampel · 2020 [cited by examiner]
US 10644995B2 · Levy et al. · 2020 [cited by applicant]
US 10812376B2 · Leitner · 2020 [cited by applicant]
US 10819621B2 · Levy et al. · 2020 [cited by applicant]
US 10826941B2 · Jain et al. · 2020 [cited by applicant]
US 10834113B2 · Balupari · 2020 [cited by applicant]
US 10862823B2 · Zhu et al. · 2020 [cited by applicant]
US 10868845B2 · Ithal et al. · 2020 [cited by applicant]
US 10965596B2 · Sharma et al. · 2021 [cited by applicant]
US 10965598B1 · Sharma · 2021 [cited by applicant]
US 10986039B2 · Sufleta et al. · 2021 [cited by applicant]
US 11005724B1 · Shpigelman et al. · 2021 [cited by applicant]
US 11018754B2 · Middlestead et al. · 2021 [cited by applicant]
US 11032301B2 · Mandrychenko et al. · 2021 [cited by applicant]
US 11036856B2 · Graun et al. · 2021 [cited by applicant]
US 11075840B1 · Qian et al. · 2021 [cited by applicant]
US 11082312B2 · Sharma · 2021 [cited by applicant]
US 11087179B2 · Yadav et al. · 2021 [cited by applicant]
US 11206405B2 · Gao et al. · 2021 [cited by applicant]
US 11212286B2 · Schmitt et al. · 2021 [cited by applicant]
US 11281775B2 · Burdett et al. · 2022 [cited by applicant]
US 20020099666A1 · Dryer et al. · 2002 [cited by applicant]
US 20030055994A1 · Herrmann et al. · 2003 [cited by applicant]
US 20030063321A1 · Inoue et al. · 2003 [cited by applicant]
US 20030172292A1 · Judge · 2003 [cited by applicant]
US 20030204632A1 · Willebeek-LeMair et al. · 2003 [cited by applicant]
US 20040015719A1 · Lee et al. · 2004 [cited by applicant]
US 20050010593A1 · Fellenstein et al. · 2005 [cited by applicant]
US 20050271246A1 · Sharma et al. · 2005 [cited by applicant]
US 20060156401A1 · Newstadt et al. · 2006 [cited by applicant]
US 20070204018A1 · Chandra et al. · 2007 [cited by applicant]
US 20070237147A1 · Quinn et al. · 2007 [cited by applicant]
US 20080069480A1 · Aarabi et al. · 2008 [cited by applicant]
US 20080134332A1 · Keohane et al. · 2008 [cited by applicant]
US 20090144818A1 · Kumar et al. · 2009 [cited by applicant]
US 20090249470A1 · Litvin et al. · 2009 [cited by applicant]
US 20090300351A1 · Lei et al. · 2009 [cited by applicant]
US 20100017436A1 · Wolge · 2010 [cited by applicant]
US 20100024008A1 · Hopen et al. · 2010 [cited by applicant]
US 20110016197A1 · Shiimori et al. · 2011 [cited by applicant]
US 20110119481A1 · Auradkar et al. · 2011 [cited by applicant]
US 20110145594A1 · Jho et al. · 2011 [cited by applicant]
US 20110196914A1 · Tribbett · 2011 [cited by applicant]
US 20120278896A1 · Fang et al. · 2012 [cited by applicant]
US 20130159694A1 · Chiueh et al. · 2013 [cited by applicant]
US 20130298190A1 · Sikka et al. · 2013 [cited by applicant]
US 20130347085A1 · Hawthorn et al. · 2013 [cited by applicant]
US 20140013112A1 · Cidon et al. · 2014 [cited by applicant]
US 20140068030A1 · Chambers et al. · 2014 [cited by applicant]
US 20140068705A1 · Chambers et al. · 2014 [cited by applicant]
US 20140259093A1 · Narayanaswamy et al. · 2014 [cited by applicant]
US 20140282843A1 · Buruganahalli et al. · 2014 [cited by applicant]
US 20140344401A1 · Varney · 2014 [cited by examiner]
US 20140359282A1 · Shikfa et al. · 2014 [cited by applicant]
US 20140366079A1 · Pasdar · 2014 [cited by applicant]
US 20150100357A1 · Seese et al. · 2015 [cited by applicant]
US 20150124815A1 · Beliveau et al. · 2015 [cited by applicant]
US 20160323318A1 · Terrill et al. · 2016 [cited by applicant]
US 20160344803A1 · Batz · 2016 [cited by examiner]
US 20160350145A1 · Botzer et al. · 2016 [cited by applicant]
US 20170013028A1 · Yang et al. · 2017 [cited by applicant]
US 20170064005A1 · Lee · 2017 [cited by applicant]
US 20170093917A1 · Chandra et al. · 2017 [cited by applicant]
US 20170250951A1 · Wang et al. · 2017 [cited by applicant]
US 20180091410A1 · Browne et al. · 2018 [cited by applicant]
US 20180115586A1 · Chou et al. · 2018 [cited by applicant]
US 20180295134A1 · Gupta · 2018 [cited by examiner]
US 20190199789A1 · Abhigyan et al. · 2019 [cited by applicant]
US 20190373305A1 · Yang et al. · 2019 [cited by applicant]
US 20200036717A1 · Akella et al. · 2020 [cited by applicant]
US 20200050686A1 · Kamalapuram et al. · 2020 [cited by applicant]
EP 1063833A2 · 2000 [cited by applicant]
Netskope, “Data Loss Prevention and Monitoring in the Cloud”, Nov. 2014, 18 pages, (NSKO 1006 2). [cited by applicant]
Repave the Cloud-Data Breach Collision Course, netSkope, Inc., 2014, 6 pgs. [cited by applicant]
“Netskope Introspection,” netSkope, Inc., 2015, 3 pgs. [cited by applicant]
Eisenbud et al., “Maglev: A Fast and Reliable Software Network Load Balancer”, Google Inc., UCLA SpaceX, [email protected], Feb. 2016, 13 pages. [cited by applicant]
Netskope Cloud Confidence Index, netSkope, Inc., 2015, 4 pgs. [cited by applicant]
Netskope, “The 5 Steps to Cloud Confidence,” netSkope Inc., 2014, 11 pgs. [cited by applicant]
Cheng et al., “Cloud Security for Dummies, Netskope Special Edition,” John Wiley & Sons, Inc., dated 2015, 53 pages. [cited by applicant]
“Cloud Data Loss Prevention Reference Architecture”, Netskope, Sep. 2015, WP-88-1, 2 pages. [cited by applicant]
“The Netskope Active Platform Enabling Safe Migration to the Cloud”, Apr. 2015, DS-1-8, Netskope, Inc., 6 pages. [cited by applicant]
“The Netskope Advantage: Three “Must-Have” Requirements for Cloud Access Security Brokers”, Jul. 2015, WP-12-2, 4 pages. [cited by applicant]
“Netskope the 15 Critical CASB Use Cases”, Netskope, Inc., EB-141-1, 19 pages. [cited by applicant]
Halpern, et al, RFC 7664, “Service Function Chaining (SFC) Architecture”, Internet Engineering Task Force (IETF), Cisco, ISSN: 2070-1721, Oct. 2015, 64 pages. [cited by applicant]
Quinn, et al—RFC 8300, “Network Service Header (NSH)”, Internet Engineering Task Force (IETF), ISSN: 2070-1721, Jan. 2018, 80 pages. [cited by applicant]
Netskope, Netskope Active Cloud DLP, dated 2015, 4 pages. [cited by applicant]
Pignataro et al., Service Function Chaining, Cisco, dated Apr. 2017, 42 pages. [cited by applicant]
Martin, Victoria “Cooperative Security Fabric,” The Fortinet Cookbook, Jun. 8, 2016, 6 pgs., archived Jul. 28, 2016 at https://web.archive.org/web/20160728170025/http://cookbook.fortinet.com/cooperative-security-fabric-… [cited by applicant]
Huckaby, Jeff “Ending Clear Text Protocols,” Rackaid.com, Dec. 9, 2008, 3 pgs. [cited by applicant]
Newton, Harry “fabric,” Newton's Telecom Dictionary, 30th Updated, Expanded, Anniversary Edition, 2016, 3 pgs. [cited by applicant]
Fortinet, “Fortinet Security Fabric Earns 100% Detection Scores Across Several Attack Vectors in NSS Labs' Latest Breach Detection Group Test [press release]”, Aug. 2, 2016, 4 pgs, available at https://www.fortinet.com/… [cited by applicant]
Fortinet, “Fortinet Security Fabric Named 2016 CRN Network Security Product of the Year [press release]”, Dec. 5, 2016, 4 pgs, available at https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2016/fortin… [cited by applicant]
McCullagh, Declan, “How safe is instant messaging? A security and privacy survey,” CNET, Jun. 9, 2008, 14 pgs. [cited by applicant]
Beck et al., “IBM and Cisco: Together for a World Class Data Center,” IBM Redbooks, Jul. 2013, 654 pgs. [cited by applicant]
Martin, Victoria “Installing internal FortiGates and enabling a security fabric,” The Fortinet Cookbook, Jun. 8, 2016, 11 pgs, archived Aug. 28, 2016 at https://web.archive.org/web/20160828235831/http://cookbook.fortine… [cited by applicant]
Zetter, Kim, “Revealed: The Internet's Biggest Security Hole,” Wired, Aug. 26, 2008, 13 pgs. [cited by applicant]
Adya et al., “Farsite: Federated, available, and reliable storage for an incompletely trusted environment,” SIGOPS Oper. Syst. Rev. 36, SI, Dec. 2002, pp. 1-14. [cited by applicant]
Agrawal et al., “Order preserving encryption for numeric data,” In Proceedings of the 2004 ACM SIGMOD international conference on Management of data, Jun. 2004, pp. 563-574. [cited by applicant]
Balakrishnan et al., “A layered naming architecture for the Internet,” ACM SIGCOMM Computer Communication Review, 34(4), 2004, pp. 343-352. [cited by applicant]
Downing et al., Naming Dictionary of Computer and Internet Terms, (11th Ed.) Barron's, 2013, 6 pgs. [cited by applicant]
Downing et al., Dictionary of Computer and Internet Terms, (10th Ed.) Barron's, 2009, 4 pgs. [cited by applicant]
Zoho Mail, “Email Protocols: What they are & their different types,” 2006, 7 pgs. available at https://www.zoho.com/mail/glossary/email-protocols.html#:˜:text=mode of communication.-,What are the different email protoco… [cited by applicant]
Niit, Special Edition Using Storage Area Networks, Que, 2002, 6 pgs. [cited by applicant]
Chapple, Mike, “Firewall redundancy: Deployment scenarios and benefits,” TechTarget, 2005, 5 pgs. available at https://www.techtarget.com/searchsecurity/tip/Firewall-redundancy-Deployment-scenarios-and-benefits?Offer=ab… [cited by applicant]
Fortinet, FortiGate—3600 User Manual (vol. 1, Version 2.50 MR2) Sep. 5, 2003, 329 pgs. [cited by applicant]
Fortinet, FortiGate SOHO and SMB Configuration Example, (Version 3.0 MR5), Aug. 24, 2007, 54 pgs. [cited by applicant]
Fortinet, FortiSandbox—Administration Guide, (Version 2.3.2), Nov. 9, 2016, 191 pgs. [cited by applicant]
Fortinet, FortiSandbox Administration Guide, (Version 4.2.4) Jun. 12, 2023, 245 pgs. available at https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/fba32b46-b7c0-11ed-8e6d-fa163e15d75b/FortiSandbox-4… [cited by applicant]
Fortinet, FortiOS—Administration Guide, (Versions 6.4.0), Jun. 3, 2021, 1638 pgs. [cited by applicant]
Heady et al., “The Architecture of a Network Level Intrusion Detection System,” University of New Mexico, Aug. 15, 1990, 21 pgs. [cited by applicant]
Kephart et al., “Fighting Computer Viruses,” Scientific American (vol. 277, No. 5) Nov. 1997, pp. 88-93. [cited by applicant]
Wang, L., Chapter 5: Cooperative Security in D2D Communications, “Physical Layer Security in Wireless Cooperative Networks,” 41 pgs. first online on Sep. 1, 2017 at https://link.springer.com/chapter/10.1007/978-3-319-61… [cited by applicant]
Lee et al., “A Data Mining Framework for Building Intrusion Detection Models,” Columbia University, n.d. 13 pgs. [cited by applicant]
Merriam-Webster Dictionary, 2004, 5 pgs. [cited by applicant]
Microsoft Computer Dictionary, (5th Ed.), Microsoft Press, 2002, 8 pgs. [cited by applicant]
Microsoft Computer Dictionary, (4th Ed.), Microsoft Press, 1999, 5 pgs. [cited by applicant]
Mika et al., “Metadata Statistics for a Large Web Corpus,” LDOW2012, Apr. 16, 2012, 6 pgs. [cited by applicant]
Oxford Dictionary of Computing (6th Ed.), 2008, 5 pgs. [cited by applicant]
Paxson, Vern, “Bro: a System for Detecting Network Intruders in Real-Time,” Proceedings of the 7th USENIX Security Symposium, Jan. 1998, 22 pgs. [cited by applicant]
Fortinet Inc., U.S. Appl. No. 62/503,252, “Building a Cooperative Security Fabric of Hierarchically Interconnected Network Security Devices.” n.d., 87 pgs. [cited by applicant]
Song et al., “Practical techniques for searches on encrypted data,” In Proceeding 2000 IEEE symposium on security and privacy. S&P 2000, May 2000, pp. 44-55. [cited by applicant]
Dean, Tamara, Guide to Telecommunications Technology, Course Technology, 2003, 5 pgs. [cited by applicant]
U.S. Appl. No. 60/520,577, “Device, System, and Method for Defending a Computer Network,” filed Nov. 17, 2003, 21 pgs. [cited by applicant]
U.S. Appl. No. 60/552,457, “Fortinet Security Update Technology,” filed Mar. 2004, 6 pgs. [cited by applicant]
Tittel, Ed, Unified Threat Management for Dummies, John Wiley & Sons, Inc., 2012, 76 pgs. [cited by applicant]
Fortinet, FortiOS Handbook: UTM Guide (Version 2), Oct. 15, 2010, 188 pgs. [cited by applicant]
Full Definition of Security, Wayback Machine Archive of Merriam-Webster on Nov. 17, 2016, 1 pg. [cited by applicant]
Definition of Cooperative, Wayback Machine Archive of Merriam-Webster on Nov. 26, 2016, 1 pg. [cited by applicant]
Pfaffenberger, Bryan, Webster's New World Computer Dictionary, (10th Ed.), 2003, 5 pgs. [cited by applicant]