Patents by Inventor Kevin L. Wiley

Kevin L. Wiley has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 7555774
    Abstract: In accordance with one embodiment of the present invention, a method for inline intrusion detection includes receiving a packet at a physical interface of an intrusion detection system. The packet is tagged with a first VLAN identifier associated with an external network. The network further includes buffering the packet at the physical interface, communicating a copy of the packet to a processor, and analyzing the copy of the packet at the processor to determine whether the packet includes an attack signature. The method also includes communicating a reply message from the processor to the interface indicating whether the packet includes an attack signature. If the packet does not contain an attack signature the buffered copy of the packet is re-tagged with a second VLAN identifier associated with a protected network and re-tagged packet is communicated to the protected network.
    Type: Grant
    Filed: August 2, 2004
    Date of Patent: June 30, 2009
    Assignee: Cisco Technology, Inc.
    Inventors: Michael Lee Hall, Kevin L. Wiley, Munawar Hossain, Joseph M. Sirrianni
  • Patent number: 7526806
    Abstract: According to one embodiment of the invention, a computerized method for addressing intrusion attacks directed at a computer includes receiving a data stream corresponding to a potential attack on the computer and calculating an event risk rating for the data stream. Calculating the event risk rating includes determining at least one component risk rating. In one embodiment, the component risk ratings are: a signature fidelity rating indicative of the likelihood the potential attack will affect the computer in the absence of knowledge regarding the computer, an attack relevance rating indicative of the relevance of the potential attack to the computer, and a target value rating indicative of the perceived value of the computer. The method also includes responding to the potential attack based on the calculated risk rating.
    Type: Grant
    Filed: November 5, 2003
    Date of Patent: April 28, 2009
    Assignee: Cisco Technology, Inc.
    Inventors: Kevin L. Wiley, Michael L. Hall, Gerald S. Lathem, Robert E. Gleichauf
  • Patent number: 7320142
    Abstract: According to one embodiment of the invention, a method for use in intrusion detection includes storing a default signature file defining one or more default signatures and storing a customized signature file defining one or more custom signatures. The method also includes automatically generating, for each of the one or more signatures defined in the default signature file, executable code operable to detect intrusions associated with the default signatures. The method also includes automatically generating, for each of the custom signatures, executable code operable to detect intrusions associated with the custom signatures.
    Type: Grant
    Filed: November 9, 2001
    Date of Patent: January 15, 2008
    Assignee: Cisco Technology, Inc.
    Inventors: James W. Kasper, Paul A. Beriswill, Kevin L. Wiley
  • Patent number: 7243371
    Abstract: According to one embodiment of the invention, a method for automatically generating software code operable to detect a defined signature in network traffic comprises providing an inspector shell, generating a plurality of parameter name-value associations from provided configuration data, and automatically generating, by computer, an instance of the inspector shell having a signature defined by the parameter name-value associations.
    Type: Grant
    Filed: November 12, 2001
    Date of Patent: July 10, 2007
    Assignee: Cisco Technology, Inc.
    Inventors: James W. Kasper, Paul A. Beriswill, Kevin L. Wiley
  • Patent number: 7017185
    Abstract: A method and system for maintaining network activity data for intrusion detection includes storing data representative of network activity in datasets. The datasets include root datasets each having a root keyset and child datasets each having a child keyset with a key combination derived from and less granular than a root keyset. Child datasets are identified through their root datasets.
    Type: Grant
    Filed: December 21, 2000
    Date of Patent: March 21, 2006
    Assignee: Cisco Technology, Inc.
    Inventors: Kevin L. Wiley, Gerald S. Lathem, Michael L. Hall, Jr.
  • Patent number: 6816973
    Abstract: A method and system for adaptive network security using intelligent packet analysis are provided. The method comprises monitoring network data traffic. The network data traffic is analyzed to assess network information. A plurality of analysis tasks are prioritized based upon the network information. The analysis tasks are to be performed on the monitored network data traffic in order to identify attacks upon the network.
    Type: Grant
    Filed: November 13, 2002
    Date of Patent: November 9, 2004
    Assignee: Cisco Technology, Inc.
    Inventors: Robert E. Gleichauf, Daniel M. Teal, Kevin L. Wiley
  • Patent number: 6499107
    Abstract: A method and system for adaptive network security using intelligent packet analysis are provided. The method comprises monitoring network data traffic. The network data traffic is analyzed to assess network information. A plurality of analysis tasks are prioritized based upon the network information. The analysis tasks are to be performed on the monitored network data traffic in order to identify attacks upon the network.
    Type: Grant
    Filed: December 29, 1998
    Date of Patent: December 24, 2002
    Assignee: Cisco Technology, Inc.
    Inventors: Robert E. Gleichauf, Daniel M. Teal, Kevin L. Wiley