Patents by Inventor Siu-Wang Leung
Siu-Wang Leung has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Publication number: 20240150937Abstract: Provided herein are protective masks made with polymer-based materials and methods of forming the materials. Methods of forming the interlaced polymer-based materials comprise applying adhesive to a substrate, electrospinning a first polymer solution onto the substrate from a first group of spinning electrodes, electrospinning a second polymer solution onto the substrate from a second group of spinning electrodes, and applying hot air to dry the polymer-based materials electrospun from the first polymer solution and the second polymer solution to form the interlaced polymer-based materials.Type: ApplicationFiled: May 18, 2022Publication date: May 9, 2024Inventors: Siu Wah WONG, Ho Wang TONG, Chi Hang YU, Yu Hang LEUNG, Wing Man CHAN
-
Publication number: 20230388349Abstract: Embodiments of the present application relate to a method for policy enforcement, a system for policy enforcement, and a computer program product for policy enforcement. A method for policy enforcement is provided. The method includes receiving a host information profile report from a client device, and enforcing a security policy for network access based on the host information profile report. The host information profile report includes device profile information associated with the client device.Type: ApplicationFiled: March 2, 2023Publication date: November 30, 2023Inventors: Siu-Wang Leung, Song Wang, Yueh-Zen Chen
-
Patent number: 11632396Abstract: Embodiments of the present application relate to a method for policy enforcement, a system for policy enforcement, and a computer program product for policy enforcement. A method for policy enforcement is provided. The method includes receiving a host information profile report from a client device, and enforcing a security policy for network access based on the host information profile report. The host information profile report includes device profile information associated with the client device.Type: GrantFiled: August 10, 2018Date of Patent: April 18, 2023Assignee: Palo Alto Networks, Inc.Inventors: Siu-Wang Leung, Song Wang, Yueh-Zen Chen
-
Publication number: 20190266210Abstract: Enforcing a policy based at least in part on URL information is disclosed. A request to access a first uniform resource locator (URL) is received from a client device. A portion of the first URL, or a transformation thereof, is matched against a bloom filter. A first query is performed using the matched portion of the received first URL, and, in response to receiving a “no match” response to the first query, a second query that is different from the first query is performed. A policy is enforced based at least in part on a category received as a result of a second query.Type: ApplicationFiled: February 26, 2019Publication date: August 29, 2019Inventors: Yonghui Cheng, Siu-Wang Leung, Wilson Xu, Liang Li
-
Patent number: 10268656Abstract: Enforcing a policy based at least in part on URL information is disclosed. A uniform resource locator (URL) is received. A portion of the URL, or a transformation thereof, is matched against a bloom filter. Based on a result of the match, a first query is performed. A policy is enforced based at least in part on a category received as a result of a second query. In some cases, the first and second query are the same.Type: GrantFiled: May 19, 2011Date of Patent: April 23, 2019Assignee: Palo Alto Networks, Inc.Inventors: Yonghui Cheng, Siu-Wang Leung, Wilson Xu, Liang Li
-
Publication number: 20180352004Abstract: Embodiments of the present application relate to a method for policy enforcement, a system for policy enforcement, and a computer program product for policy enforcement. A method for policy enforcement is provided. The method includes receiving a host information profile report from a client device, and enforcing a security policy for network access based on the host information profile report. The host information profile report includes device profile information associated with the client device.Type: ApplicationFiled: August 10, 2018Publication date: December 6, 2018Inventors: Siu-Wang Leung, Song Wang, Yueh-Zen Chen
-
Patent number: 10075472Abstract: Embodiments of the present application relate to a method for policy enforcement, a system for policy enforcement, and a computer program product for policy enforcement. A method for policy enforcement is provided. The method includes receiving a host information profile report from a client device, and enforcing a security policy for network access based on the host information profile report. The host information profile report includes device profile information associated with the client device.Type: GrantFiled: January 20, 2015Date of Patent: September 11, 2018Assignee: Palo Alto Networks, Inc.Inventors: Siu-Wang Leung, Song Wang, Yueh-Zen Chen
-
Publication number: 20150200969Abstract: Embodiments of the present application relate to a method for policy enforcement, a system for policy enforcement, and a computer program product for policy enforcement. A method for policy enforcement is provided. The method includes receiving a host information profile report from a client device, and enforcing a security policy for network access based on the host information profile report. The host information profile report includes device profile information associated with the client device.Type: ApplicationFiled: January 20, 2015Publication date: July 16, 2015Inventors: Siu-Wang Leung, Song Wang, Yueh-Zen Chen
-
Patent number: 9001661Abstract: Methods and apparatuses are described for inspecting data packets in a computer network. One or more data packets through the network have associated header data and content. One method includes receiving a data packet, examining the data packet to classify the data packet including classifying the data packet using information included in the header and content, determining flow instructions for processing the packet based on both the header information and the content and processing of the packet using the flow instructions.Type: GrantFiled: September 4, 2013Date of Patent: April 7, 2015Assignee: Palo Alto Networks, Inc.Inventors: Nir Zuk, Song Wang, Siu-Wang Leung, Fengmin Gong
-
Patent number: 8973088Abstract: Embodiments of the present application relate to a method for policy enforcement, a system for policy enforcement, and a computer program product for policy enforcement. A method for policy enforcement is provided. The method includes receiving a host information profile report from a client device, and enforcing a security policy for network access based on the host information profile report. The host information profile report includes device profile information associated with the client device.Type: GrantFiled: May 24, 2011Date of Patent: March 3, 2015Assignee: Palo Alto Networks, Inc.Inventors: Siu-Wang Leung, Song Wang, Yueh-Zen Chen
-
Publication number: 20140075539Abstract: Methods and apparatuses are described for inspecting data packets in a computer network. One or more data packets through the network have associated header data and content. One method includes receiving a data packet, examining the data packet to classify the data packet including classifying the data packet using information included in the header and content, determining flow instructions for processing the packet based on both the header information and the content and processing of the packet using the flow instructions.Type: ApplicationFiled: September 4, 2013Publication date: March 13, 2014Applicant: Palo Alto Networks, Inc.Inventors: Nir Zuk, Song Wang, Siu-Wang Leung, Fengmin Gong
-
Patent number: 8565093Abstract: Methods and apparatuses are described for inspecting data packets in a computer network. One or more data packets through the network have associated header data and content. One method includes receiving a data packet, examining the data packet to classify the data packet including classifying the data packet using information included in the header and content, determining flow instructions for processing the packet based on both the header information and the content and processing of the packet using the flow instructions.Type: GrantFiled: July 28, 2011Date of Patent: October 22, 2013Assignee: Palo Alto Networks, Inc.Inventors: Nir Zuk, Song Wang, Siu-Wang Leung, Fengmin Gong
-
Patent number: 8209756Abstract: An intrusion detection and prevention (IDP) device includes an attack detection module and a forwarding component. The attack detection module applies a compound attack definition to a packet flow of a computer network to determine whether the packet flow includes at least one pattern and at least one protocol anomaly. The forwarding component selectively discards the packet flow based on the determination. The IDP device may further include a reassembly module to form application-layer communications from the packet flows, and a plurality of protocol-specific decoders to process the application-layer communications to extract application-layer elements and detect protocol anomalies.Type: GrantFiled: January 27, 2005Date of Patent: June 26, 2012Assignee: Juniper Networks, Inc.Inventors: Kowsik Guruswamy, Siu-Wang Leung
-
Publication number: 20120026881Abstract: Methods and apparatuses are described for inspecting data packets in a computer network. One or more data packets through the network have associated header data and content. One method includes receiving a data packet, examining the data packet to classify the data packet including classifying the data packet using information included in the header and content, determining flow instructions for processing the packet based on both the header information and the content and processing of the packet using the flow instructions.Type: ApplicationFiled: July 28, 2011Publication date: February 2, 2012Applicant: PALO ALTO NETWORKS, INC.Inventors: Nir Zuk, Song Wang, Siu-Wang Leung, Fengmin Gong
-
Patent number: 8009566Abstract: Methods and apparatuses are described for inspecting data packets in a computer network. One or more data packets through the network have associated header data and content. One method includes receiving a data packet, examining the data packet to classify the data packet including classifying the data packet using information included in the header and content, determining flow instructions for processing the packet based on both the header information and the content and processing of the packet using the flow instructions.Type: GrantFiled: June 26, 2006Date of Patent: August 30, 2011Assignee: Palo Alto Networks, Inc.Inventors: Nir Zuk, Song Wang, Siu-Wang Leung, Fengmin Gong
-
Patent number: 7769851Abstract: An intrusion detection and prevention (IDP) device includes a flow analysis module, an analysis engine, a plurality of protocol-specific decoders and a profiler. The flow analysis module processes packet flows in a network to identify network elements associated with the packet flows. The analysis engine forms application-layer communications from the packet flows. The plurality of protocol-specific decoders processes the application-layer communications to generate application-layer elements. The profiler correlates the application-layer elements of the application-layer communications with the network elements of the packet flows of the computer network.Type: GrantFiled: January 27, 2005Date of Patent: August 3, 2010Assignee: Juniper Networks, Inc.Inventors: Kowsik Guruswamy, Siu-Wang Leung
-
Publication number: 20070297333Abstract: Methods and apparatuses are described for inspecting data packets in a computer network. One or more data packets through the network have associated header data and content. One method includes receiving a data packet, examining the data packet to classify the data packet including classifying the data packet using information included in the header and content, determining flow instructions for processing the packet based on both the header information and the content and processing of the packet using the flow instructions.Type: ApplicationFiled: June 26, 2006Publication date: December 27, 2007Inventors: Nir Zuk, Song Wang, Siu-Wang Leung, Fengmin Gong