Patents by Inventor Steven D. Shanklin

Steven D. Shanklin has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 8239942
    Abstract: Various embodiments of a method and system for detecting unauthorized signatures to or from a local network. Multiple sensors are connected at an internetworking device, which can be a router or a switch. The sensors operate in parallel and each receives a portion of traffic through the internetworking device, at a session-based level or at a lower (packet-based) level. Depending on the type of internetworking device (router or switch) the load balancing mechanism that distributes the packets can be internal or external to the internetworking device. Also depending on the level of packet distribution (session-based or packet-based), the sensors share a network analyzer (if session-based) or both a network analyzer and a session analyzer (if packet-based).
    Type: Grant
    Filed: May 16, 2005
    Date of Patent: August 7, 2012
    Assignee: Cisco Technology, Inc.
    Inventors: Steven D. Shanklin, Gerald S. Lathem
  • Patent number: 6954775
    Abstract: Various embodiments of a method and system for detecting unauthorized signatures to or from a local network. Multiple sensors are connected at an internetworking device, which can be a router or a switch. The sensors operate in parallel and each receives a portion of traffic through the internetworking device, at a session-based level or at a lower (packet-based) level. Depending on the type of internetworking device (router or switch) the load balancing mechanism that distributes the packets can be internal or external to the internetworking device. Also depending on the level of packet distribution (session-based or packet-based), the sensors share a network analyzer (if session-based) or both a network analyzer and a session analyzer (if packet-based).
    Type: Grant
    Filed: December 30, 2002
    Date of Patent: October 11, 2005
    Assignee: Cisco Technology, Inc.
    Inventors: Steven D. Shanklin, Gerald S. Lathem
  • Patent number: 6792546
    Abstract: A method of describing intrusion signatures, which are used by an intrusion detection system to detect attacks on a local network. The signatures are described using a “high level” syntax having features in common with regular expression and logical expression methodology. These high level signatures may then be compiled, or otherwise analyzed, to provide a process executable by a sensor or other processor-based signature detector.
    Type: Grant
    Filed: November 25, 2002
    Date of Patent: September 14, 2004
    Assignee: Cisco Technology, Inc.
    Inventors: Steven D. Shanklin, Thomas E. Bernhard, Gerald S. Lathem
  • Publication number: 20030196123
    Abstract: According to one embodiment of the invention, a method for analyzing and addressing alarms from network intrusion detection systems includes receiving an alarm indicating an attack on a target host may have occurred, automatically accessing the target host in response to the alarm, and identifying the presence of the attack on the target host.
    Type: Application
    Filed: May 14, 2003
    Publication date: October 16, 2003
    Inventors: Craig H. Rowland, Nathan M. Cohen, Steven D. Shanklin, Steve R. Snapp, Stephen B. Campos, Stephen A. Burke
  • Patent number: 6609205
    Abstract: A method of detecting signatures representing misuse of a local network. Known reference signatures having one or more common events are identified, and represented with a decision graph having one or more shared nodes. Each node of the decision graph represents the occurrence of an event. Given a set of input events, test functions associated with nodes determine the path taken during traversal of the graph. A path of the graph from the parent node to a leaf node represents the occurrence of all events that comprise a signature. The decision graph permits any of the signatures to be detected with only one traversal, and avoids the need for a separate matching process for each signature. In this manner, an entire set of all known reference signatures may be consolidated into a smaller set of decision graphs.
    Type: Grant
    Filed: March 18, 1999
    Date of Patent: August 19, 2003
    Assignee: Cisco Technology, Inc.
    Inventors: Thomas E. Bernhard, Steven D. Shanklin, Gerald S. Lathem
  • Patent number: 6578147
    Abstract: Various embodiments of a method and system for detecting unauthorized signatures to or from a local network. Multiple sensors are connected at an internetworking device, which can be a router or a switch. The sensors operate in parallel and each receives a portion of traffic through the internetworking device, at a session-based level or at a lower (packet-based) level. Depending on the type of internetworking device (router or switch) the load balancing mechanism that distributes the packets can be internal or external to the internetworking device. Also depending on the level of packet distribution (session-based or packet-based), the sensors share a network analyzer (if session-based) or both a network analyzer and a session analyzer (if packet-based).
    Type: Grant
    Filed: January 15, 1999
    Date of Patent: June 10, 2003
    Assignee: Cisco Technology, Inc.
    Inventors: Steven D. Shanklin, Gerald S. Lathem
  • Patent number: 6487666
    Abstract: A method of describing intrusion signatures, which are used by an intrusion detection system to detect attacks on a local network. The signatures are described using a “high level” syntax having features in common with regular expression and logical expression methodology. These high level signatures may then be compiled, or otherwise analyzed, to provide a process executable by a sensor or other processor-based signature detector.
    Type: Grant
    Filed: January 15, 1999
    Date of Patent: November 26, 2002
    Assignee: Cisco Technology, Inc.
    Inventors: Steven D. Shanklin, Thomas E. Bernhard, Gerald S. Lathem