Patents by Inventor Thomas E. Bernhard

Thomas E. Bernhard has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 6792546
    Abstract: A method of describing intrusion signatures, which are used by an intrusion detection system to detect attacks on a local network. The signatures are described using a “high level” syntax having features in common with regular expression and logical expression methodology. These high level signatures may then be compiled, or otherwise analyzed, to provide a process executable by a sensor or other processor-based signature detector.
    Type: Grant
    Filed: November 25, 2002
    Date of Patent: September 14, 2004
    Assignee: Cisco Technology, Inc.
    Inventors: Steven D. Shanklin, Thomas E. Bernhard, Gerald S. Lathem
  • Patent number: 6609205
    Abstract: A method of detecting signatures representing misuse of a local network. Known reference signatures having one or more common events are identified, and represented with a decision graph having one or more shared nodes. Each node of the decision graph represents the occurrence of an event. Given a set of input events, test functions associated with nodes determine the path taken during traversal of the graph. A path of the graph from the parent node to a leaf node represents the occurrence of all events that comprise a signature. The decision graph permits any of the signatures to be detected with only one traversal, and avoids the need for a separate matching process for each signature. In this manner, an entire set of all known reference signatures may be consolidated into a smaller set of decision graphs.
    Type: Grant
    Filed: March 18, 1999
    Date of Patent: August 19, 2003
    Assignee: Cisco Technology, Inc.
    Inventors: Thomas E. Bernhard, Steven D. Shanklin, Gerald S. Lathem
  • Patent number: 6487666
    Abstract: A method of describing intrusion signatures, which are used by an intrusion detection system to detect attacks on a local network. The signatures are described using a “high level” syntax having features in common with regular expression and logical expression methodology. These high level signatures may then be compiled, or otherwise analyzed, to provide a process executable by a sensor or other processor-based signature detector.
    Type: Grant
    Filed: January 15, 1999
    Date of Patent: November 26, 2002
    Assignee: Cisco Technology, Inc.
    Inventors: Steven D. Shanklin, Thomas E. Bernhard, Gerald S. Lathem