Invention Grant
- Patent Title: Detecting evasive network behaviors using machine learning
-
Application No.: US16288628Application Date: 2019-02-28
-
Publication No.: US11310205B2Publication Date: 2022-04-19
- Inventor: Constantinos Kleopa , Michael Joseph Stepanek , Silviu Dorin Minut , Carter Ryan Waxman
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Behmke Innovation Group
- Agent Kenneth J. Heywood; James J. Wong
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L12/851 ; G06N20/00 ; H04L12/24 ; H04L12/859 ; H04L47/2441 ; H04L47/2483 ; H04L41/16 ; H04L47/2475

Abstract:
In one embodiment, a traffic analysis service identifies a client in a network having an associated traffic flow that was blocked by a firewall. The traffic analysis service obtains traffic telemetry data regarding one or more subsequent traffic flows associated with the identified client that are subsequent to the blocked flow. The traffic analysis service uses a machine learning-based classifier to determine that the identified client is exhibiting evasive network behavior, based on the obtained traffic telemetry data. The traffic analysis service initiates a mitigation action in the network, based on the determination that the identified client is exhibiting evasive network behavior.
Public/Granted literature
- US20200280536A1 DETECTING EVASIVE NETWORK BEHAVIORS USING MACHINE LEARNING Public/Granted day:2020-09-03
Information query