Invention Grant
- Patent Title: Automatically detecting authorized remote administration sessions in a network monitoring system
-
Application No.: US17376924Application Date: 2021-07-15
-
Publication No.: US11632309B2Publication Date: 2023-04-18
- Inventor: David McGrew , Martin Rehak , Blake Harrell Anderson , Sunil Amin
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Behmke Innovation Group. LLC
- Agent James M. Behmke; Jonathon P. Western
- Main IPC: H04L41/28
- IPC: H04L41/28 ; H04L9/40 ; H04W12/12 ; G06F21/55 ; H04L67/143

Abstract:
In one embodiment, a service receives administration traffic data in a network associated with a remote administration session in which a control device remotely administers a client device. The service analyzes the administration traffic data to determine whether any portion of the administration traffic data is resulting from an administration session involving a trusted administrator. The service flags a first portion of the administration traffic data as authorized when the first portion of the administration traffic data is determined to result from an administration session involving a trusted administrator, and a second portion of the administration traffic data is non-flagged. The service assesses the second portion of the administration traffic data using a machine learning-based traffic classifier to determine whether the second portion of the administration traffic data is malicious.
Public/Granted literature
- US20210344573A1 AUTOMATICALLY DETECTING AUTHORIZED REMOTE ADMINISTRATION SESSIONS IN A NETWORK MONITORING SYSTEM Public/Granted day:2021-11-04
Information query