Invention Grant
- Patent Title: Scanning server ports to infer service protocols
-
Application No.: US17964456Application Date: 2022-10-12
-
Publication No.: US11681936B2Publication Date: 2023-06-20
- Inventor: Roy Hodgman , Derek Abdine , Thomas Sellers , Prashant Subbarao
- Applicant: Rapid7, Inc.
- Applicant Address: US MA Boston
- Assignee: Rapid7, Inc.
- Current Assignee: Rapid7, Inc.
- Current Assignee Address: US MA Boston
- Agent Ashwin Anand; Lei Sun
- Main IPC: H04L67/60
- IPC: H04L67/60 ; H04L69/00 ; G06N5/04 ; G06N20/00 ; H04L9/40 ; H04L69/164

Abstract:
Systems and methods are disclosed to infer, using a machine learned model, a service protocol of a server based on the banner data produced by the server. In embodiments, the machine learned model is implemented by a network scanner configured to receive banner data from open ports on servers. A received banner is parsed into a set of features, such as the counts or presence of particular characters or strings in the banner. In embodiments, certain types of banner content such as network addresses, hostnames, dates, and times, are replaced with special characters. The machine learned model is applied to the features to infer a most likely protocol of the server port that produced the banner. Advantageously, the model can be trained to perform the inference task with high accuracy and without using human-specified rules, which can be brittle for unconventional banner data and carry undesired biases.
Public/Granted literature
- US20230034866A1 Machined Learned Inference of Protocols from Banner Data Public/Granted day:2023-02-02
Information query