Invention Grant
- Patent Title: ML-based encrypted file classification for identifying encrypted data movement
-
Application No.: US17860037Application Date: 2022-07-07
-
Publication No.: US11947682B2Publication Date: 2024-04-02
- Inventor: Yi Zhang , Siying Yang , Yihua Liao , Dagmawi Mulugeta , Raymond Joseph Canzanese, Jr. , Ari Azarafrooz
- Applicant: Netskope, Inc.
- Applicant Address: US CA Santa Clara
- Assignee: Netskope, Inc.
- Current Assignee: Netskope, Inc.
- Current Assignee Address: US CA Santa Clara
- Main IPC: G06F21/60
- IPC: G06F21/60 ; G06F9/54 ; H04L41/16

Abstract:
The disclosed technology teaches facilitate User and Entity Behavior Analytics (UEBA) by classifying a file being transferred as encrypted or not. The technology involves monitoring movement of a files by a user over a wide area network, detecting file encryption for the files using a trained classifier, wherein the detecting includes processing by the classifier some or all of the following features extracted from each of the files: a chi-square randomness test; an arithmetic mean test; a serial correlation coefficient test; a Monte Carlo-Pi test; and a Shannon entropy test, counting a number of the encrypted files moved by the user in a predetermined period, comparing a predetermined maximum number of encrypted files allowed in the predetermined period to the count of the encrypted files moved by the user and detecting that the user has moved more encrypted files than the predetermined maximum number, and generating an alert.
Public/Granted literature
- US20240012912A1 ML-BASED ENCRYPTED FILE CLASSIFICATION FOR IDENTIFYING ENCRYPTED DATA MOVEMENT Public/Granted day:2024-01-11
Information query