Invention Grant
- Patent Title: Signature creation for unknown attacks
-
Application No.: US14338719Application Date: 2014-07-23
-
Publication No.: US09705914B2Publication Date: 2017-07-11
- Inventor: Andrea Di Pietro , Jean-Philippe Vasseur , Javier Cruz Mota
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Parker Ibrahim & Berg LLC
- Agent James M. Behmke; Stephen D. LeBarron
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/53 ; G06F21/56 ; G06F21/55

Abstract:
In one embodiment, a device in a network generates an expected traffic model based on a training set of data used to train a machine learning attack detector. The device provides the expected traffic model to one or more nodes in the network. The device receives an unexpected behavior notification from a particular node of the one or more nodes. The particular node generates the unexpected behavior notification based on a comparison between the expected traffic model and an observed traffic behavior by the node. The particular node also prevents the machine learning attack detector from analyzing the observed traffic behavior. The device updates the machine learning attack detector to account for the observed traffic behavior.
Public/Granted literature
- US20160028750A1 SIGNATURE CREATION FOR UNKNOWN ATTACKS Public/Granted day:2016-01-28
Information query