Systems and methods for reinforcement learning to improve encrypted visibility engines
In one embodiment, a method includes classifying a first encrypted data flow in accordance with a classification. Classifying the first encrypted data flow is based on characteristic information associated with the first encrypted data flow. The method further includes generating an indicator that indicates a confidence in the classification of the first encrypted data flow. The method further includes generating a determination of whether the first encrypted data flow comprises malware. The method further includes classifying one or more subsequent encrypted data flows in accordance with the classification. Classifying the one or more subsequent encrypted data flows is based on the determination of whether the first encrypted data flow comprises malware.
1 . One or more network components comprising one or more processors and one or more computer-readable non-transitory storage media coupled to the one or more processors and including instructions that, when executed by the one or more processors, cause the one or more network components to perform operations comprising:
classifying a first encrypted data flow in accordance with a classification, wherein classifying the first encrypted data flow is based on characteristic information associated with the first encrypted data flow;
generating an indicator that indicates a confidence in the classification of the first encrypted data flow;
decrypting the first encrypted data flow, resulting in a first decrypted data flow;
generating a determination of whether the first encrypted data flow comprises malware based on analyzing the first decrypted data flow; and
classifying one or more subsequent encrypted data flows in accordance with the classification, wherein classifying the one or more subsequent encrypted data flows is based on the determination of whether the first encrypted data flow comprises malware.
2 . The one or more network components of claim 1 , wherein classifying the first encrypted data flow in accordance with the classification comprises classifying the first encrypted data flow as either malware, a particular type of malware, or benign.
3 . The one or more network components of claim 1 , wherein the characteristic information associated with the first encrypted data flow comprises a header of the first encrypted data flow, information identifying a source of the first encrypted data flow, information identifying a destination of the first encrypted data flow, or a size of the first encrypted data flow.
4 . The one or more network components of claim 1 , wherein generating the determination of whether the first encrypted data flow comprises malware is based on the indicator having a value that is less than a threshold.
5 . The one or more network components of claim 2 , the operations further comprising:
comparing the classification of the first encrypted data flow with the determination of whether the first encrypted data flow comprises malware.
6 . The one or more network components claim 5 , the operations further comprising:
training a machine learning model configured for classifying encrypted data flows based on whether the classification of the first encrypted data flow matches the determination of whether the first encrypted data flow comprises malware.
7 . A method, comprising:
classifying a first encrypted data flow in accordance with a classification, wherein classifying the first encrypted data flow is based on characteristic information associated with the first encrypted data flow;
generating an indicator that indicates a confidence in the classification of the first encrypted data flow;
decrypting the first encrypted data flow, resulting in a first decrypted data flow;
generating a determination of whether the first encrypted data flow comprises malware based on analyzing the first decrypted data flow; and
classifying one or more subsequent encrypted data flows in accordance with the classification, wherein classifying the one or more subsequent encrypted data flows is based on the determination of whether the first encrypted data flow comprises malware.
8 . The method of claim 7 , wherein classifying the first encrypted data flow in accordance with the classification comprises classifying the first encrypted data flow as either malware, a particular type of malware, or benign.
9 . The method of claim 7 , wherein the characteristic information associated with the first encrypted data flow comprises a header of the first encrypted data flow, information identifying a source of the first encrypted data flow, information identifying a destination of the first encrypted data flow, or a size of the first encrypted data flow.
10 . The method of claim 7 , wherein generating the determination of whether the first encrypted data flow comprises malware is based on the indicator having a value that is less than a threshold.
11 . The method of claim 8 , further comprising:
comparing the classification of the first encrypted data flow with the determination of whether the first encrypted data flow comprises malware.
12 . The method of claim 11 , further comprising:
training a machine learning model configured for classifying encrypted data flows based on whether the classification of the first encrypted data flow matches the determination of whether the first encrypted data flow comprises malware.
13 . One or more computer-readable non-transitory storage media embodying instructions that, when executed by one or more processors, cause the processor one or more processors to perform operations comprising:
classifying a first encrypted data flow in accordance with a classification, wherein classifying the first encrypted data flow is based on characteristic information associated with the first encrypted data flow;
generating an indicator that indicates a confidence in the classification of the first encrypted data flow;
decrypting the first encrypted data flow, resulting in a first decrypted data flow;
generating a determination of whether the first encrypted data flow comprises malware based on analyzing the first decrypted data flow; and
classifying one or more subsequent encrypted data flows in accordance with the classification, wherein classifying the one or more subsequent encrypted data flows is based on the determination of whether the first encrypted data flow comprises malware.
14 . The one or more computer-readable non-transitory storage media of claim 13 , wherein classifying the first encrypted data flow in accordance with the classification comprises classifying the first encrypted data flow as either malware, a particular type of malware, or benign.
15 . The one or more computer-readable non-transitory storage media of claim 13 , wherein the characteristic information associated with the first encrypted data flow comprises a header of the first encrypted data flow, information identifying a source of the first encrypted data flow, information identifying a destination of the first encrypted data flow, or a size of the first encrypted data flow.
16 . The one or more computer-readable non-transitory storage media of claim 13 , wherein generating the determination of whether the first encrypted data flow comprises malware is based on the indicator having a value that is less than a threshold.
17 . The one or more computer-readable non-transitory storage media of claim 14 , the operations further comprising:
comparing the classification of the first encrypted data flow with the determination of whether the first encrypted data flow comprises malware.
18 . The one or more network components of claim 1 , wherein:
generating the indicator is performed by a firewall; and
decrypting the first encrypted data flow is performed by a secondary inspection device.
19 . The method of claim 7 , wherein:
generating the indicator is performed by a firewall; and
decrypting the first encrypted data flow is performed by a secondary inspection device.
20 . The one or more computer-readable non-transitory storage media of claim 13 , wherein:
generating the indicator is performed by a firewall; and
decrypting the first encrypted data flow is performed by a secondary inspection device.