IP Library Granted Patent US 10,812,334
Granted Patent B2
US 10,812,334 · App. 16/023,413 · Granted Oct 20, 2020

Self-training classification

Inventors: Siying Yang (Cupertino, CA); Yang Zhang (Fremont, CA)
Assignee: FORESCOUT TECHNOLOGIES, INC.
H04L41/0853G06K9/6267G06N20/00H04L43/04H04L43/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,812,334
App. No.
16/023,413
Granted
Oct 20, 2020
Kind
B2
Abstract

Systems, methods, and related technologies for self-training classification are described. In certain aspects, a plurality of device classification methods with associated models are accessed. Each of the classification methods have an associated reliability level. The models of classification methods with a higher reliability level than other classifications methods are used to train the models associated with lower reliability level. The trained models and associated classification methods are thus improved.

Claims (46)

1. A training method comprising:

accessing a plurality of device classification methods, wherein each of the plurality of methods has a respective associated model, and wherein each of the plurality of methods has a respective associated reliability level;

performing an initial classification of the plurality of devices communicatively coupled to the network;

determining which of the plurality of device classification methods can be used based on the initial classification of the plurality of devices communicatively coupled to the network, wherein determining comprises identifying which of the plurality of device classification methods are allowed or available for performing in a network environment being classified;

generating a respective data set associated with each of the device classification methods based on classifying a plurality of devices communicatively coupled to a network;

selecting a first device classification method and a second device classification method of the plurality of device classification methods, wherein the first device classification method has a higher reliability level than the second device classification method;

determining a training data set using a respective data set associated with the first device classification method;

training, by a processing device, the second device classification method model using the training data set; and

storing the trained second device classification model.

2. The training method of claim 1 , further comprising:

performing classification using the second device classification method.

3. The training method of claim 1 , wherein the training of the second device classification method model using the training data set is performed on a per device basis.

4. The training method of claim 1 , wherein each respective model associated with the plurality of device classification methods is a machine learning model.

5. The training method of claim 1 , wherein the respective associated reliability level associated with the plurality of device classification methods is configurable.

6. The training method of claim 1 , wherein the respective associated reliability level associated with a device classification methods is automatically adjusted based on one or more classification results based on the device classification method.

7. The training method of claim 1 , wherein the selecting of the first device classification method and the second device classification method of the plurality of device classification methods is based on a network environment.

8. The training method of claim 1 , wherein the first device classification method comprises at least one of an agent based classification method, an aggregator based method, an active probing based method, a passive traffic analysis method, a traffic log analysis method, or a traffic based behavior heuristic method.

9. A system comprising:

a memory; and

a processing device, operatively coupled to the memory, to:

access a plurality of device classification methods, wherein each of the plurality of methods has a respective associated model, and wherein each of the plurality of methods has a respective associated reliability level;

perform an initial classification of the plurality of devices communicatively coupled to the network;

determine which of the plurality of device classification methods can be used based on the initial classification of the plurality of devices communicatively coupled to the network, wherein determining comprises identifying which of the plurality of device classification methods are allowed or available for performing in a network environment being classified;

generate a respective data set associated with each of the device classification methods based on classifying a plurality of devices communicatively coupled to a network;

select a first device classification method and a second device classification method of the plurality of device classification methods, wherein the first device classification method has a higher reliability level than the second device classification method;

determine a training data set using a respective data set associated with the first device classification method;

train the second device classification method model using the training data set; and

store the trained second device classification model.

10. The system of claim 9 , wherein the processing device further to:

perform classification using the second device classification method.

11. The system of claim 9 , wherein the training of the second device classification method model using the training data set is performed on a per device basis.

12. The system of claim 9 , wherein each respective model associated with the plurality of device classification methods is a machine learning model.

13. The system of claim 9 , wherein the respective associated reliability level associated with the plurality of device classification methods is configurable.

14. The system of claim 9 , wherein the selecting of the first device classification method and the second device classification method of the plurality of device classification methods is based on a network environment.

15. The system of claim 9 , wherein the first device classification method comprises at least one of an agent based classification method, an aggregator based method, an active probing based method, a passive traffic analysis method, a traffic log analysis method, or a traffic based behavior heuristic method.

16. A non-transitory computer readable medium having instructions encoded thereon that, when executed by a processing device, cause the processing device to:

access a plurality of device classification methods, wherein each of the plurality of methods has a respective associated model, and wherein each of the plurality of methods has a respective associated reliability level;

perform an initial classification of the plurality of devices communicatively coupled to the network;

determine which of the plurality of device classification methods can be used based on the initial classification of the plurality of devices communicatively coupled to the network, wherein the determination comprises identifying which of the plurality of device classification methods are allowed or available for performing in a network environment being classified;

generate a respective data set associated with each of the device classification methods based on classifying a plurality of devices communicatively coupled to a network;

select a first device classification method and a second device classification method of the plurality of device classification methods, wherein the first device classification method has a higher reliability level than the second device classification method;

determine a training data set using a respective data set associated with the first device classification method;

train, by the processing device, the second device classification method model using the training data set; and

storing the trained second device classification model.

17. The non-transitory computer readable medium of claim 16 , wherein the training of the second device classification method model using the training data set is performed on a per device basis.

18. The non-transitory computer readable medium of claim 16 , wherein the selection of the first device classification method and the second device classification method of the plurality of device classification methods is based on a network environment.

Assignments (2)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 17, 2020
From: FORESCOUT TECHNOLOGIES, INC.
To: OWL ROCK CAPITAL CORPORATION, AS ADMINISTRATIVE AGENT
Reel/Frame 053519/0982 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 7, 2019
From: YANG, SIYING; ZHANG, YANG
To: FORESCOUT TECHNOLOGIES, INC.
Reel/Frame 049405/0402 →
Continuity (1)
Related Publication 20200007391A1 · Jan 2, 2020