IP Library › Granted Patent US 11,689,468
Granted Patent B2
US 11,689,468 · App. 17/139,704 · Granted Jun 27, 2023

Device classification using machine learning models

Inventors: Itai Koren (Tel Aviv, IL); Zvika Plotkin (Tel Aviv, IL)
Assignee: FORESCOUT TECHNOLOGIES, INC.
H04L47/2441G06N20/00H04L43/04H04L43/062
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,689,468
App. No.
17/139,704
Granted
Jun 27, 2023
Kind
B2
Abstract

Systems, methods, and related technologies for classification are described. Network traffic transmitted by a first device is obtained. A set of features is determined based on the network traffic. A first classification for the device is determine a first classification for the first device based on the set of features. The first classification is associated with a first classification level. A second machine learning model is identified based on the first classification. The second machine learning model is associated with the first classification. A second classification for the first device is determined based on the second machine learning model. The second classification is associated with a second classification level. At least one of the first classification and the second classification is stored.

Claims (76)

1. A method, comprising:

obtaining network traffic from a network, wherein the network traffic is transmitted by a first device that is communicatively coupled to the network;

determining a set of features based on the network traffic;

determining a first classification for the first device based on the set of features and a first machine learning model, wherein the first classification is associated with a first classification level;

identifying a second machine learning model based on the first classification, wherein the second machine learning model is associated with the first classification;

determining a second classification for the first device based on the second machine learning model, wherein the second classification is associated with a second classification level;

storing at least one of the first classification and the second classification;

obtaining additional network traffic from the network, wherein the additional network traffic is transmitted by the first device;

determining a second set of features based on the additional network traffic; determining an updated first classification for the first device based on the second set of features;

identifying a third machine learning model based on the updated first classification, wherein the third machine learning model is associated with the updated first classification;

determining an updated second classification for the first device based on the third machine learning model; and

storing at least one of the updated first classification and the updated second classification.

2. The method of claim 1 , further comprising:

performing an action based on at least one of the first classification or the second classification.

3. The method of claim 2 , wherein the action comprises one or more of a remediation action or a security action.

4. The method of claim 1 , wherein:

determining the first classification for the first device comprises: determining a first confidence level associated with the first classification;

the method further comprises: determining whether the first confidence level is above a threshold confidence level; and

the second machine learning model is identified in response to the first confidence level being above the threshold confidence level.

5. The method of claim 4 , wherein:

determining the second classification for the first device comprises: determining a second confidence level associated with the second classification;

the method further comprises: determining whether the second confidence level is above the threshold confidence level; and

the second classification is determined in response to the second confidence level being above the threshold confidence level.

6. The method of claim 1 , further comprising:

determining a third classification for the first device based on the set of features, wherein the third classification is associated with the first classification level;

identifying a third machine learning model based on the third classification, wherein the third machine learning model is associated with the third classification;

determining a fourth classification for the first device based on the third machine learning model, wherein the fourth classification is associated with the second classification level; and

storing at least one of the third classification and the fourth classification.

7. The method of claim 1 , wherein the set of features comprises one or more of textual features and a device fingerprint.

8. The method of claim 1 , wherein the second classification is determined further based on one or more of the set of features or a subset of the set of features.

9. The method of claim 1 , wherein the set of features are associated with a set of properties associated with the first device.

10. The method of claim 1 , wherein:

determining the second machine learning model based on the first classification comprises determining whether at least one machine learning model is associated with the first classification; and

the second machine learning model is identified in response to at least one machine learning model being associated with the first classification.

11. A system, comprising:

a memory; and

a processing device, operatively coupled to the memory, to:

obtain network traffic from a network, wherein the network traffic is transmitted by a first device that is communicatively coupled to the network;

determine a set of features based on the network traffic;

determine a first classification for the first device based on the set of features a first machine learning model, wherein the first classification is associated with a first classification level, wherein to determine the first classification for the first device the processing device is further to determine a first confidence level associated with the first classification;

identify a second machine learning model based on the first classification, wherein the second machine learning model is associated with the first classification;

determine a second classification for the first device based on the second machine learning model, wherein the second classification is associated with a second classification level, to determine the second classification for the first device the processing device is further to determine a second confidence level associated with the second classification;

store at least one of the first classification and the second classification;

determine whether the first confidence level is above a threshold confidence level;

identify the second machine learning model in response to the first confidence level being above the threshold confidence level; and

determine whether the second confidence level is above the threshold confidence level, wherein the second classification is determined in response to the second confidence level being above the threshold confidence level.

12. The system of claim 11 , wherein the processing device is further to: perform an action based on at least one of the first classification or the second classification.

13. The system of claim 12 , wherein the action comprises one or more of a remediation action or a security action.

14. The system of claim 11 , wherein the processing device is further to:

obtain additional network traffic from the network, wherein the additional network traffic is transmitted by the first device;

determine a second set of features based on the additional network traffic;

determine an updated first classification for the first device based on the second set of features;

identify a third machine learning model based on the updated first classification, wherein the third machine learning model is associated with the updated first classification;

determine an updated second classification for the first device based on the third machine learning model; and

store at least one of the updated first classification and the updated second classification.

15. The system of claim 11 , wherein the processing device is further to:

determine a third classification for the first device based on the set of features,

wherein the third classification is associated with the first classification level;

identify a third machine learning model based on the third classification, wherein the third machine learning model is associated with the third classification;

determine a fourth classification for the first device based on the third machine learning model, wherein the fourth classification is associated with the second classification level; and

store at least one of the third classification and the fourth classification.

16. The system of claim 11 , wherein:

to determine the second machine learning model based on the first classification the processing device is further to determine whether at least one machine learning model is associated with the first classification; and

the second machine learning model is determined in response to at least one machine learning model being associated with the first classification.

17. A non-transitory computer readable medium having instructions encoded thereon that, when executed by a processing device, cause the processing device to:

obtain network traffic from a network, wherein the network traffic is transmitted by a first device that is communicatively coupled to the network;

determine a set of features based on the network traffic;

determine a first classification for the first device based on the set of features a first machine learning model, wherein the first classification is associated with a first classification level;

identify a second machine learning model based on the first classification, wherein the second machine learning model is associated with the first classification;

determine a second classification for the first device based on the second machine learning model, wherein the second classification is associated with a second classification level;

store at least one of the first classification and the second classification;

determine a third classification for the first device based on the set of features,

wherein the third classification is associated with the first classification level;

identify a third machine learning model based on the third classification, wherein the third machine learning model is associated with the third classification;

determine a fourth classification for the first device based on the third machine learning model, wherein the fourth classification is associated with the second classification level; and

store at least one of the third classification and the fourth classification.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 7, 2023
From: KOREN, ITAI; PLOTKIN, ZVIKA
To: FORESCOUT TECHNOLOGIES, INC.
Reel/Frame 062905/0694 →
Continuity (1)
Related Publication 20220210079A1 · Jun 30, 2022
Cited By (1)
US 12,289,241