IP Library Granted Patent US 11,800,260
Granted Patent B2
US 11,800,260 · App. 17/154,053 · Granted Oct 24, 2023

Network telemetry with byte distribution and cryptographic protocol data elements

Inventors: Blake Harrell Anderson (Chapel Hill, NC); David Arthur McGrew (Poolesville, MD); Alison Kendler (Allston, MA)
Assignee: Cisco Technology, Inc.
H04Q9/02H04L9/3066H04L63/0428H04L63/166H04Q9/00H04L63/0823H04Q2209/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,800,260
App. No.
17/154,053
Granted
Oct 24, 2023
Kind
B2
Abstract

In one embodiment, a method includes receiving a traffic flow including a plurality of packets encrypted using a cryptographic protocol, determining cryptographic protocol data of the traffic flow, and transmitting telemetry data of the traffic flow including the cryptographic protocol data. In another embodiment, a method includes receiving telemetry data of a traffic flow including a plurality of packets encrypted using a cryptographic protocol, the telemetry data including cryptographic protocol data of the traffic flow, classifying the traffic flow based on the cryptographic protocol data using a machine learning classifier; and taking a remedial action with respect to the traffic flow based on the classification of the traffic flow.

Claims (15)

1. An apparatus comprising:

a network interface configured to interface with a computer network;

one or more processors coupled to the network interface; and

a non-transitory memory comprising instructions that when executed cause the one or more processors to perform operations comprising:

receiving, via the network interface, a traffic flow including a plurality of packets encrypted using a cryptographic protocol and one or more unencrypted packets associated with a handshake procedure;

determining cryptographic protocol data of the traffic flow by inspecting the one or more unencrypted packets which include information indicative of the cryptographic protocol data of the traffic flow, wherein the cryptographic protocol data of the traffic flow includes at least one of: a Transport Layer Security (TLS) version number, one or more ciphersuites offered by a source device, a ciphersuite selected by a destination device, a TLS sequence of record lengths and times, a record type, a handshake type, an extension type, a size of a cryptographic key, a supported elliptical curve, and a supported point format; and

transmitting, via the network interface, telemetry data of the traffic flow, the telemetry data of the traffic flow including the cryptographic protocol data of the traffic flow.

2. A method comprising:

receiving, by a device in a computer network, a traffic flow including a plurality of packets encrypted using a cryptographic protocol and one or more unencrypted packets associated with a handshake procedure;

determining, by the device, cryptographic protocol data of the traffic flow by inspecting the one or more unencrypted packets which include information indicative of the cryptographic protocol data of the traffic flow, wherein the cryptographic protocol data of the traffic flow includes at least one of: a Transport Layer Security (TLS) version number, one or more ciphersuites offered by a source device, a ciphersuite selected by a destination device, a TLS sequence of record lengths and times, a record type, a handshake type, an extension type, a size of a cryptographic key, a supported elliptical curve, and a supported point format; and

transmitting, from the device, telemetry data of the traffic flow, the telemetry data of the traffic flow including the cryptographic protocol data of the traffic flow.

3. The method of claim 2 , wherein the one or more unencrypted packets further include information to establish an encrypted connection using the cryptographic protocol.

4. The method of claim 2 , wherein the telemetry data of the traffic flow further includes at least one of: a source IP address of the traffic flow, a destination IP address of the traffic flow, a start time of the traffic flow, a stop time of the traffic flow, a protocol associated with the traffic flow, a number of bytes of the traffic flow, and a number of the plurality of packets.

5. The method of claim 2 , wherein the telemetry data of the traffic flow further includes a sequence of packet lengths and times (SRLT) for one or more of the plurality of packets.

6. The method of claim 2 , wherein the telemetry data of the traffic flow further includes a byte value distribution metric.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2021
From: ANDERSON, BLAKE HARRELL; MCGREW, DAVID ARTHUR; KENDLER, ALISON
To: CISCO TECHNOLOGY, INC.
Reel/Frame 054981/0598 →
Continuity (5)
Continuation 16436489 · Jun 10, 2019
Continuation 15083586 · Mar 29, 2016
Provisional Application 62275917 · Jan 7, 2016
Provisional Application 62275925 · Jan 7, 2016
Related Publication 20210144455A1 · May 13, 2021