IP Library Granted Patent US 11,711,308
Granted Patent B2
US 11,711,308 · App. 17/694,060 · Granted Jul 25, 2023

On-box behavior-based traffic classification

Inventors: Michael Joseph Stepanek (Fulton, MD); Costas Kleopa (Clarksville, MD); David McGrew (Poolesville, MD); Blake Harrell Anderson (Chapel Hill, NC); Saravanan Radhakrishnan (Bangalore, IN)
Assignee: Cisco Technology, Inc.
H04L47/2441H04L47/2475H04L47/2483H04L47/25H04L49/355H04L63/0254H04L63/0428H04L63/1425H04L63/1458H04L63/166H04W12/12H04W12/122H04W12/128
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,711,308
App. No.
17/694,060
Granted
Jul 25, 2023
Kind
B2
Abstract

In one embodiment, a networking device in a network detects an traffic flow conveyed in the network via the networking device. The networking device generates flow data for the traffic flow. The networking device performs a classification of the traffic flow using the flow data as input to a machine learning-based classifier. The networking device performs a mediation action based on the classification of the traffic flow.

Claims (40)

1. A method, comprising:

detecting, at a networking device in a network, an encrypted traffic flow conveyed in the network via the networking device;

generating, by the networking device, behavioral flow data for the encrypted traffic flow, the behavioral flow data comprising one or more of: Transport Layer Security (TLS)-based metadata regarding the encrypted traffic flow and Secure Socket Layer (SSL)-based metadata regarding the encrypted traffic flow;

selecting, by the networking device, a machine learning-based classifier among a plurality of machine learning-based classifiers hosted by the networking device based on one or more characteristics of the encrypted traffic flow; and

performing, by the networking device, a classification of the encrypted traffic flow using the behavioral flow data as input to the machine learning-based classifier that is selected by the networking device.

2. The method as in claim 1 , further comprising:

receiving, at the networking device, an adjustment to the machine learning-based classifier from a supervisory device that provides supervisory control over the network.

3. The method as in claim 1 , wherein the machine learning-based classifier is configured to assess a maliciousness of the encrypted traffic flow.

4. The method as in claim 1 , wherein the networking device selects the machine learning-based classifier based in part on a number of bytes or packets of the encrypted traffic flow.

5. The method as in claim 1 , further comprising:

performing, by the networking device, a mediation action when the classification of the encrypted traffic flow indicates that the encrypted traffic flow is suspicious or malicious.

6. The method as in claim 5 , wherein the mediation action comprises at least one of generating an alert and blocking the encrypted traffic flow.

7. The method as in claim 1 , wherein the networking device is a switch or a router through which the encrypted traffic flow flows.

8. An apparatus, comprising:

one or more network interfaces to communicate with a network;

a processor coupled to the one or more network interfaces and configured to execute one or more processes; and

a memory configured to store a process executable by the processor, the one or more processes when executed operable to:

detect an encrypted traffic flow conveyed in the network via the apparatus;

generate behavioral flow data for the encrypted traffic flow, the behavioral flow data comprising one or more of: Transport Layer Security (TLS)-based metadata regarding the encrypted traffic flow and Secure Socket Layer (SSL)-based metadata regarding the encrypted traffic flow;

select a machine learning-based classifier among a plurality of machine learning-based classifiers hosted by the apparatus based on one or more characteristics of the encrypted traffic flow; and

perform a classification of the encrypted traffic flow using the behavioral flow data as input to the machine learning-based classifier that is selected by the apparatus.

9. The apparatus as in claim 8 , wherein the one or more processes when executed are further operable to:

receive an adjustment to the machine learning-based classifier from a supervisory device that provides supervisory control over the network.

10. The apparatus as in claim 8 , wherein the machine learning-based classifier is configured to assess a maliciousness of the encrypted traffic flow.

11. The apparatus as in claim 8 , wherein the apparatus selects the machine learning-based classifier based in part on a number of bytes or packets of the encrypted traffic flow.

12. The apparatus as in claim 8 , wherein the one or more processes when executed are further operable to:

perform a mediation action when the classification of the encrypted traffic flow indicates that the encrypted traffic flow is suspicious or malicious.

13. The apparatus as in claim 12 , wherein the mediation action comprises at least one of generating an alert and blocking the encrypted traffic flow.

14. The apparatus as in claim 8 , wherein the apparatus is a switch or a router through which the encrypted traffic flow flows.

15. A tangible, non-transitory, computer-readable medium that stores program instructions causing a networking device in a network to execute a process comprising:

detecting, at the networking device, an encrypted traffic flow conveyed in the network via the networking device;

generating, by the networking device, behavioral flow data for the encrypted traffic flow, the behavioral flow data comprising one or more of: Transport Layer Security (TLS)-based metadata regarding the encrypted traffic flow and Secure Socket Layer (SSL)-based metadata regarding the encrypted traffic flow;

selecting, by the networking device, a machine learning-based classifier among a plurality of machine learning-based classifiers hosted by the networking device based on one or more characteristics of the encrypted traffic flow; and

performing, by the networking device, a classification of the encrypted traffic flow using the behavioral flow data as input to the machine learning-based classifier that is selected by the networking device.

16. The tangible, non-transitory, computer-readable medium as in claim 15 , wherein the machine learning-based classifier is configured to assess a maliciousness of the encrypted traffic flow.

17. The tangible, non-transitory, computer-readable medium as in claim 15 , wherein the networking device selects the machine learning-based classifier based in part on a number of bytes or packets of the encrypted traffic flow.

18. The tangible, non-transitory, computer-readable medium as in claim 15 , wherein the process further comprises:

performing, by the networking device, a mediation action when the classification of the encrypted traffic flow indicates that the encrypted traffic flow is suspicious or malicious.

19. The tangible, non-transitory, computer-readable medium as in claim 15 , wherein the networking device is a switch or a router through which the encrypted traffic flow flows.

20. The tangible, non-transitory, computer-readable medium as in claim 15 , wherein the networking device is internal to the network and in communication with one or more network edge devices located on an edge of the network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2022
From: STEPANEK, MICHAEL JOSEPH; KLEOPA, COSTAS; MCGREW, DAVID; ANDERSON, BLAKE HARRELL; RADHAKRISHNAN, SARAVANAN
To: CISCO TECHNOLOGY, INC.
Reel/Frame 059257/0553 →
Continuity (4)
Continuation 16910380 · Jun 24, 2020
Continuation 16379352 · Apr 9, 2019
Continuation 15353940 · Nov 17, 2016
Related Publication 20220200914A1 · Jun 23, 2022
Cited By (1)
US 12,640,994