IP Library Granted Patent US 12,438,892
Granted Patent B2
US 12,438,892 · App. 18/088,284 · Granted Oct 7, 2025

Correlating endpoint and network views to identify evasive applications

Inventors: Blake Harrell Anderson (Chapel Hill, NC); David McGrew (Poolesville, MD); Vincent E. Parla (North Hampton, NH); Jan Jusko (Prague, CZ); Martin Grill (Prague, CZ); Martin Vejman (Litomysl, CZ)
Assignee: Cisco Technology, Inc.
H04L63/1416G06F21/44G06F21/52G06F21/554H04L9/3242H04L63/0876H04L63/1425H04L63/1466G06F21/55H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,438,892
App. No.
18/088,284
Granted
Oct 7, 2025
Kind
B2
Abstract

In one embodiment, a service receives traffic telemetry data regarding encrypted traffic sent by an endpoint device in a network. The service analyzes the traffic telemetry data to infer characteristics of an application on the endpoint device that generated the encrypted traffic. The service receives, from a monitoring agent on the endpoint device, application telemetry data regarding the application. The service determines that the application is evasive malware based on the characteristics of the application inferred from the traffic telemetry data and on the application telemetry data received from the monitoring agent on the endpoint device. The service initiates performance of a mitigation action in the network, after determining that the application on the endpoint device is evasive malware.

Claims (58)

1. A method comprising:

extracting, at a service, one or more Transport Layer Security (TLS)-based features from encrypted traffic sent by an endpoint device in a network;

analyzing, by the service, the one or more extracted TLS-based features to infer an identity of an application on the endpoint device that sent the encrypted traffic;

receiving, at the service and from a monitoring agent on the endpoint device, application telemetry data regarding the application;

determining, by the service, that the application is malware based on the identity of the application inferred from the one or more extracted TLS-based features and on the application telemetry data received from the monitoring agent on the endpoint device by:

determining an identity of the application based on the application telemetry data received from the monitoring agent on the endpoint device, and

comparing the identity of the application determined based on the application telemetry data with the identity of the application inferred from the one or more extracted TLS-based features; and

initiating, by the service, performance of a mitigation action in the network, after determining that the application on the endpoint device is malware.

2. The method as in claim 1 , wherein the mitigation action comprises at least one of: blocking the encrypted traffic or generating an alert regarding the endpoint device.

3. The method as in claim 1 , wherein the application telemetry data comprises a process hash fingerprint of the application.

4. The method as in claim 1 , further comprising:

verifying, by the service, that the identity of the application inferred from the one or more extracted TLS-based features is correct based on comparing the identity of the application determined based on the application telemetry data with the identity of the application inferred from the one or more extracted TLS-based features.

5. The method as in claim 1 , further comprising:

determining, by the service, that the application is malware when the identity of the application determined based on the application telemetry data is inconsistent with the identity of the application inferred from the one or more extracted TLS-based features.

6. The method as in claim 1 , wherein receiving, from the monitoring agent on the endpoint device, the application telemetry data regarding the application comprises:

sending, by the service, a request to the monitoring agent for the application telemetry data; and

receiving, at the service, the application telemetry data, in response to the request.

7. The method as in claim 1 , wherein the extracting of the one or more TLS-based features from the encrypted traffic comprises:

analyzing, by the service, packet headers of the encrypted traffic sent by the endpoint device to extract the one or more TLS-based features.

8. An apparatus, comprising:

one or more network interfaces to communicate with a network;

a processor coupled to the one or more network interfaces and configured to execute one or more processes; and

a memory configured to store a process executable by the processor, the one or more processes when executed configured to:

extract one or more Transport Layer Security (TLS)-based features from encrypted traffic sent by an endpoint device in a network;

analyze the one or more extracted TLS-based features to infer an identity of an application on the endpoint device that sent the encrypted traffic;

receive, from a monitoring agent on the endpoint device, application telemetry data regarding the application;

determine that the application is malware based on the identity of the application inferred from the one or more extracted TLS-based features and on the application telemetry data received from the monitoring agent on the endpoint device by:

determining an identity of the application based on the application telemetry data received from the monitoring agent on the endpoint device, and

comparing the identity of the application determined based on the application telemetry data with the identity of the application inferred from the one or more extracted TLS-based features; and

initiate performance of a mitigation action in the network, after determining that the application on the endpoint device is malware.

9. The apparatus as in claim 8 , wherein the mitigation action comprises at least one of: blocking the encrypted traffic or generating an alert regarding the endpoint device.

10. The apparatus as in claim 8 , wherein the application telemetry data comprises a process hash fingerprint of the application.

11. The apparatus as in claim 8 , wherein the one or more processes when executed are further configured to:

verify that the identity of the application inferred from the one or more extracted TLS-based features is correct based on comparing the identity of the application determined based on the application telemetry data with the identity of the application inferred from the one or more extracted TLS-based features.

12. The apparatus as in claim 8 , wherein the one or more processes when executed are further configured to:

determine that the application is malware when the identity of the application determined based on the application telemetry data is inconsistent with the identity of the application inferred from the one or more extracted TLS-based features.

13. The apparatus as in claim 8 , wherein the apparatus receives, from the monitoring agent on the endpoint device, the application telemetry data regarding the application by:

sending a request to the monitoring agent for the application telemetry data; and

receiving the application telemetry data, in response to the request.

14. The apparatus as in claim 8 , wherein the apparatus extracts the one or more TLS-based features from the encrypted traffic by:

analyzing packet headers of the encrypted traffic sent by the endpoint device to extract the one or more TLS-based features.

15. A tangible, non-transitory, computer-readable medium that stores program instructions causing a service to execute a process comprising:

extracting, at a service, one or more Transport Layer Security (TLS)-based features from encrypted traffic sent by an endpoint device in a network;

analyzing, by the service, the one or more extracted TLS-based features to infer an identity of an application on the endpoint device that sent the encrypted traffic;

receiving, at the service and from a monitoring agent on the endpoint device, application telemetry data regarding the application;

determining, by the service, that the application is malware based on the identity of the application inferred from the one or more extracted TLS-based features and on the application telemetry data received from the monitoring agent on the endpoint device by:

determining an identity of the application based on the application telemetry data received from the monitoring agent on the endpoint device, and

comparing the identity of the application determined based on the application telemetry data with the identity of the application inferred from the one or more extracted TLS-based features; and

initiating, by the service, performance of a mitigation action in the network, after determining that the application on the endpoint device is malware.

16. The tangible, non-transitory, computer-readable medium as in claim 15 , wherein the mitigation action comprises at least one of: blocking the encrypted traffic or generating an alert regarding the endpoint device.

17. The tangible, non-transitory, computer-readable medium as in claim 15 , wherein the application telemetry data comprises a process hash fingerprint of the application.

18. The tangible, non-transitory, computer-readable medium as in claim 15 , wherein the process further comprises:

verifying, by the service, that the identity of the application inferred from the one or more extracted TLS-based features is correct based on comparing the identity of the application determined based on the application telemetry data with the identity of the application inferred from the one or more extracted TLS-based features.

19. The tangible, non-transitory, computer-readable medium as in claim 15 , wherein the process further comprises:

determining, by the service, that the application is malware when the identity of the application determined based on the application telemetry data is inconsistent with the identity of the application inferred from the one or more extracted TLS-based features.

20. The tangible, non-transitory, computer-readable medium as in claim 15 , wherein receiving, from the monitoring agent on the endpoint device, the application telemetry data regarding the application comprises:

sending, by the service, a request to the monitoring agent for the application telemetry data; and

receiving, at the service, the application telemetry data, in response to the request.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2022
From: ANDERSON, BLAKE HARRELL; MCGREW, DAVID; PARLA, VINCENT E.; JUSKO, JAN; GRILL, MARTIN; VEJMAN, MARTIN
To: CISCO TECHNOLOGY, INC.
Reel/Frame 062197/0244 →
Continuity (3)
Continuation 16912471 · Jun 25, 2020
Continuation 15848150 · Dec 20, 2017
Related Publication 20230129786A1 · Apr 27, 2023
References Cited (19)
US 8910285B2 · Kolbitsch et al. · 2014 [cited by applicant]
US 9100320B2 · Hsy · 2015 [cited by examiner]
US 9215239B1 · Wang et al. · 2015 [cited by applicant]
US 20110302656A1 · El-Moussa · 2011 [cited by examiner]
US 20130160119A1 · Sartin · 2013 [cited by examiner]
US 20160006755A1 · Donnelly · 2016 [cited by examiner]
US 20170223032A1 · El-Moussa · 2017 [cited by applicant]
US 20180131711A1 · Chen · 2018 [cited by examiner]
US 20180341494A1 · Sood · 2018 [cited by examiner]
US 20180375882A1 · Kallos · 2018 [cited by examiner]
US 20190012457A1 · El-Moussa · 2019 [cited by examiner]
US 20190068474A1 · Vasseur · 2019 [cited by examiner]
US 20190149396A1 · Zafer · 2019 [cited by examiner]
US 20190207955A1 · El-Moussa · 2019 [cited by examiner]
WO WO2017108575A1 · 2017 [cited by applicant]
“Advanced Malware Protection: A Buyer's Guide”, http://informationsecurity.report/Resources/Whitepapers/6df58cb5-f79f-4e5c-82fd-d3e5663aa494_advanced-malware-protection-buyers-guide-pdf-1-w-2078.pdf, 7 pages, May 2016, … [cited by applicant]
“Detecting Advanced Threats and Evasive Malware with Symantec Cynic™”, White Paper: Symantec™ Advanced Threat Protection, https://www.pax8.com/resource/display/2496/, 9 pages, 2016, Symantec Corporation. [cited by applicant]
Anderson, Blake et al., “Identifying Encrypted Malware Traffic With Contextual Flow Data”, Artificial Intelligence and Security, ACM, 2 Penn Plaza, Suite 701, New York, NY 10121-0701 USA, Oct. 28, 2016, pp. 35-46. [cited by applicant]
International Search Report and Written Opinion issued Feb. 15, 2019 in connection with PCT/US2018/063774. [cited by applicant]