IP Library › Granted Patent US 12,684,008
Granted Patent B2
US 12,684,008 · App. 18/441,414 · Granted Jul 14, 2026

Analyzing encrypted traffic behavior using contextual traffic data

Inventors: Jan Kohout (Roudnice Nad Labem, CZ); Blake Harrell Anderson (Chapel Hill, NC); Martin Grill (Prague, CZ); David McGrew (Poolesville, MD); Martin Kopp (Beroun, CZ); Tomas Pevny (Praha-Modrany, CZ)
Assignee: Cisco Technology, Inc.
H04L63/1441G06N20/00H04L41/0686H04L47/2441H04L63/0428H04L63/1416H04L63/1425H04L63/145H04L63/168G06N20/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,684,008
App. No.
18/441,414
Filed
Feb 14, 2024
Granted
Jul 14, 2026
Kind
B2
Art Unit
2491
USPC
726/23
Abstract

In one embodiment, a device in a network detects an encrypted traffic flow associated with a client in the network. The device captures contextual traffic data regarding the encrypted traffic flow from one or more unencrypted packets associated with the client. The device performs a classification of the encrypted traffic flow by using the contextual traffic data as input to a machine learning-based classifier. The device generates an alert based on the classification of the encrypted traffic flow.

Claims (39)

1 . A method, comprising:

detecting, at a device in a network, an encrypted traffic flow comprising one or more encrypted packets sent by a client in the network;

capturing, at the device, one or more initial packets of the encrypted traffic flow sent by the client, wherein at least one of the one or more initial packets is a packet captured as part of a local context and is determined based on information associated with a request by the client to initiate the encrypted traffic flow, wherein the local context comprises one or more packets from one or more additional traffic flows associated with the client that are distinct from the encrypted traffic flow;

performing, by the device, a classification of the encrypted traffic flow by using the one or more initial packets from both the encrypted traffic flow and the one or more additional traffic flows as input to a machine learning-based classifier, wherein the machine learning-based classifier uses information from the one or more additional traffic flows to characterize the encrypted traffic flow; and

generating, by the device, an alert based on the classification of the encrypted traffic flow.

2 . The method as in claim 1 , wherein the machine learning-based classifier is trained using sample contextual traffic data for encrypted traffic flows that are known to be either benign or malicious.

3 . The method as in claim 1 , wherein the one or more initial packets comprise one or more HTTP Secure (HTTPS) packets.

4 . The method as in claim 1 , wherein capturing the one or more initial packets of the encrypted traffic flow is based on a predefined fixed-size set of packets: 1) sent sequentially before or after a request packet of the encrypted traffic flow, 2) sent by the client within a predefined timespan of the request packet of the encrypted traffic flow, or 3) associated with a predefined micro-activity performed by the client.

5 . The method as in claim 4 , wherein the predefined fixed-size set of packets defines a fixed number of requests issued by the client sequentially before or after a request packet of the encrypted traffic flow.

6 . The method as in claim 4 , wherein the predefined timespan defines a window within which the request packet of the encrypted traffic flow and at least one other request packet are issued by the client.

7 . The method as in claim 4 , wherein the predefined micro-activity represents an activity performed by a user of the client.

8 . The method as in claim 1 , wherein capturing the one or more initial packets of the encrypted traffic flow comprises:

extracting, by the device, header information from the one or more initial packets sent by the client; and

constructing, by the device, a feature vector for input to the machine learning-based classifier based on the header information that is extracted.

9 . The method as in claim 8 , wherein the header information is extracted from one or more of: a content-type header field, a user-agent header field, an accept-language header field, a server header field, or a status-code header field.

10 . An apparatus, comprising:

one or more network interfaces to communicate with a network;

a processor coupled to the one or more network interfaces and configured to execute one or more processes; and

a memory configured to store a process that is executable by the processor, the process when executed operable to:

detect an encrypted traffic flow comprising one or more encrypted packets sent by a client in the network;

capture one or more initial packets of the encrypted traffic flow sent by the client, wherein at least one of the one or more initial packets is a packet captured as part of a local context and is determined based on information associated with a request by the client to initiate the encrypted traffic flow, wherein the local context comprises one or more packets from one or more additional traffic flows associated with the client that are distinct from the encrypted traffic flow;

perform a classification of the encrypted traffic flow by using the one or more initial packets from both the encrypted traffic flow and the one or more additional traffic flows as input to a machine learning-based classifier, wherein the machine learning-based classifier uses information from the one or more additional traffic flows to characterize the encrypted traffic flow; and

generate an alert based on the classification of the encrypted traffic flow.

11 . The apparatus as in claim 10 , wherein the machine learning-based classifier is trained using sample contextual traffic data for encrypted traffic flows that are known to be either benign or malicious.

12 . The apparatus as in claim 10 , wherein the one or more initial packets comprise one or more HTTP Secure (HTTPS) packets.

13 . The apparatus as in claim 10 , wherein capturing the one or more initial packets of the encrypted traffic flow is based on a predefined fixed-size set of packets: 1) sent sequentially before or after a request packet of the encrypted traffic flow, 2) sent by the client within a predefined timespan of the request packet of the encrypted traffic flow, or 3) associated with a predefined micro-activity performed by the client.

14 . The apparatus as in claim 13 , wherein the predefined fixed-size set of packets defines a fixed number of requests issued by the client sequentially before or after a request packet of the encrypted traffic flow.

15 . The apparatus as in claim 13 , wherein the predefined timespan defines a window within which the request packet of the encrypted traffic flow and at least one other request packet are issued by the client.

16 . The apparatus as in claim 13 , wherein the predefined micro-activity represents an activity performed by a user of the client.

17 . The apparatus as in claim 10 , wherein capturing the one or more initial packets of the encrypted traffic flow comprises:

extracting header information from the one or more initial packets sent by the client; and

constructing a feature vector for input to the machine learning-based classifier based on the header information that is extracted.

18 . The apparatus as in claim 17 , wherein the header information is extracted from one or more of: a content-type header field, a user-agent header field, an accept-language header field, a server header field, or a status-code header field.

19 . A tangible, non-transitory, computer-readable medium that stores program instructions that cause a device in a network to execute a process comprising:

detecting, at the device, an encrypted traffic flow comprising one or more encrypted packets sent by a client in the network;

capturing, at the device, one or more initial packets of the encrypted traffic flow sent by the client, wherein at least one of the one or more initial packets is a packet captured as part of a local context and is determined based on information associated with a request by the client to initiate the encrypted traffic flow, wherein the local context comprises one or more packets from one or more additional traffic flows associated with the client that are distinct from the encrypted traffic flow;

performing, by the device, a classification of the encrypted traffic flow by using the one or more initial packets from both the encrypted traffic flow and the one or more additional traffic flows as input to a machine learning-based classifier, wherein the machine learning-based classifier uses information from the one or more additional traffic flows to characterize the encrypted traffic flow; and

generating, by the device, an alert based on the classification of the encrypted traffic flow.

20 . The tangible, non-transitory, computer-readable medium as in claim 19 , wherein capturing the one or more initial packets of the encrypted traffic flow is based on a predefined fixed-size set of packets: 1) sent sequentially before or after a request packet of the encrypted traffic flow, 2) sent by the client within a predefined timespan of the request packet of the encrypted traffic flow, or 3 ) associated with a predefined micro-activity performed by the client.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 14, 2024
From: KOHOUT, JAN; ANDERSON, BLAKE HARRELL; GRILL, MARTIN; MCGREW, DAVID; KOPP, MARTIN; PEVNY, TOMAS
To: CISCO TECHNOLOGY, INC.
Reel/Frame 066463/0500 →
Continuity (4)
Continuation 17873544 · Jul 26, 2022
Continuation 17029156 · Sep 23, 2020
Continuation 15286728 · Oct 6, 2016
Related Publication 20240187444A1 · Jun 6, 2024
References Cited (36)
US 7634811B1 · Kienzle et al. · 2009 [cited by applicant]
US 7778194B1 · Yung · 2010 [cited by applicant]
US 8539221B2 · Tremblay · 2013 [cited by examiner]
US 8549645B2 · Tang et al. · 2013 [cited by applicant]
US 8699357B2 · Deshpande et al. · 2014 [cited by applicant]
US 8832007B2 · Nahum et al. · 2014 [cited by applicant]
US 9038178B1 · Lin · 2015 [cited by applicant]
US 9043919B2 · Wyatt et al. · 2015 [cited by applicant]
US 9055093B2 · Borders · 2015 [cited by applicant]
US 9374385B1 · Falkowitz et al. · 2016 [cited by applicant]
US 9846780B2 · Tonn et al. · 2017 [cited by applicant]
US 10212176B2 · Wang · 2019 [cited by applicant]
US 10361931B2 · Sokolik et al. · 2019 [cited by applicant]
US 10659478B2 · Heilig · 2020 [cited by examiner]
US 10778700B2 · Azvine · 2020 [cited by examiner]
US 10805338B2 · Kohout et al. · 2020 [cited by applicant]
US 20070056046A1 · Claudatos et al. · 2007 [cited by applicant]
US 20110142240A1 · Yoon et al. · 2011 [cited by applicant]
US 20120287922A1 · Heck et al. · 2012 [cited by applicant]
US 20160269448A1 · Jayaraman et al. · 2016 [cited by applicant]
US 20170237777A1 · Joch · 2017 [cited by examiner]
US 20180115567A1 · El-Moussa · 2018 [cited by examiner]
US 20200327252A1 · McFall et al. · 2020 [cited by applicant]
WO 2015128609A1 · 2015 [cited by applicant]
Anderson B., et al., “Deciphering Malware's use of TLS (Without Decryption),” arxiv.org, Cornell University Library, 201 Olin Library Cornell University Ithaca, NY 14853, Jul. 6, 2016, 17 pages, XP080712441. [cited by applicant]
Bocchi E., et al., “MAGMA Network Behavior Classifier for Malware Traffic,” Mar. 31, 2016, 19 Pages. [cited by applicant]
Conti M., et al., “Analyzing Android Encrypted Network Traffic to Identify User Actions”, IEEE Transactions on Information Forensics and Security, vol. 11, No. 1, Jan. 1, 2016, pp. 114-125. [cited by applicant]
Extended European Search Report for European Application No. 17194010.9, mailed Feb. 14, 2018, 10 Pages. [cited by applicant]
Husák M., et al., “HTTPS Traffic Analysis and Client Identification Using Passive SSL/TLS Fingerprinting,” EURASIP Journal on Information Security, SpringerOpen Journal, Feb. 2016, 14 Pages. [cited by applicant]
Krzanowski R., “Burst (of Packets) and Burstiness,” 66th IETF—Montreal, Quebec, Canada, Oct. 7, 2006, pp. 1-24, [Retrieved on Jan. 31, 2018]. Retrieved from URL: https://www.ietf.org/proceedings/66/slides/ippm-10.pdf. [cited by applicant]
Searchmetrics: “HTTPS Encryption—What is the impact of TLS/SSL on Rankings?,” Mar. 3, 2015, pp. 1-16, Retrieved from URL: https://blog.searchmetrics.com/us/https-vs-http-website-ssl-tls-encryption-ranking-seo-secure-con… [cited by applicant]
Warmer M., “Detection Of Web Based Command & Control Channels” University of Twente, Nov. 2011, 85 Pages. [cited by applicant]
Wikipedia: “Network Behavior Anomaly Detection (NBAD),” Aug. 9, 2016, pp. 1-3, Retrieved from URL: https://en.wikipedia.org/wiki/Network_Behavior_Anomaly_Detection. [cited by applicant]
Wireshark: “The “Capture Options” dialog box,” Jun. 18, 2016, 3 Pages, [Retrieved on Jan. 31, 2018] Retrieved from URL: https://web.archive.org/web/20160618040335/https://www.wireshark.org/docs/wsug_html_chuncked//ChCap… [cited by applicant]
Wright C.V., et al., “On Inferring Application Protocol Behaviors in Encrypted Network Traffic,” Journal of Machine Learning Research, Submitted On Mar. 2006, Revised On Sep. 2006, Published On Dec. 2006, vol. 7, pp. 27… [cited by applicant]
Yen T., “Detecting Stealthy Malware Using Behavioral Features in Network Traffic” Department of Electrical and Computer Engineering Carnegie Mellon University, Aug. 2011, 123 Pages. [cited by applicant]