IP Library › Granted Patent US 12,289,241
Granted Patent B2
US 12,289,241 · App. 18/312,128 · Granted Apr 29, 2025

Device classification using machine learning models

Inventors: Itai Koren (Tel Aviv, IL); Zvika Plotkin (Tel Aviv, IL)
Assignee: Forescout Technologies, Inc.
H04L47/2441G06N20/00H04L43/04H04L43/062
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,289,241
App. No.
18/312,128
Granted
Apr 29, 2025
Kind
B2
Abstract

Systems, methods, and related technologies for classification are described. Network traffic transmitted by a first device is obtained. A set of features is determined based on the network traffic. A first classification for the device is determine a first classification for the first device based on the set of features. The first classification is associated with a first classification level. A second machine learning model is identified based on the first classification. The second machine learning model is associated with the first classification. A second classification for the first device is determined based on the second machine learning model. The second classification is associated with a second classification level. At least one of the first classification and the second classification is stored.

Claims (56)

1. A method, comprising:

obtaining network traffic from a network, wherein the network traffic is transmitted by a first device that is communicatively coupled to the network;

determining a set of features based on the network traffic;

determining a first classification for the first device based on the set of features and a first machine learning model, wherein determining the first classification comprises determining a first confidence level associated with the first classification, and wherein the first classification is associated with a first classification level;

in response to the first confidence level being above a threshold, selecting a second machine learning model from a plurality of machine learning models based on the first classification, wherein the second machine learning model is associated with the first classification;

determining a second classification for the first device based on the second machine learning model, wherein determining the second classification comprises determining a second confidence level associated with the second classification, and determining the second classification in response to the second confidence level being above the threshold, and wherein the second classification is associated with a second classification level; and

storing at least one of the first classification and the second classification.

2. The method of claim 1 , further comprising:

performing an action based on at least one of the first classification or the second classification.

3. The method of claim 2 , wherein the action comprises one or more of a remediation action or a security action.

4. The method of claim 1 , further comprising:

obtaining additional network traffic from the network, wherein the additional network traffic is transmitted by the first device; and

determining an updated classification for the first device based on the additional network traffic.

5. The method of claim 1 , further comprising:

determining a third classification for the first device based on the set of features, wherein the third classification is associated with the first classification level;

identifying a third machine learning model based on the third classification, wherein the third machine learning model is associated with the third classification;

determining a fourth classification for the first device based on the third machine learning model, wherein the fourth classification is associated with the second classification level; and

storing at least one of the third classification and the fourth classification.

6. The method of claim 1 , wherein the set of features comprises one or more of textual features and a device fingerprint.

7. The method of claim 1 , wherein the second classification is determined further based on one or more of the set of features or a subset of the set of features.

8. The method of claim 1 , wherein the set of features are associated with a set of properties associated with the first device.

9. The method of claim 1 , wherein:

selecting the second machine learning model based on the first classification comprises determining whether at least one machine learning model is associated with the first classification; and

the second machine learning model is identified in response to at least one machine learning model being associated with the first classification.

10. A system, comprising:

a memory; and

a processing device, operatively coupled to the memory, to:

obtain network traffic from a network, wherein the network traffic is transmitted by a first device that is communicatively coupled to the network;

determine a set of features based on the network traffic;

determine a first classification for the first device based on the set of features a first machine learning model, wherein the first classification is associated with a first classification level;

select a second machine learning model from a plurality of machine learning models based on the first classification, wherein the second machine learning model is associated with the first classification, wherein to select the second machine learning model comprises to determine whether at least one machine learning model is associated with the first classification, and to identify the second machine learning model in response to at least one machine learning model being associated with the first classification;

determine a second classification for the first device based on the second machine learning model, wherein the second classification is associated with a second classification level; and

store at least one of the first classification and the second classification.

11. The system of claim 10 , wherein the processing device is further to:

perform an action based on at least one of the first classification or the second classification.

12. The system of claim 11 , wherein the action comprises one or more of a remediation action or a security action.

13. The system of claim 10 , wherein:

determine the first classification for the first device the processing device is further to determine a first confidence level associated with the first classification;

the processing device is further to determine whether the first confidence level is above a threshold confidence level; and

the second machine learning model is identified in response to the first confidence level being above the threshold confidence level.

14. The system of claim 10 , wherein the processing device is further to:

obtain additional network traffic from the network, wherein the additional network traffic is transmitted by the first device;

determine a second set of features based on the additional network traffic;

determine an updated first classification for the first device based on the second set of features;

identify a third machine learning model based on the updated first classification, wherein the third machine learning model is associated with the updated first classification;

determine an updated second classification for the first device based on the third machine learning model; and

store at least one of the updated first classification and the updated second classification.

15. A non-transitory computer readable medium having instructions encoded thereon that, when executed by a processing device, cause the processing device to:

obtain network traffic from a network, wherein the network traffic is transmitted by a first device that is communicatively coupled to the network;

determine a set of features based on the network traffic;

determine a first classification for the first device based on the set of features a first machine learning model, wherein to determine the first classification comprises to determine a first confidence level associated with the first classification, and wherein the first classification is associated with a first classification level;

in response to the first confidence level being above a threshold, select a second machine learning model from a plurality of machine learning models based on the first classification, wherein the second machine learning model is associated with the first classification;

determine a second classification for the first device based on the second machine learning model, wherein to determine the second classification comprises to determine a second confidence level associated with the second classification, and to determine the second classification in response to the second confidence level being above the threshold, and wherein the second classification is associated with a second classification level; and

store at least one of the first classification and the second classification.

16. The non-transitory computer readable medium of claim 15 , wherein the processing device is further to perform an action based on at least one of the first classification or the second classification.

17. The system of claim 16 , wherein the action comprises one or more of a remediation action or a security action.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2023
From: KOREN, ITAI; PLOTKIN, ZVIKA
To: FORESCOUT TECHNOLOGIES, INC.
Reel/Frame 063554/0114 →
Continuity (2)
Continuation 17139704 · Dec 31, 2020
Related Publication 20230283561A1 · Sep 7, 2023
References Cited (30)
US 11689468B2 · Koren · 2023 [cited by examiner]
US 20140237595A1 · Sridhara · 2014 [cited by examiner]
US 20150254555A1 · Williams, Jr. · 2015 [cited by examiner]
US 20160206239A1 · Yoon · 2016 [cited by examiner]
US 20170249455A1 · Permeh · 2017 [cited by examiner]
US 20180144042A1 · Sheng · 2018 [cited by examiner]
US 20180314975A1 · Zang · 2018 [cited by examiner]
US 20190043619A1 · Vaughan · 2019 [cited by examiner]
US 20190228336A1 · Kanagawa · 2019 [cited by examiner]
US 20190245866A1 · Anderson · 2019 [cited by examiner]
US 20190306731A1 · Raghuramu · 2019 [cited by examiner]
US 20190336096A1 · Itu · 2019 [cited by examiner]
US 20200007391A1 · Yang · 2020 [cited by examiner]
US 20200134391A1 · Assaderaghi · 2020 [cited by examiner]
US 20200300970A1 · Nguyen · 2020 [cited by examiner]
US 20200304530A1 · Savalle · 2020 [cited by examiner]
US 20200382527A1 · Mitelman · 2020 [cited by examiner]
US 20210056434A1 · Raghunathan · 2021 [cited by examiner]
US 20210126833A1 · Tedaldi · 2021 [cited by examiner]
US 20210264025A1 · Givental · 2021 [cited by examiner]
US 20210335505A1 · Tedaldi · 2021 [cited by examiner]
US 20210406720A1 · Song · 2021 [cited by examiner]
US 20220210079A1 · Koren · 2022 [cited by examiner]
US 20230012719A1 · Reimer · 2023 [cited by examiner]
US 20230274191A1 · Neumann · 2023 [cited by examiner]
US 20230283561A1 · Koren · 2023 [cited by examiner]
“A review on machine learning-based approaches for Internet traffic classification”; Salman et al.; Institut Mines-T'el'ecom and Springer Nature Switzerland AG 2020; Jun. 2020 (Year: 2020). [cited by examiner]
“Towards the Deployment of Machine Learning Solutions in Network Traffic Classification: A Systematic Survey”; Pacheco et al.; IEEE Communications Surveys & Tutorials, vol. 21, No. 2, Second Quarter 2019 (Year: 2019). [cited by examiner]
International Searching Authority, International Search Report and Written Opinion mailed Mar. 17, 2022, for International Application No. PCT/US2021/062446. [cited by applicant]
Chakraborty et al., “Hierarchical Learning for Automated Malware Classification”; Milcom 2017 Track 3—Cyber Security and Trusted Computing; 2017 (Year: 2017). [cited by applicant]