IP Library Granted Patent US 12,401,661
Granted Patent B2
US 12,401,661 · App. 17/004,435 · Granted Aug 26, 2025

Detecting network activity from sampled network metadata

Inventors: Omer Karin (Tel Aviv, IL); Idan Y. Hen (Tel Aviv, IL); Roy Levin (Haifa, IL)
Assignee: Microsoft Technology Licensing, LLC
H04L63/12H04L43/08H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,401,661
App. No.
17/004,435
Granted
Aug 26, 2025
Kind
B2
Abstract

Generally discussed herein are devices, systems, and methods for cloud traffic monitoring. A method can include receiving sampled network metadata of a packet transmitted via a computer network, providing the sampled network metadata to a neural network (NN) trained on labeled sampled network metadata, and providing, based on only the sampled network metadata, a classification for the sampled network metadata via the trained neural network.

Claims (34)

1. A device comprising:

processing circuitry;

a memory including instructions that when executed by the processing circuitry cause the processing circuitry to perform operations, the operations comprising:

performing deep packet inspection on deep network information of network traffic, including a packet transmitted via a computer network, resulting in network metadata;

sampling the network metadata to include data of a subset of the packets associated with the network metadata resulting in sampled network metadata;

providing the sampled network metadata to a recurrent neural network (RNN) trained (i) on labeled sampled network metadata and the deep network information and (ii) to generate a classification based on only the sampled network metadata, the classification indicating whether the network traffic associated with the sampled network metadata is malicious;

generating, by an analyzer and based on the classification for the sampled network metadata, an action, the action indicating an operation to mitigate malicious traffic associated with the sampled network metadata; and

performing the action.

2. The device of claim 1 , wherein the RNN is trained further based on contents of the packet and the label is an actual classification associated with the contents of the packet and associated sampled network metadata.

3. The device of claim 2 , wherein the actual classification is determined using the deep packet inspection.

4. The device of claim 2 , wherein the actual classification includes one of a user authentication, a device authentication, a database query, file transfer, data streaming, or a malicious action.

5. The device of claim 1 , wherein the RNN includes a bi-directional long short term memory (LSTM) NN.

6. The device of claim 1 , wherein the sampled network metadata is of network traffic provided over layer three of the computer network.

7. The device of claim 1 , wherein the device is a router, switch, firewall, or client device.

8. A method comprising

performing, by processing circuitry, deep packet inspection on deep network information of network traffic, including a packet transmitted via a computer network, resulting in network metadata;

sampling the network metadata to include data of a subset of the packets associated with the network metadata resulting in the sampled network metadata;

providing, by the processing circuitry, the sampled network metadata to a recurrent neural network (RNN) trained (i) on labeled sampled network metadata and the deep network information and the deep network information and (ii) to generate a classification based on only the sampled network metadata, the classification indicating whether the network traffic associated with the sampled network metadata is malicious;

generating, by an analyzer and based on the classification for the sampled network metadata, an action, the action indicating an operation to mitigate malicious traffic associated with the sampled network metadata; and

performing the action.

9. The method of claim 8 , wherein the RNN is trained further based on contents of the packet and the label is an actual classification associated with the contents of the packet and associated sampled network metadata.

10. The method of claim 9 , wherein the actual classification is determined using the deep packet inspection.

11. The method of claim 9 , wherein the actual classification includes one of a user authentication, a device authentication, a database query, file transfer, data streaming, or a malicious action.

12. The method of claim 8 , wherein the RNN includes a bi-directional long short term memory (LSTM) NN.

13. The method of claim 8 , wherein the sampled network metadata is of network traffic provided over layer three of the computer network.

14. A non-transitory machine-readable medium including instructions that, when executed by a machine, cause the machine to perform operations comprising:

performing deep packet inspection on deep network information of network traffic, including a packet transmitted via a computer network, resulting in network metadata;

sampling the network metadata to include data of a subset of the packets associated with the network metadata resulting in the sampled network metadata;

providing the sampled network metadata to a recurrent neural network (RNN) trained (i) on labeled sampled network metadata and (ii) to generate a classification based on only the sampled network metadata, the classification indicating whether the network traffic associated with the sampled network metadata is malicious;

generating, by an analyzer and based on the classification for the sampled network metadata, an action, the action indicating an operation to mitigate malicious traffic associated with the sampled network metadata; and

performing the action.

15. The non-transitory machine-readable medium of claim 14 , wherein the RNN is trained further based on contents of the packet and the label is an actual classification associated with the contents of the packet and associated sampled network metadata.

16. The non-transitory machine-readable medium of claim 15 , wherein the actual classification is determined using the deep packet inspection.

17. The non-transitory machine-readable medium of claim 14 , wherein the RNN includes a bi-directional long short term memory (LSTM) NN.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE EXECUTION DATE OF ROY LEVIN TO "08/26/2020" AND ALSO CORRECT THE ASSIGNMENT AGREEMENT PREVIOUSLY RECORDED ON REEL 053615 FRAME 0460. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Aug 31, 2020
From: KARIN, OMER; HEN, IDAN Y.; LEVIN, ROY
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 053641/0464 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2020
From: KARIN, OMER; HAN, IDAN Y.; LEVIN, ROY
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 053615/0460 →
Continuity (1)
Related Publication 20220067484A1 · Mar 3, 2022
References Cited (19)
US 8065721B1 · Shah · 2011 [cited by examiner]
US 10412105B2 · Sofka · 2019 [cited by examiner]
US 11301778B2 · Pastor Perales · 2022 [cited by examiner]
US 11616798B2 · Achleitner · 2023 [cited by examiner]
US 11621899B1 · Bettaiah · 2023 [cited by examiner]
US 20190294995A1 · Pastor Perales · 2019 [cited by examiner]
US 20200067935A1 · Carnes, III · 2020 [cited by examiner]
US 20200117523A1 · Morrison · 2020 [cited by examiner]
US 20200236131A1 · Vejman · 2020 [cited by examiner]
US 20200272859A1 · Lashyn · 2020 [cited by examiner]
US 20210256156A1 · Enuka · 2021 [cited by examiner]
US 20220004897A1 · Jadon · 2022 [cited by examiner]
CN 110532564A · 2019 [cited by applicant]
Bachl et al. “SparseIDS: Learning Packet Sampling with Reinforcement Learning”, IEEE Conference on Comm'ns and Network Security (CNS) p. 1-9, Jun. 29, 2020 [retrieved on Aug. 22, 2022]. DOI: 10.1109/CNS48642.2020.916225… [cited by examiner]
Wang et al. “A Framework for QoS-aware Traffic Classification Using Semi-supervised Machine Learning in SDNs”, 2016 IEEE Int'l Conf'n on Services Computing, Jun. 30, 2016. DOI: 10.1109/SCC.2016.133. (Year: 2016). [cited by examiner]
Lee, Nicholas, et al., “Study of long short-term memory in flow-based network intrusion detection system”, In Journal of Intelligent & Fuzzy Systems, vol. 35, Issue 6, Jan. 1, 2018. 5947-5957. [cited by applicant]
Lopez-Martin, et al., “Network Traffic Classifier With Convolutional and Recurrent Neural Networks for Internet of Things”, In Proceedings of IEEE Access, vol. 5, Sep. 6, 2017, pp. 18042-18050. [cited by applicant]
“International Search Report and Written Opinion Issued in PCT Application No. PCT/US2021/034123”, Mailed Date: Aug. 31, 2021, 11 Pages. [cited by applicant]
Rezaei, et al., “Large-Scale Mobile App Identification Using Deep Learning”, In Proceedings of IEEE Access, vol. 8, Dec. 24, 2019, pp. 348-362. [cited by applicant]