IP Library Granted Patent US 12,549,595
Granted Patent B2
US 12,549,595 · App. 18/413,801 · Granted Feb 10, 2026

Using packet fingerprinting at an endpoint to detect malware

Inventors: Apoorv Raj (Bangalore, IN); Durairaj Murugasamy (Bangalore, IN); Paritosh Sinha (Bihar, IN); Vinay Singh (Ranchi, IN); George Mathew Koikara (Bangalore, IN); David Arthur McGrew (Poolesville, MD); Sivakrishna Lingareddy (Bangalore, IN)
Assignee: Cisco Technology, Inc.
H04L63/145H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,549,595
App. No.
18/413,801
Granted
Feb 10, 2026
Kind
B2
Abstract

Aspects of the present disclosure are directed to on-device firewall and library agents integrated with secure agents on network connected endpoints. The on-device firewall and library agents enable inline analysis and inspection of data packets using protocol fingerprints generated for the data packets using an on-device malware detection engine. In one aspect, a network device includes a driver configured to capture a plurality of data packets received at the network device; and an on-device malware detection engine configured to receive at least a subset of the plurality of packets, and generate a fingerprint for the subset of the plurality of packets, the fingerprint being indicative of whether the plurality of data packets are associated with an external malware communication.

Claims (43)

1 . A network device comprising:

a driver configured to capture a plurality of data packets received at the network device; and

an on-device malware detection engine configured to:

receive at least a subset of the plurality of packets, and

generate a fingerprint for the subset of the plurality of packets, the fingerprint being indicative of whether the plurality of data packets are associated with an external malware communication, wherein

the network device is a user device that is communicatively coupled to one or more cloud-based services and devices in a network, and

the fingerprint is generated before the plurality of packets reach the one or more cloud-based services and devices in the network.

2 . The network device of claim 1 , wherein the on-device malware detection engine is configured to generate the fingerprint inline with reception and processing of the plurality of packets at the network device.

3 . The network device of claim 1 , further comprising:

a firewall agent on the network device configured to determine whether to drop the plurality of packets or permit the plurality of packets to pass through, based on the fingerprint.

4 . The network device of claim 1 , wherein the on-device malware detection engine is configured to generate the fingerprint using a malware detection database.

5 . The network device of claim 4 , wherein the malware detection database is generated using a machine learning engine.

6 . The network device of claim 5 , wherein the machine learning engine is cloud-based and is trained using metadata of previously examined data packets for which the on-device malware detection engine has generated fingerprints.

7 . The network device of claim 1 , further comprising:

a connection agent configured to provide secure network access to the network device, and

the driver and the on-device malware detection engine are software modules within the connection agent.

8 . The network device of claim 7 , wherein the network device is an endpoint terminal connected to a network using the connection agent.

9 . One or more non-transitory computer-readable media comprising computer-readable instructions, which when executed by one or more processors of a network device, cause the network device to:

capture a plurality of data packets received at the network device;

receive at least a subset of the plurality of packets, and

generate a fingerprint for the subset of the plurality of packets, the fingerprint being indicative of whether the plurality of data packets are associated with an external malware communication, wherein

the network device is a user device that is communicatively coupled to one or more cloud-based services and devices in a network, and

the fingerprint is generated before the plurality of packets reach the one or more cloud-based services and devices in the network.

10 . The one or more non-transitory computer-readable media of claim 9 , wherein the network device includes an on-device malware detection engine configured to generate the fingerprint inline with reception and processing of the plurality of packets at the network device.

11 . The one or more non-transitory computer-readable media of claim 9 , wherein the execution of the computer-readable instructions further cause the network device to determine whether to drop the plurality of packets or permit the plurality of packets to pass through, based on the fingerprint.

12 . The one or more non-transitory computer-readable media of claim 9 , wherein the fingerprint is generated using a malware detection database.

13 . The one or more non-transitory computer-readable media of claim 12 , wherein the malware detection database is generated using a machine learning engine.

14 . The one or more non-transitory computer-readable media of claim 13 , wherein the machine learning engine is cloud-based and is trained using metadata of previously examined data packets for which the on-device malware detection engine has generated fingerprints.

15 . The one or more non-transitory computer-readable media of claim 9 , wherein the network device comprises:

a connection agent configured to provide secure network access to the network device, and

a driver and an on-device malware detection engine as software modules within the connection agent to capture the plurality of data packets and generate the fingerprint.

16 . A method for on-device inspection of network traffic, the method comprising:

capturing a plurality of data packets received at a network device;

using an on-device malware detection engine,

processing a subset of the plurality of packets, and

generating a fingerprint for the subset of the plurality of packets, the fingerprint being indicative of whether the plurality of data packets are associated with an external malware communication, wherein

the network device is a user device that is communicatively coupled to one or more cloud-based services and devices in a network, and

the fingerprint is generated before the plurality of packets reach the one or more cloud-based services and devices in the network.

17 . The method of claim 16 , further comprising:

determining whether to drop the plurality of packets or permit the plurality of packets to pass through, based on the fingerprint.

18 . The method of claim 16 , wherein the on-device malware detection engine generates the fingerprint using a malware detection database.

19 . The method of claim 18 , wherein the malware detection database is generated using a machine learning engine.

20 . The method of claim 19 , wherein the machine learning engine is cloud-based and is trained using metadata of previously examined data packets for which the on-device malware detection engine has generated fingerprints.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2024
From: LINGAREDDY, SIVAKRISHNA
To: CISCO TECHNOLOGY, INC.
Reel/Frame 066593/0121 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 17, 2024
From: RAJ, APOORV; MURUGASWAMY, DURAIRAJ; SINHA, PARITOSH; SINGH, VINAY; KOIKARA, GEORGE MATHEW; MCGREW, DAVID ARTHUR
To: CISCO TECHNOLOGY, INC.
Reel/Frame 066146/0050 →
Continuity (1)
Related Publication 20250233885A1 · Jul 17, 2025
References Cited (38)
US 10382479B2 · Adams · 2019 [cited by examiner]
US 10523609B1 · Subramanian · 2019 [cited by examiner]
US 11140196B1 · Bilge et al. · 2021 [cited by applicant]
US 11240262B1 · Aziz et al. · 2022 [cited by applicant]
US 11888870B2 · Garyani · 2024 [cited by examiner]
US 12166793B2 · Jain · 2024 [cited by examiner]
US 12218968B1 · Harb · 2025 [cited by examiner]
US 12425416B2 · Ahmed · 2025 [cited by examiner]
US 20170223046A1 · Singh · 2017 [cited by examiner]
US 20170289176A1 · Chen · 2017 [cited by examiner]
US 20180063199A1 · Lara · 2018 [cited by examiner]
US 20190020664A1 · Wood · 2019 [cited by examiner]
US 20190109820A1 · Clark · 2019 [cited by examiner]
US 20190109822A1 · Clark · 2019 [cited by examiner]
US 20200125721A1 · Antony · 2020 [cited by examiner]
US 20210243208A1 · Rubin · 2021 [cited by examiner]
US 20210288981A1 · Numainville · 2021 [cited by examiner]
US 20210377283A1 · Anderson et al. · 2021 [cited by applicant]
US 20220014554A1 · Vasu · 2022 [cited by examiner]
US 20220224716A1 · Salji · 2022 [cited by applicant]
US 20230129786A1 · Anderson et al. · 2023 [cited by applicant]
US 20240163261A1 · Crabtree · 2024 [cited by examiner]
US 20240205240A1 · Duan · 2024 [cited by examiner]
US 20240259397A1 · Li · 2024 [cited by examiner]
US 20240314141A1 · Nanivadekar · 2024 [cited by examiner]
US 20240396913A1 · Shah · 2024 [cited by examiner]
US 20250039193A1 · Jia · 2025 [cited by examiner]
US 20250039196A1 · Crabtree · 2025 [cited by examiner]
US 20250071139A1 · Sethi · 2025 [cited by examiner]
US 20250071142A1 · Sethi · 2025 [cited by examiner]
US 20250088521A1 · Rahman · 2025 [cited by examiner]
US 20250106185A1 · Ieong · 2025 [cited by examiner]
US 20250193240A1 · Bishop · 2025 [cited by examiner]
US 20250193241A1 · Bishop · 2025 [cited by examiner]
Kim, Hyundo et al. Revisiting TLS-Encrypted Traffic Fingerprinting Methods for Malware Family Classification. 2022 13th International Conference on Information and Communication Technology Convergence (ICTC). https://ie… [cited by examiner]
Tyagi, Rohit et al. Packet Inspection for Unauthorized OS Detection in Enterprises. IEEE Security and Privacy, vol. 13, Issue: 4. https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=7180275 (Year: 2015). [cited by examiner]
Thom, Jay et al. Smart Recon: Network Traffic Fingerprinting for IoT Device Identification. 2022 IEEE 12th Annual Computing and Communication Workshop and Conference (CCWC). https://ieeexplore.ieee.org/stamp/stamp.jsp?t… [cited by examiner]
Yao, Le et al. Intelligent Device Identification Method Based on Network Packet Fingerprint. 2021 IEEE Sixth International Conference on Data Science in Cyberspace (DSC). https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&… [cited by examiner]