Invention Grant
- Patent Title: Identifying self-signed certificates using HTTP access logs for malware detection
-
Application No.: US15386006Application Date: 2016-12-21
-
Publication No.: US10375097B2Publication Date: 2019-08-06
- Inventor: Martin Kopp , Martin Grill , Jan Kohout
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Behmke Innovation Group LLC
- Agent James Behmke; Stephen D. LeBarron
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/32

Abstract:
In one embodiment, a device in a network receives traffic information regarding one or more secure sessions in the network. The device associates the one or more secure sessions with corresponding certificate validation check traffic indicated by the received traffic information. The device makes a self-signed certificate determination for an endpoint domain of a particular secure session based on whether the particular secure session is associated with certificate validation check traffic. The device causes the self-signed certificate determination for the endpoint domain to be used as input to a malware detector.
Public/Granted literature
- US20180176240A1 IDENTIFYING SELF-SIGNED CERTIFICATES USING HTTP ACCESS LOGS FOR MALWARE DETECTION Public/Granted day:2018-06-21
Information query