Invention Grant
- Patent Title: System and method of detecting whether a source of a packet flow transmits packets which bypass an operating system stack
-
Application No.: US15171879Application Date: 2016-06-02
-
Publication No.: US10454793B2Publication Date: 2019-10-22
- Inventor: Khawar Deen , Navindra Yadav , Anubhav Gupta , Shashidhar Gandham , Rohit Chandra Prasad , Abhishek Ranjan Singh , Shih-Chun Chang
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: CISCO TECHNOLOGY, INC.
- Current Assignee: CISCO TECHNOLOGY, INC.
- Current Assignee Address: US CA San Jose
- Agency: Polsinelli PC
- Main IPC: G06F17/00
- IPC: G06F17/00 ; G06F15/16 ; G06F9/00 ; H04L12/26 ; H04L29/06 ; G06F9/455 ; G06N20/00 ; G06F16/29 ; G06F16/248 ; G06F16/28 ; G06F16/9535 ; G06F16/2457 ; H04L12/851 ; H04L12/24 ; H04W84/18 ; H04L29/08 ; G06F21/53 ; H04L12/723 ; G06F3/0484 ; H04L1/24 ; H04W72/08 ; H04L9/08 ; H04L9/32 ; H04J3/06 ; H04J3/14 ; H04L29/12 ; H04L12/813 ; H04L12/823 ; H04L12/801 ; H04L12/741 ; H04L12/833 ; H04L12/721 ; G06F3/0482 ; G06T11/20 ; H04L12/841 ; H04L12/725 ; H04L12/715 ; G06F21/55 ; G06F21/56 ; G06F16/16 ; G06F16/17 ; G06F16/11 ; G06F16/13 ; G06N99/00 ; G06F16/174 ; G06F16/23

Abstract:
A method includes capturing first data associated with a first packet flow originating from a first host using a first capture agent deployed at the first host to yield first flow data, capturing second data associated with a second packet flow originating from the first host from a second capture agent deployed on a second host to yield second flow data and comparing the first flow data and the second flow data to yield a difference. When the difference is above a threshold value, the method includes determining that the second packet flow was transmitted by a component that bypassed an operating stack of the first host or a packet capture agent at the device to yield a determination, detecting that hidden network traffic exists, and predicting a malware issue with the first host based on the determination.
Public/Granted literature
Information query