Invention Grant
- Patent Title: Device detection in network telemetry with TLS fingerprinting
-
Application No.: US16686364Application Date: 2019-11-18
-
Publication No.: US11245675B2Publication Date: 2022-02-08
- Inventor: Jan Kohout , Martin Kopp , Jan Brabec , Lukas Bajer
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Behmke Innovation Group LLC
- Agent Kenneth J. Heywood; Jonathon P. Western
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L12/26
Abstract:
In one embodiment, a traffic analysis service obtains telemetry data regarding encrypted traffic associated with a particular device in the network, wherein the telemetry data comprises Transport Layer Security (TLS) features of the traffic. The service determines, based on the TLS features from the obtained telemetry data, a set of one or more TLS fingerprints for the traffic associated with the particular device. The service calculates a measure of similarity between the set of one or more TLS fingerprints for the traffic associated with the particular device and a set of one or more TLS fingerprints of traffic associated with a second device. The service determines, based on the measure of similarity, that the particular device and the second device were operated by the same user.
Public/Granted literature
- US20210152526A1 DEVICE DETECTION IN NETWORK TELEMETRY WITH TLS FINGERPRINTING Public/Granted day:2021-05-20
Information query