Invention Grant
- Patent Title: Automatically generating a fingerprint prevalence database without ground truth
-
Application No.: US17307677Application Date: 2021-05-04
-
Publication No.: US11558424B2Publication Date: 2023-01-17
- Inventor: Blake Harrell Anderson , David Arthur McGrew
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Lee & Hayes, P.C.
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/40 ; G06K9/62

Abstract:
Techniques and mechanisms for using passively collected network data to automatically generate a fingerprint prevalence database without the need for endpoint ground truth. The process first clusters all observations with the same fingerprint string and similar source and destination context. The process then annotates each cluster with descriptive information and uses a rule-based system to derive an informative name from that descriptive information, e.g., “winnt amp client” or “cross-platform browser”. Optionally, the learned database may be augmented by a user to clarify custom process labels. Additionally, the generated database may be used to report the inferred processes in the same way as databases generated with endpoint ground truth.
Public/Granted literature
- US20220360606A1 AUTOMATICALLY GENERATING A FINGERPRINT PREVALENCE DATABASE WITHOUT GROUND TRUTH Public/Granted day:2022-11-10
Information query