- 专利标题: Automatically detecting authorized remote administration sessions in a network monitoring system
-
申请号: US17376924申请日: 2021-07-15
-
公开(公告)号: US11632309B2公开(公告)日: 2023-04-18
- 发明人: David McGrew , Martin Rehak , Blake Harrell Anderson , Sunil Amin
- 申请人: Cisco Technology, Inc.
- 申请人地址: US CA San Jose
- 专利权人: Cisco Technology, Inc.
- 当前专利权人: Cisco Technology, Inc.
- 当前专利权人地址: US CA San Jose
- 代理机构: Behmke Innovation Group. LLC
- 代理商 James M. Behmke; Jonathon P. Western
- 主分类号: H04L41/28
- IPC分类号: H04L41/28 ; H04L9/40 ; H04W12/12 ; G06F21/55 ; H04L67/143
摘要:
In one embodiment, a service receives administration traffic data in a network associated with a remote administration session in which a control device remotely administers a client device. The service analyzes the administration traffic data to determine whether any portion of the administration traffic data is resulting from an administration session involving a trusted administrator. The service flags a first portion of the administration traffic data as authorized when the first portion of the administration traffic data is determined to result from an administration session involving a trusted administrator, and a second portion of the administration traffic data is non-flagged. The service assesses the second portion of the administration traffic data using a machine learning-based traffic classifier to determine whether the second portion of the administration traffic data is malicious.
公开/授权文献
信息查询