- 专利标题: AUTOMATICALLY DETECTING AUTHORIZED REMOTE ADMINISTRATION SESSIONS IN A NETWORK MONITORING SYSTEM
-
申请号: US18668697申请日: 2024-05-20
-
公开(公告)号: US20240305539A1公开(公告)日: 2024-09-12
- 发明人: David McGrew , Martin Rehak , Blake Harrell Anderson , Sunil Amin
- 申请人: Cisco Technology, Inc.
- 申请人地址: US CA San Jose
- 专利权人: Cisco Technology, Inc.
- 当前专利权人: Cisco Technology, Inc.
- 当前专利权人地址: US CA San Jose
- 主分类号: H04L41/28
- IPC分类号: H04L41/28 ; G06F21/55 ; H04L9/40 ; H04L67/143 ; H04W12/12
摘要:
In one embodiment, a service receives administration traffic data in a network associated with a remote administration session in which a control device remotely administers a client device. The service analyzes the administration traffic data to determine whether any portion of the administration traffic data is resulting from an administration session involving a trusted administrator. The service flags a first portion of the administration traffic data as authorized when the first portion of the administration traffic data is determined to result from an administration session involving a trusted administrator, and a second portion of the administration traffic data is non-flagged. The service assesses the second portion of the administration traffic data using a machine learning-based traffic classifier to determine whether the second portion of the administration traffic data is malicious.
信息查询