Invention Grant
- Patent Title: Detection of malicious network connections
-
Application No.: US15095076Application Date: 2016-04-10
-
Publication No.: US09531742B2Publication Date: 2016-12-27
- Inventor: Jan Kohout , Jan Jusko , Tomas Pevny , Martin Rehak
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agent Samuel M. Katz
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
In one embodiment a method, system and apparatus is described for detecting a malicious network connection, the method system and apparatus including determining, for each connection over a network, if each connection is a persistent connection, if, as a result of the determining, a first connection is determined to be a persistent connection, collecting connection statistics for the first connection, creating a feature vector for the first connection based on the collected statistics, performing outlier detection for all of the feature vector for all connections over a network which have been determined to be persistent connections, and reporting detected outliers. Related methods, systems and apparatus are also described.
Public/Granted literature
- US20160226902A1 DETECTION OF MALICIOUS NETWORK CONNECTIONS Public/Granted day:2016-08-04
Information query