- 专利标题: Endpoint network traffic analysis
-
申请号: US16295122申请日: 2019-03-07
-
公开(公告)号: US11223639B2公开(公告)日: 2022-01-11
- 发明人: Oleksii Mandrychenko
- 申请人: Fortinet, Inc.
- 申请人地址: US CA Sunnyvale
- 专利权人: Fortinet, Inc.
- 当前专利权人: Fortinet, Inc.
- 当前专利权人地址: US CA Sunnyvale
- 代理机构: HDC Intellectual Property Law, LLP
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; G06F9/54 ; G06F16/2458 ; H04L29/08 ; G06F21/57
摘要:
Systems and methods for an agent-based approach that facilitates endpoint network traffic analysis are provided. According to an embodiment, an agent running on an endpoint device associated with an enterprise network collects network communication metadata from the endpoint device responsive to receiving callbacks from a kernel-level tracing facility implemented within an OS of the endpoint device and locally stores the collected network communication metadata. Further, the agent performs time-based aggregation of the collected metadata to reduce transmission bandwidth and local storage requirements. The aggregated metadata from the endpoint device is submitted to an anomaly detection service when the endpoint device is connected to the enterprise network. The anomaly detection service uses a machine-learning based approach for detection of anomalous behavior.
公开/授权文献
- US20200287920A1 ENDPOINT NETWORK TRAFFIC ANALYSIS 公开/授权日:2020-09-10
信息查询