- 专利标题: Device detection in network telemetry with TLS fingerprinting
-
申请号: US16686364申请日: 2019-11-18
-
公开(公告)号: US11245675B2公开(公告)日: 2022-02-08
- 发明人: Jan Kohout , Martin Kopp , Jan Brabec , Lukas Bajer
- 申请人: Cisco Technology, Inc.
- 申请人地址: US CA San Jose
- 专利权人: Cisco Technology, Inc.
- 当前专利权人: Cisco Technology, Inc.
- 当前专利权人地址: US CA San Jose
- 代理机构: Behmke Innovation Group LLC
- 代理商 Kenneth J. Heywood; Jonathon P. Western
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; H04L12/26
摘要:
In one embodiment, a traffic analysis service obtains telemetry data regarding encrypted traffic associated with a particular device in the network, wherein the telemetry data comprises Transport Layer Security (TLS) features of the traffic. The service determines, based on the TLS features from the obtained telemetry data, a set of one or more TLS fingerprints for the traffic associated with the particular device. The service calculates a measure of similarity between the set of one or more TLS fingerprints for the traffic associated with the particular device and a set of one or more TLS fingerprints of traffic associated with a second device. The service determines, based on the measure of similarity, that the particular device and the second device were operated by the same user.
公开/授权文献
信息查询