- 专利标题: Correlating endpoint and network views to identify evasive applications
-
申请号: US16912471申请日: 2020-06-25
-
公开(公告)号: US11539721B2公开(公告)日: 2022-12-27
- 发明人: Blake Harrell Anderson , David McGrew , Vincent E. Parla , Jan Jusko , Martin Grill , Martin Vejman
- 申请人: Cisco Technology, Inc.
- 申请人地址: US CA San Jose
- 专利权人: Cisco Technology, Inc.
- 当前专利权人: Cisco Technology, Inc.
- 当前专利权人地址: US CA San Jose
- 代理机构: Behmke Innovation Group LLC
- 代理商 James M. Behmke; Jonathon P. Western
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; H04L9/40 ; G06F21/55 ; H04L9/32 ; G06F21/44 ; G06F21/52
摘要:
In one embodiment, a service receives traffic telemetry data regarding encrypted traffic sent by an endpoint device in a network. The service analyzes the traffic telemetry data to infer characteristics of an application on the endpoint device that generated the encrypted traffic. The service receives, from a monitoring agent on the endpoint device, application telemetry data regarding the application. The service determines that the application is evasive malware based on the characteristics of the application inferred from the traffic telemetry data and on the application telemetry data received from the monitoring agent on the endpoint device. The service initiates performance of a mitigation action in the network, after determining that the application on the endpoint device is evasive malware.
公开/授权文献
信息查询