-
公开(公告)号:US20190342173A1
公开(公告)日:2019-11-07
申请号:US15969462
申请日:2018-05-02
Applicant: Cisco Technology, Inc.
Inventor: Laurent Navarro , Jeffrey Markey , Matthew Robertson , Sunil Amin , Marc Dupont , Timothy Deeb-Swihart, II
IPC: H04L12/24 , H04L12/851 , H04L29/06
Abstract: In one example embodiment, a server obtains network flow metadata of a network flow of a host in a network. The server identifies one or more attributes of the network flow metadata. For each host group of a plurality of host groups, the server determines whether the one or more attributes of the network flow metadata satisfy one or more criteria for the host group. For each host group for which it is determined that the one or more attributes of the network flow metadata satisfy the one or more criteria, the server classifies the host as belonging to the host group.
-
公开(公告)号:US20190199753A1
公开(公告)日:2019-06-27
申请号:US15854879
申请日:2017-12-27
Applicant: Cisco Technology, Inc.
Inventor: Matthew Scott Robertson , David McGrew , Timothy David Keanini , Sunil Amin , Ellie Marie Daw
IPC: H04L29/06
Abstract: In one embodiment, a service receives captured traffic flow data regarding a traffic flow sent via a network between a first device assigned to a first network zone and a second device assigned to a second network zone. The service identifies, from the captured traffic flow data, one or more cryptographic parameters of the traffic flow. The service determines whether the one or more cryptographic parameters of the traffic flow satisfy an inter-zone policy associated with the first and second network zones. The service causes performance of a mitigation action in the network when the one or more cryptographic parameters of the traffic flow do not satisfy the inter-zone policy associated with the first and second network zones.
-
13.
公开(公告)号:US20190190794A1
公开(公告)日:2019-06-20
申请号:US15848101
申请日:2017-12-20
Applicant: Cisco Technology, Inc.
Inventor: David McGrew , Martin Rehak , Blake Harrell Anderson , Sunil Amin
CPC classification number: H04L41/28 , G06F21/55 , H04L63/14 , H04L63/1425 , H04L63/1441 , H04L63/20 , H04L67/143 , H04W12/12
Abstract: In one embodiment, a service receives data regarding administration traffic in a network associated with a remote administration session in which a control device remotely administers a client device. The service analyzes the received data to determine whether the administration traffic is authorized. The service flags the received data as authorized, based on the analysis of the received data. The service uses the data flagged as authorized to distinguish between benign traffic and malicious traffic in the network.
-
-