×

Using a probability-based model to detect random content in a protocol field associated with network traffic

  • US 9,680,832 B1
  • Filed: 12/30/2014
  • Issued: 06/13/2017
  • Est. Priority Date: 12/30/2014
  • Status: Active Grant
First Claim
Patent Images

1. A device, comprising:

  • one or more processors to;

    receive network traffic;

    identify candidate text included in a communication protocol field associated with the network traffic;

    identify a set of candidate strings included in the candidate text;

    determine whether a candidate string, of the set of candidate strings, matches a model string,the model string being included in a model text associated with the communication protocol field,the model text being stored in a data structure;

    identify a set of characters that precedes or follows the candidate string in the candidate text;

    determine, using the data structure, a frequency with which the set of characters precedes or follows the candidate string;

    determine whether the candidate text includes random text based on determining whether the candidate string matches the model string or based on the frequency; and

    execute a policy to perform an action on the network traffic based on determining whether the candidate text includes random text.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×