×

Systems and methods for traffic classification

  • US 10,050,986 B2
  • Filed: 02/08/2017
  • Issued: 08/14/2018
  • Est. Priority Date: 06/14/2013
  • Status: Active Grant
First Claim
Patent Images

1. A method of classifying network traffic comprising:

  • performing processing associated with monitoring, with a domain identification module in communication with a processor circuit and a network, network traffic;

    performing processing associated with comparing, with a traffic classification module in communication with the processor circuit and the domain identification module, the network traffic with a control protocol template (CPT) stored in a database in communication with the domain identification module and the processor circuit;

    when a similarity between the monitored traffic and the CPT exceeds a match threshold, performing processing associated with associating, with the domain identification module, the monitored traffic with the CPT;

    when the similarity between the monitored traffic and the CPT does not exceed the match threshold, performing processing associated with identifying, with the traffic classification module, the monitored traffic as having an unknown classification;

    performing processing associated with monitoring, with a CPT generation module in communication with the processor circuit and the network, traffic on the network to identify malicious traffic;

    performing processing associated with clustering, with the CPT generation module, identified associated traffic into a cluster including one or more similar network requests;

    performing processing associated with generating, with the CPT generation module, a CPT associated with the cluster, the CPT including information allowing a network request similar to the one or more network requests of the cluster to be identified based on the CPT; and

    performing processing associated with combining, with the CPT generation module, the CPT with a second CPT associated with a second cluster of one or more network requests similar to the network requests associated with the CPT.

View all claims
  • 6 Assignments
Timeline View
Assignment View
    ×
    ×