The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jan. 29, 2019

Filed:

Aug. 04, 2016
Applicant:

Cisco Technology, Inc., San Jose, CA (US);

Inventors:

Lukas Machlica, San Jose, CA (US);

Michal Sofka, San Jose, CA (US);

Assignee:

Cisco Technology, Inc., San Jose, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); H04L 12/66 (2006.01); H04L 12/24 (2006.01); H04L 29/08 (2006.01); G06N 99/00 (2010.01); G06F 17/16 (2006.01);
U.S. Cl.
CPC ...
H04L 63/1425 (2013.01); G06F 17/16 (2013.01); G06N 99/005 (2013.01); H04L 12/66 (2013.01); H04L 41/12 (2013.01); H04L 67/12 (2013.01);
Abstract

Systems and methods of the present disclosure provide technology to identify when network-connected devices are likely infected with malware. Network communications are be monitored during a specific time window and a graph is created for a conditional random field (CRF) model. Vertices of the graph represent devices connected to the network and an edge between two vertices indicates that one or more network communications occurred between two devices represented by the two vertices during the time window. Network devices can report observations about network behavior during the time window and the observations can be used as input for the CRF model. The CRF model can then be used to determine infection-status values for the network devices.


Find Patent Forward Citations

Loading…