The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Aug. 24, 2021

Filed:

Jul. 13, 2020
Applicant:

Armis Security Ltd., Tel Aviv-Jaffa, IL;

Inventors:

Yuval Sarel, Tel Aviv, IL;

Ben Seri, Tel Aviv, IL;

Gil Ben Zvi, Hod Hasharon, IL;

Tom Hanetz, Tel Aviv, IL;

Yuval Friedlander, Petah-Tiqwa, IL;

Ron Shoham, Tel Aviv, IL;

Assignee:

Armis Security Ltd., Tel Aviv-Jaffa, IL;

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); H04L 12/24 (2006.01); G06N 7/00 (2006.01); H04L 29/08 (2006.01); G06N 20/20 (2019.01); G06N 5/04 (2006.01); G06K 9/62 (2006.01);
U.S. Cl.
CPC ...
H04L 41/142 (2013.01); G06K 9/6256 (2013.01); G06N 5/04 (2013.01); G06N 7/005 (2013.01); G06N 20/20 (2019.01); H04L 67/303 (2013.01);
Abstract

A system and method for inferring device operating systems. A method includes applying a sequence-based model to an option-types sequence in order to output a plurality of first features, wherein each of the first features is a value representing a probability that the options-type sequence is associated with a respective operating system; applying a distribution dissimilarity model to metadata field distribution data extracted from the headers of the packets sent by the device in order to output a plurality of second features, wherein the plurality of second features includes a plurality of distances, wherein each distance is based on a difference between a distribution of values of each metadata field indicated in the metadata field distribution data; and applying an operating system inference model to the plurality of first features and the plurality of second features in order to output an inferred operating system for the device.


Find Patent Forward Citations

Loading…