The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Apr. 11, 2023

Filed:

Jun. 01, 2020
Applicant:

Splunk, Inc., San Francisco, CA (US);

Inventor:

John Clifton Pierce, San Jose, CA (US);

Assignee:

SPLUNK INC., San Francisco, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/00 (2013.01); H04L 9/40 (2022.01); H04L 43/0888 (2022.01); H04L 41/142 (2022.01); H04L 43/0894 (2022.01);
U.S. Cl.
CPC ...
H04L 63/1416 (2013.01); H04L 41/142 (2013.01); H04L 43/0888 (2013.01); H04L 63/1441 (2013.01); H04L 43/0894 (2013.01); H04L 2463/121 (2013.01);
Abstract

Various embodiments of the present invention set forth techniques for security monitoring of a network connection, including analyzing network traffic data for a network connection associated with a computing device, identifying one or more network traffic metrics for the network connection based on the network traffic data, determining that the network connection corresponds to at least one network connection profile based on the one or more network traffic metrics, detecting a potential security threat for the network connection based on the one or more network traffic metrics and the at least one network connection profile, and initiating a mitigation action with respect to the network connection in response to detecting the potential security threat. Advantageously, the techniques allow detecting potential security threats based on network traffic metrics and categorizations, without requiring monitoring of the content or the total volume of all traffic exchanged via the connection.


Find Patent Forward Citations

Loading…