Inline detection of encrypted malicious network sessions
US12395523B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Apr 30, 2024 |
| Grant date | Aug 19, 2025 |
| Priority date | — |
| Expiry date | Apr 30, 2044 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L63/0428
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
An inline malicious traffic detector captures handshake messages in a session with a security protocol. The inline malicious traffic detector comprises a classifier that generates a verdict for the session indicating malicious or benign. The classifier is trained on labelled sessions using custom features generated from handshake messages. Based on determining that the session is malicious using features of the handshake messages, the inline malicious traffic detector blocks the session.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.