Patent · US Active

System and method for passively identifying encrypted and interactive network sessions

US8707440B2 · kind B2 · utility

45Cited by
63References
18Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMar 22, 2010
Grant dateApr 22, 2014
Priority date
Expiry dateFeb 1, 2032

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1433
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

The system and method for passively identifying encrypted and interactive network sessions described herein may distribute a passive vulnerability scanner in a network, wherein the passive vulnerability scanner may observe traffic travelling across the network and reconstruct a network session from the observed traffic. The passive vulnerability scanner may then analyze the reconstructed network session to determine whether the session was encrypted or interactive (e.g., based on randomization, packet timing characteristics, or other qualities measured for the session). Thus, the passive vulnerability scanner may monitor the network in real-time to detect any devices in the network that run encrypted or interactive services or otherwise participate in encrypted or interactive sessions, wherein detecting encrypted and interactive sessions in the network may be used to manage changes and potential vulnerabilities in the network.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.