Patent · US Active

Rule-based network-threat detection for encrypted communications

US9917856B2 · kind B2 · utility

22Cited by
39References
25Claims
0Family size

Assignee

Inventors

Key dates

Filing dateDec 23, 2015
Grant dateMar 13, 2018
Priority date
Expiry dateDec 23, 2035

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1441
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A packet-filtering system configured to filter packets in accordance with packet-filtering rules may receive data indicating network-threat indicators and may configure the packet-filtering rules to cause the packet-filtering system to identify packets comprising unencrypted data, and packets comprising encrypted data. A portion of the unencrypted data may correspond to one or more of the network-threat indicators, and the packet-filtering rules may be configured to cause the packet-filtering system to determine, based on the portion of the unencrypted data, that the packets comprising encrypted data correspond to the one or more network-threat indicators.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.