Using a probability-based model to detect random content in a protocol field associated with network traffic
Abstract
A device may receive network traffic. The device may identify candidate text included in a protocol field associated with the network traffic. The device may identify a set of candidate strings included in the candidate text. The device may identify a set of characters that precedes or follows a candidate string, of the set of candidate strings, in the candidate text. The device may determine, using a data structure, a frequency with which the set of characters precedes or follows the candidate string. The device may determine whether the candidate text includes random text based on the frequency. The device may perform an action on the network traffic based on determining whether the candidate text includes random text.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A method comprising:
identifying, by a device, candidate text included in a protocol field associated with network traffic; determining, by the device, that the candidate text includes random text based on a probability-based model; and executing, by the device, a policy with regards to the network traffic based on determining that the candidate text includes random text.
22 . The method of claim 21 , further comprising:
identifying a set of candidate strings that are included in the candidate text,
where determining that the candidate text includes random text comprises:
determining that the candidate text includes random text based on the probability-based model and the set of candidate strings.
23 . The method of claim 21 , further comprising:
determine that a candidate string, of the candidate text, is not included in a model text,
where determining that the candidate text includes random text comprises:
determining that the candidate text includes random text based on the probability-based model and based on determining that the candidate string is not included in the model text.
24 . The method of claim 21 , further comprising:
identifying one or more characters that precede or follow a candidate string in the candidate text,
where determining that the candidate text includes random text comprises:
determining that the candidate text includes random text based on the probability-based model and the one or more characters.
25 . The method of claim 21 , further comprising:
determining a frequency based on the candidate text,
where determining that the candidate text includes random text comprises:
determining that the candidate text includes random text based on the probability-based model and the frequency.
26 . The method of claim 21 , further comprising:
intercepting the network traffic before identifying the candidate text,
the network traffic being intended for a server device that is different from the device.
27 . The method of claim 21 , where the protocol field is a Hypertext Transfer Protocol (HTTP) host field.
28 . The method of claim 21 , further comprising:
selecting to read the candidate text from the protocol field by using a protocol identification architecture.
29 . The method of claim 21 , further comprising:
determining that different candidate text does not include random text; and adding the different candidate text to model text based on determining that different candidate text does not include random text.
30 . A system comprising:
one or more processors to:
identify candidate text included in a protocol field associated with network traffic;
determine that the candidate text includes random text; and
execute a policy with regards to the network traffic based on determining that the candidate text includes random text.
31 . The system of claim 30 ,
where the one or more processors are further to:
identify a candidate string included the candidate text; and
determine that the candidate string is not included in model text, and
where, when determining that the candidate text includes random text, the one or more processors are to:
determine that the candidate text includes random text based on determining that the candidate string is not included in the model text.
32 . The system of claim 30 ,
where the one or more processors are further to:
identify candidate strings based on the candidate text; and
determine a proportion of the candidate strings that are included in model text, and
where, when determining that the candidate text includes random text, the one or more processors are to:
determine that the candidate text includes random text based on the proportion of the candidate strings.
33 . The system of claim 30 , where the one or more processors are further to:
determine a proportion of the network traffic that is malicious based on determining that the candidate text includes random text, and send a duplicate of the proportion to another device.
34 . The system of claim 30 , where, when determining that the candidate text includes random text, the one or more processors are to:
determine that the candidate text includes random text based on a probability-based model.
35 . The system of claim 34 , where the one or more processors are further to:
train the probability-based model by using live network traffic.
36 . A non-transitory computer-readable medium storing instructions, the instructions comprising:
one or more instructions that, when executed by at least one processor, cause the at least one processor to:
identify candidate text included in a protocol field associated with network traffic;
determine that the candidate text includes random text based on a probability-based model; and
execute a policy with regards to the network traffic based on determining that the candidate text includes random text.
37 . The non-transitory computer-readable medium of claim 36 , where the instructions further comprise:
one or more instructions that, when executed by the at least one processor, cause the at least one processor to:
intercept the network traffic before identifying the candidate text,
the network traffic being intended for a server device that is different from a device that includes the at least one processor.
38 . The non-transitory computer-readable medium of claim 36 , where the protocol field is a Hypertext Transfer Protocol (HTTP) host field.
39 . The non-transitory computer-readable medium of claim 36 , where the instructions further comprise:
one or more instructions that, when executed by the at least one processor, cause the at least one processor to:
select to read the candidate text from the protocol field by using a protocol identification architecture.
40 . The non-transitory computer-readable medium of claim 36 ,
where the instructions further comprise:
one or more instructions that, when executed by the at least one processor, cause the at least one processor to:
determine a frequency based on the candidate text and model text, and
where one or more instructions to determine that the candidate text includes random text comprise:
one or more instructions that, when executed by the at least one processor, cause the at least one processor to:
determining that the candidate text includes random text based on the probability-based model and the frequency.Join the waitlist — get patent alerts
Track US2017346827A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.