US2023006936A1PendingUtilityA1

Intelligent dataflow-based service discovery and analysis

Assignee: YAHOO AD TECH LLCPriority: Sep 4, 2019Filed: Sep 9, 2022Published: Jan 5, 2023
Est. expirySep 4, 2039(~13.1 yrs left)· nominal 20-yr term from priority
H04L 61/4511H04L 9/3236H04L 47/2483H04L 47/2441H04L 67/51H04L 63/166H04L 63/0428G06N 20/00H04L 63/0236
63
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The disclosed embodiments are directed toward monitoring and classifying encrypted network traffic. In one embodiment, a method is disclosed comprising intercepting an encrypted network request, the network request transmitted by a client device to a network endpoint; identifying a network service associated with the network endpoint based on unencrypted properties of the encrypted network request; identifying, based on the encrypted network request and a series of subsequent network requests issued by the client device, an action taken by the client device, the action comprising an activity performed during a session established with the network service; and updating a catalog of network interactions using the network service and the action.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 identifying a transaction burst, the transaction burst comprising a series of encrypted network requests issued by a client device to a network endpoint during a secure session;   extracting one or more transaction properties from the transaction burst;   assigning labels to the one or more transaction properties, a given label comprising one or more of a network service and an action; and   training a predictive model with the labels and the one or more transaction properties.   
     
     
         2 . The method of  claim 1 , the one or more transaction properties comprising a property selected from the group consisting of:
 a transmission control protocol (TCP) port;   an Internet Protocol (IP) address space;   a size of a datagram;   a response time;   a number of requests in the transaction burst; and   a network route trace.   
     
     
         3 . The method of  claim 1 , further comprising combining the one or more transaction properties to form a fingerprint prior to training the predictive model. 
     
     
         4 . The method of  claim 1 , wherein assigning labels to the one or more transaction properties comprises executing a script to access the network service. 
     
     
         5 . The method of  claim 4 , wherein assigning labels to the one or more transaction properties further comprises executing the script to perform a known action with the network service. 
     
     
         6 . The method of  claim 1 , wherein assigning labels to the one or more transaction properties comprises clustering a set of unlabeled transaction bursts and applying labels to each transaction burst within each cluster. 
     
     
         7 . The method of  claim 1 , wherein the predictive model comprises one of a neural network or support vector machine. 
     
     
         8 . A non-transitory computer-readable storage medium for tangibly storing computer program instructions capable of being executed by a computer processor, the computer program instructions defining the steps of:
 identifying a transaction burst, the transaction burst comprising a series of encrypted network requests issued by a client device to a network endpoint during a secure session;   extracting one or more transaction properties from the transaction burst;   assigning labels to the one or more transaction properties, a given label comprising one or more of a network service and an action; and   training a predictive model with the labels and the one or more transaction properties.   
     
     
         9 . The non-transitory computer-readable storage medium of  claim 8 , the one or more transaction properties comprising a property selected from the group consisting of:
 a transmission control protocol (TCP) port;   an Internet Protocol (IP) address space;   a size of a datagram;   a response time;   a number of requests in the transaction burst; and   a network route trace.   
     
     
         10 . The non-transitory computer-readable storage medium of  claim 8 , further comprising combining the one or more transaction properties to form a fingerprint prior to training the predictive model. 
     
     
         11 . The non-transitory computer-readable storage medium of  claim 8 , wherein assigning labels to the one or more transaction properties comprises executing a script to access the network service. 
     
     
         12 . The non-transitory computer-readable storage medium of  claim 11 , wherein assigning labels to the one or more transaction properties further comprises executing the script to perform a known action with the network service. 
     
     
         13 . The non-transitory computer-readable storage medium of  claim 8 , wherein assigning labels to the one or more transaction properties comprises clustering a set of unlabeled transaction bursts and applying labels to each transaction burst within each cluster. 
     
     
         14 . The non-transitory computer-readable storage medium of  claim 8 , wherein the predictive model comprises one of a neural network or support vector machine. 
     
     
         15 . A device comprising:
 a processor; and   a storage medium for tangibly storing thereon logic for execution by the processor, the logic comprising instructions for:
 identifying a transaction burst, the transaction burst comprising a series of encrypted network requests issued by a client device to a network endpoint during a secure session, 
 extracting one or more transaction properties from the transaction burst, 
 assigning labels to the one or more transaction properties, a given label comprising one or more of a network service and an action, and 
 training a predictive model with the labels and the one or more transaction properties. 
   
     
     
         16 . The device of  claim 15 , the one or more transaction properties comprising a property selected from the group consisting of:
 a transmission control protocol (TCP) port;   an Internet Protocol (IP) address space;   a size of a datagram;   a response time;   a number of requests in the transaction burst; and   a network route trace.   
     
     
         17 . The device of  claim 15 , the instructions further comprising combining the one or more transaction properties to form a fingerprint prior to training the predictive model. 
     
     
         18 . The device of  claim 15 , wherein assigning labels to the one or more transaction properties comprises executing a script to access the network service. 
     
     
         19 . The device of  claim 18 , wherein assigning labels to the one or more transaction properties further comprises executing the script to perform a known action with the network service. 
     
     
         20 . The device of  claim 15 , wherein assigning labels to the one or more transaction properties comprises clustering a set of unlabeled transaction bursts and applying labels to each transaction burst within each cluster.

Join the waitlist — get patent alerts

Track US2023006936A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.