Cisco Systems, Inc.
Passive decryption of encrypted traffic to generate more accurate machine learning training data
Last updated:
Abstract:
In one embodiment, an apparatus captures a memory dump of a device in a sandbox environment executing a malware sample. The apparatus identifies a cryptographic key based on a particular data structure in the captured memory dump. The apparatus uses the identified cryptographic key to decrypt encrypted traffic sent by the device. The apparatus labels at least a portion of the decrypted traffic sent by the device as benign. The apparatus trains a machine learning-based traffic classifier based on the at least a portion of the decrypted traffic sent by the device and labeled as benign.
Status:
Grant
Type:
Utility
Filling date:
3 Dec 2019
Issue date:
7 Dec 2021