Cisco Systems, Inc.
Passive decryption of encrypted traffic to generate more accurate machine learning training data

Last updated:

Abstract:

In one embodiment, an apparatus captures a memory dump of a device in a sandbox environment executing a malware sample. The apparatus identifies a cryptographic key based on a particular data structure in the captured memory dump. The apparatus uses the identified cryptographic key to decrypt encrypted traffic sent by the device. The apparatus labels at least a portion of the decrypted traffic sent by the device as benign. The apparatus trains a machine learning-based traffic classifier based on the at least a portion of the decrypted traffic sent by the device and labeled as benign.

Status:
Grant
Type:

Utility

Filling date:

3 Dec 2019

Issue date:

7 Dec 2021