Cisco Systems, Inc.
Automatically detecting authorized remote administration sessions in a network monitoring system
Last updated:
Abstract:
In one embodiment, a service receives data regarding administration traffic in a network associated with a remote administration session in which a control device remotely administers a client device. The service analyzes the received data to determine whether the administration traffic is authorized. The service flags the received data as authorized, based on the analysis of the received data. The service uses the data flagged as authorized to distinguish between benign traffic and malicious traffic in the network.
Status:
Grant
Type:
Utility
Filling date:
20 Dec 2017
Issue date:
27 Jul 2021