Cisco Systems, Inc.
Instant network threat detection system

Last updated:

Abstract:

In one embodiment, a network security service forms, for each of a plurality of malware classes, a feature vector descriptor for the malware class. The service uses the feature vector descriptors for the malware classes and a symmetric mapping function to generate a training dataset having both positively and negatively labeled feature vectors. The service trains, using the training dataset, an instant threat detector to determine whether telemetry data for a particular traffic flow is within a threshold of similarity to a feature vector descriptor for a new malware class that was not part of the plurality of malware classes.

Status:
Grant
Type:

Utility

Filling date:

19 Dec 2018

Issue date:

28 Jun 2022