Cisco Systems, Inc.
Instant network threat detection system
Last updated:
Abstract:
In one embodiment, a network security service forms, for each of a plurality of malware classes, a feature vector descriptor for the malware class. The service uses the feature vector descriptors for the malware classes and a symmetric mapping function to generate a training dataset having both positively and negatively labeled feature vectors. The service trains, using the training dataset, an instant threat detector to determine whether telemetry data for a particular traffic flow is within a threshold of similarity to a feature vector descriptor for a new malware class that was not part of the plurality of malware classes.
Status:
Grant
Type:
Utility
Filling date:
19 Dec 2018
Issue date:
28 Jun 2022