Skip to content
September 16, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Technology
  • Cisco uses machine learning to Detect Malware in Encrypted Traffic
  • Technology

Cisco uses machine learning to Detect Malware in Encrypted Traffic

Do Son January 15, 2018 2 minutes read
Encrypted Traffic Analysis
Add Daily CyberSecurity as a preferred source on Google

On January 10, 2018, Cisco officially released its Encrypted Traffic Analysis (ETA) software platform to examine network metadata and discover malware-delivered network traffic packets as early as possible. As early as June 2017, Cisco added ETA software capabilities to enterprise-class production equipment, piloting it on a small scale. Now that the official release, the ETA system can be used on all major data centers and platforms like Cisco Cloud Services Routers, Integrated Routers and branch offices, all using Cisco Enterprise Routing Services.

Cisco’s ETA system helps businesses monitor encrypted, malformed network traffic without requiring decryption, preventing malware from spreading until users open malicious Web pages or software. Traditional monitoring software can not analyze encrypted data traffic and therefore can not meet the monitoring requirements under encrypted network conditions. If some enterprises need to encrypt all the network data for some special reasons, the traditional traffic monitoring software cannot meet the needs of enterprise security. ETA systems use multi-tier machine learning to distinguish between “good” and “bad” network traffic.

ETA system according to the order of the original data packet, time, length to find out whether the data content is abnormal, but also in the encrypted data packets in the network load, the implementation of the data packet monitoring process. The entire process required the use of StealthWatch software to compare the difference between the metadata in the malicious traffic and the normal traffic data to determine if it was malicious network traffic. This can be a seamless link for organizations that use Cisco equipment over their existing network infrastructure.

Reference &Image source: Cisco

Related coverage

  • Apple Planning $350 Smart Display (2026) and Robotic Desktop Device (2027), Manufactured in Vietnam
  • Self-Hosting No Longer Free: GitHub Introduces New $0.002/Min Platform Fee for Actions
  • Microsoft to Pay Publishers for AI Content in New Pilot Program
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our tech and OS security coverage helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Stay Ahead of the Threat

Join security professionals receiving zero-hour CVE alerts, PoC updates, and threat analysis directly to their inbox.

No spam. One actionable email per week. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: cisco Encrypted Traffic Analysis

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-87886
    Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin...
    Admin intel📅 Updated: Sep 16, 2026
  • CVE-2026-87827CVSS 10.0
    Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-78006CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-39364
    Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-27540CVSS 9.0
    Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-76461CVSS 9.8
    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an...
    CISA KEV📅 Added to KEV: Sep 14, 2026
  • CVE-2026-51990
    A critical remote code execution vulnerability in Sogou Input Method, one of the most widely used Chinese-language input...
    Admin intel📅 Updated: Sep 12, 2026
  • CVE-2026-85706CVSS 10.0
    GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-73807CVSS 9.8
    The mySCADA myPRO Manager command API does not properly enforce authentication for...
  • CVE-2026-81855CVSS 9.1
    A hardcoded cryptographic client authentication key vulnerability exists in the robot testing...
  • CVE-2026-78225CVSS 9.0
    A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller...
  • CVE-2026-61560CVSS 9.8
    `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version...
  • CVE-2026-73437CVSS 9.6
    On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP)...
  • CVE-2026-61559CVSS 9.6
    `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version...
  • CVE-2026-91939CVSS 9.8
    Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without...
  • CVE-2026-61568CVSS 9.6
    `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to...
  • CVE-2026-66887CVSS 9.6
    The affected products are missing authorization on state-changing CGIs and session checks...
  • CVE-2026-66890CVSS 9.6
    The affected products use hard-coded credentials, which could allow remote access to...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.