Close Menu
  • Home
  • AI
  • Big Data
  • Cloud Computing
  • iOS Development
  • IoT
  • IT/ Cybersecurity
  • Tech
    • Nanotechnology
    • Green Technology
    • Apple
    • Software Development
    • Software Engineering

Subscribe to Updates

Get the latest technology news from Bigteetechhub about IT, Cybersecurity and Big Data.

    What's Hot

    Nanoscale Ceramic Film Boosts High-Frequency Performance

    November 7, 2025

    Hackers target massage parlour clients in blackmail scheme

    November 7, 2025

    Turning Security into Profit: Advanced VMware vDefend Opportunities for Cloud Service Providers

    November 7, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Big Tee Tech Hub
    • Home
    • AI
    • Big Data
    • Cloud Computing
    • iOS Development
    • IoT
    • IT/ Cybersecurity
    • Tech
      • Nanotechnology
      • Green Technology
      • Apple
      • Software Development
      • Software Engineering
    Big Tee Tech Hub
    Home»IoT»Powerful Upgrade to Cisco’s ML Detection Engine
    IoT

    Powerful Upgrade to Cisco’s ML Detection Engine

    big tee tech hubBy big tee tech hubSeptember 13, 2025004 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email Telegram WhatsApp
    Follow Us
    Google News Flipboard
    Powerful Upgrade to Cisco’s ML Detection Engine
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    In March 2024, we introduced SnortML, an innovative machine learning engine for the Snort intrusion prevention (IPS) system. SnortML was developed to tackle the limitations of static signature-based methods by proactively identifying exploits as they evolve rather than reacting to newly discovered exploits. After its release, we’ve continued to invest in this capability to help customers act on global threat data fast enough to stop rapidly spreading threats.

    Why SnortML?

    At the end of 2020, the list of Common Vulnerabilities and Exposures (CVEs) stood at 18,375. By 2024, that number had skyrocketed to over 40,000. While traditional intrusion prevention systems relying on static signatures are effective against known threats, they often struggle to detect new or evolving exploits.

    SnortML addresses these challenges with state-of-the-art neural network algorithms while ensuring complete data privacy by running entirely on the device. The machine-learning engine runs entirely on firewall hardware, keeping every packet within the network perimeter. Decisions are computed locally in real time, without the need to send data to the cloud or expose it to third-party analytics. This approach satisfies strict data-residency, privacy, and compliance requirements, especially for critical infrastructure and sensitive environments.

    This is why our engineers at Cisco Talos developed SnortML. Leveraging deep neural networks trained on extensive datasets, SnortML identifies patterns associated with exploit attempts, even those it hasn’t encountered before. When we launched SnortML, we started with protection for SQL Injection, one of the most common and impactful attack vectors.

    Exciting New Developments in 2025

    What Is Cross-Site Scripting (XSS)?

    Cross-Site Scripting (XSS) is a pervasive web vulnerability that allows attackers to inject malicious client-side scripts into web pages. These scripts execute in the victim’s browser, enabling attackers to compromise user data, hijack sessions, or deface websites, leading to significant security risks.

    This can occur in two primary ways: Stored XSS, where malicious JavaScript is sent to a vulnerable web application and stored on the server, later delivered and executed when a user accesses content containing it; or Reflected XSS, where an attacker crafts a malicious script, often in a link, which when clicked, is “reflected” by the web application back to the victim’s browser for immediate execution without being stored on the server.

    In both cases, the malicious XSS payload typically appears in the HTTP request query or body. SnortML blocks malicious XSS scripts sent for storage on a vulnerable server (Stored XSS). It also blocks requests from malicious links intended to reflect a script back at a victim (Reflected XSS), preventing the malicious response. By scanning HTTP request queries and bodies, SnortML effectively addresses all XSS threats.

    How SnortML Protects Against XSS

    Let’s dive into an example to illustrate how SnortML stops XSS attacks in real-time. In this case, we’ll use CVE-2024-25327, a recently disclosed Cross-Site Scripting (XSS) vulnerability found in Justice Systems FullCourt Enterprise v.8.2. This particular CVE allows a remote attacker to execute arbitrary code by injecting malicious scripts through the formatCaseNumber parameter within the application’s Citation search function. For our demonstration, no static signature has been created/enabled for this CVE yet.

    The screenshot below, taken from the Cisco Secure Firewall Management Center (FMC), clearly illustrates SnortML in action. It shows the malicious input targeting the formatCaseNumber parameter. SnortML’s advanced machine learning engine immediately identified the anomalous behavior characteristic of an XSS exploit, even though this specific CVE (CVE-2024-25327) had no static signature. The FMC log confirms that SnortML successfully detected and blocked the attack in real-time, preventing the malicious script from ever reaching the target application.

    FMC event log showing the XSS attack blocked by SnortMLFMC event log showing the XSS attack blocked by SnortML
    Fig. 1: FMC event log showing the XSS attack blocked by SnortML

    The Road Ahead for SnortML

    SnortML is transforming the landscape of exploit detection and prevention. First with SQL Injection protection, and now with the recent additions of Command Injection and XSS protection, SnortML continues to strengthen its defenses against today’s most critical threats. And this is just the beginning.

    Coming soon, SnortML will feature a fast pattern engine and a least recently used (LRU) cache, dramatically increasing threat detection speed and efficiency. These enhancements will pave the way for even broader exploit detection capabilities.

    Stay tuned for more updates as we continue to advance SnortML and deliver even greater security innovations.

    Ready to Explore Further?

    Check out the Cisco Talos video explaining how SnortML uses machine learning to stop zero-day attacks.

    Want to dive deeper into Cisco firewalls? Sign up for the Cisco Secure Firewall Test Drive, an instructor-led, four-hour hands-on course where you’ll experience the Cisco firewall technology in action and learn about the latest security challenges and attacker techniques.


    We’d love to hear what you think! Ask a question and stay connected with Cisco Security on social media.

    Cisco Security Social Media

    LinkedIn
    Facebook
    Instagram
    X

    Share:





    Source link

    Ciscos Detection Engine powerful upgrade
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    tonirufai
    big tee tech hub
    • Website

    Related Posts

    Cisco AI Networking for Developers: What’s New

    November 6, 2025

    Developer innovation at the center at GitHub Universe 2025

    November 6, 2025

    IoT Now Contract Win List – October 2025

    November 5, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Nanoscale Ceramic Film Boosts High-Frequency Performance

    November 7, 2025

    Hackers target massage parlour clients in blackmail scheme

    November 7, 2025

    Turning Security into Profit: Advanced VMware vDefend Opportunities for Cloud Service Providers

    November 7, 2025

    Developers decode their journeys from app ideas to App Store

    November 6, 2025
    About Us
    About Us

    Welcome To big tee tech hub. Big tee tech hub is a Professional seo tools Platform. Here we will provide you only interesting content, which you will like very much. We’re dedicated to providing you the best of seo tools, with a focus on dependability and tools. We’re working to turn our passion for seo tools into a booming online website. We hope you enjoy our seo tools as much as we enjoy offering them to you.

    Don't Miss!

    Nanoscale Ceramic Film Boosts High-Frequency Performance

    November 7, 2025

    Hackers target massage parlour clients in blackmail scheme

    November 7, 2025

    Subscribe to Updates

    Get the latest technology news from Bigteetechhub about IT, Cybersecurity and Big Data.

      • About Us
      • Contact Us
      • Disclaimer
      • Privacy Policy
      • Terms and Conditions
      © 2025 bigteetechhub.All Right Reserved

      Type above and press Enter to search. Press Esc to cancel.