Patent attributes
A system, method, and computer-readable media are described for identifying a split-flow communications session occurring over two or more incompatible communications protocols. A data stream governed by a first communications protocol is associated with a device or end device by comparing information in the data packet headers with information in a device database that matches devices with the header characteristics such as an IP address. A second data stream governed by a second incompatible communications protocol is similarly associated with the same target endpoint or device. The two incompatible data streams may then be evaluated as a single split-flow communications session for malicious content, or for other purposes. If malicious content is detected, corrective policies may be implemented on the split-flow communications session to protect the device from the malicious content.