×

Detecting anomalous web proxy activity

  • US 7,661,136 B1
  • Filed: 12/13/2005
  • Issued: 02/09/2010
  • Est. Priority Date: 12/13/2005
  • Status: Expired due to Fees
First Claim
Patent Images

1. A method of detecting anomalous web proxy activity comprising:

  • extracting a plurality of records from a proxy log for a specified time period using a detection module implemented by a server;

    filtering the plurality of records extracted from the proxy log by the detection module to exclude records that do not include identified information, the identified information being at least an Internet Protocol (IP) address at a beginning of a uniform resource locator (URL) field and a connect instruction;

    determining, with the detection module, whether a first one of the records extracted from a web proxy log, and not excluded by the filtering, comprises suspicious web activity based on a number of distinct destination hosts to which a source connects; and

    generating an alert in response to the determination by the detection module.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×