×

Detecting anomalous web proxy activity

  • US 8,117,655 B2
  • Filed: 12/14/2009
  • Issued: 02/14/2012
  • Est. Priority Date: 12/13/2005
  • Status: Active Grant
First Claim
Patent Images

1. A method of detecting anomalous web proxy activity comprising:

  • filtering a plurality of records from a proxy log by a detection module to exclude records that do not include identified information, the plurality of records representing proxy connections made by a proxy server, the records including connection-specific transaction information comprising one or more of a source internet protocol address, a destination internet protocol address and a uniform resource locator field, the identified information comprising an internet protocol address at a beginning of the uniform resource locator field of the plurality of records;

    calculating a number of distinct destination internet protocol addresses to which a source internet protocol address is connected from the plurality of records not excluded by the filtering;

    comparing the calculated number of distinct destination internet protocol addresses to a threshold number established for the source internet protocol address; and

    determining, based on the comparing, whether a first one of the records extracted from the web proxy log, and not excluded by the filtering, comprises suspicious web activity.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×