×

Automatic detection of reverse tunnels

  • US 8,151,348 B1
  • Filed: 06/30/2004
  • Issued: 04/03/2012
  • Est. Priority Date: 06/30/2004
  • Status: Active Grant
First Claim
Patent Images

1. A method of detecting a covert communications channel in a network, comprising:

  • monitoring in real-time a plurality of packets in said network, each said packet belonging to a packet flow having a flow identifier;

    classifying each said packet into a first category if said packet meets a first criterion indicative of the presence of said covert communications channel and into a second category otherwise, wherein said classifying comprises using one or more tests; and

    for each of said packets classified into said first category, probing said packet in real-time, wherein said probing comprises re-classifying each said packet into a third category if said packet meets a second criterion indicative of said covert communications channel,wherein said re-classifying comprises using one or more additional tests;

    wherein said covert communications channel is a reverse tunnel; and

    wherein said classifying comprises randomly selecting according to a frequency distribution a subset of the one or more tests to apply to each said respective packet.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×