×

UNWANTED TUNNELING ALERT SYSTEM

  • US 20160344756A1
  • Filed: 08/04/2016
  • Published: 11/24/2016
  • Est. Priority Date: 08/13/2014
  • Status: Active Grant
First Claim
Patent Images

1. A computing system configured to detect and handle malicious network tunneling, the computing system comprising:

  • a computer processor; and

    a non-transitory computer readable storage medium storing program instructions configured for execution by the computer processor in order to cause the computing system to;

    access a virtual private network (VPN) log including a listing of one or more client IP addresses assigned to a corresponding one or more remote users;

    access a data connection log including a listing of one or more remote IP addresses requested via the network;

    identify a first IP address included in the VPN log and in the data connection log;

    generate a risk score based on at least traffic data associated with the first IP address, the risk score at least partly indicative of a likelihood that the traffic data includes one or more malicious tunneling connections; and

    terminate a first connection if the risk score exceeds a threshold value.

View all claims
  • 8 Assignments
Timeline View
Assignment View
    ×
    ×