Invention Grant
- Patent Title: Unwanted tunneling alert system
-
Application No.: US15891873Application Date: 2018-02-08
-
Publication No.: US10609046B2Publication Date: 2020-03-31
- Inventor: Juan Ricafort , Harkirat Singh , Philip Martin
- Applicant: Palantir Technologies Inc.
- Applicant Address: US CA Palo Alto
- Assignee: Palantir Technologies Inc.
- Current Assignee: Palantir Technologies Inc.
- Current Assignee Address: US CA Palo Alto
- Agency: Knobbe Martens Olson & Bear LLP
- Main IPC: G06F12/14
- IPC: G06F12/14 ; H04L29/06 ; H04L29/12 ; G06F21/55

Abstract:
Various systems and methods are provided that detect malicious network tunneling. For example, VPN logs and data connection logs may be accessed. The VPN logs may list client IP addresses that have established a VPN connection with an enterprise network. The data connection logs may list client IP addresses that have requested connections external to the enterprise network and remote IP addresses to which connections are requested. The VPN logs and the data connection logs may be parsed to identify IP addresses that are present in the VPN logs as a client IP address and in the data connection logs as a remote IP address. If an IP address is so present, user data and traffic data associated with the IP address may be retrieved to generate a risk score. If the risk score exceeds a threshold, an alert to be displayed in a GUI is generated.
Public/Granted literature
- US20180159874A1 UNWANTED TUNNELING ALERT SYSTEM Public/Granted day:2018-06-07
Information query