IP Library Granted Patent US 9,692,730
Granted Patent B2
US 9,692,730 · App. 13/358,476 · Granted Jun 27, 2017

System and method for decoding traffic over proxy servers

Inventor: Naomi Frid (Modi'in, IL)
Assignee: VERINT SYSTEMS LTD.
H04L63/0407H04L63/0281H04L63/30H04L63/306
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,692,730
App. No.
13/358,476
Granted
Jun 27, 2017
Kind
B2
Abstract

Methods and systems for applying surveillance to client computers that communicate via proxy servers. A decoding system accepts communication packets from a communication network. Based on the received packets, the decoding system identifies that a certain client computer conducts a communication session with a target server via a proxy server. The decoding system processes the packets so as to correlate the identity of the client computer with the identity of the target server. The correlated identities may comprise, for example, Internet Protocol (IP) addresses or Uniform Resource Locators (URLs).

Claims (18)

1. A method, comprising:

receiving communication packets from a communication network;

identifying at least some of the communication packets as belonging to a communication session that is conducted between a client computer and a target server via a proxy server;

modifying at least some of the identified communication packets to represent an artificial direct session between the client computer and the target server, which does not traverse the proxy server;

decoding the modified packets so as to reconstruct the artificial direct session; and

presenting the reconstructed artificial direct session to a surveillance operator.

2. The method according to claim 1 , further comprising correlating a first identity of the client computer with a second identity of the target server, wherein an indication of the second identity is encoded in one or more of the communication packets that are exchanged between the client computer and the proxy server, and wherein correlating the first identity with the second identity comprises decoding the indication.

3. The method according to claim 1 , further comprising correlating a first identity of the client computer with a second identity of the target server, wherein the client computer communicates with the proxy server over a first Transmission Control Protocol (TCP) tunnel, wherein the proxy server communicates with the target server over a second TCP tunnel, and wherein correlating the first identity with the second identity comprises decoding at least one of the first and second TCP tunnels.

4. The method according to claim 1 , wherein the proxy server comprises a Hyper-Text Transfer Protocol (HTTP) proxy server.

5. The method according to claim 1 , wherein the proxy server operates in accordance with a SOCKS protocol.

6. Apparatus, comprising:

a network interface, which is configured to receive communication packets from a communication network; and

a hardware processor, which is configured to identify at least some of the communication packets as belonging to a communication session that is conducted between a client computer and a target server via a proxy server,

wherein the processor is configured to modify at least some of the identified communication packets to represent an artificial direct session between the client computer and the target server, which does not traverse the proxy server, to decode the modified packets so as to reconstruct the artificial session, and to present the reconstructed artificial direct session to a surveillance operator.

7. The apparatus according to claim 6 , wherein the processor is further configured to correlate a first identity of the client computer with a second identity of the target server, wherein an indication of the second identity is encoded in one or more of the communication packets that are exchanged between the client computer and the proxy server, and wherein the processor is configured to correlate the first identity with the second identity by decoding the indication.

8. The apparatus according to claim 6 , wherein the processor is further configured to correlate a first identity of the client computer with a second identity of the target server, wherein the client computer communicates with the proxy server over a first Transmission Control Protocol (TCP) tunnel, wherein the proxy server communicates with the target server over a second TCP tunnel, and wherein the processor is configured to correlate the first identity with the second identity by decoding at least one of the first and second TCP tunnels.

9. The apparatus according to claim 6 , wherein the proxy server comprises a Hyper-Text Transfer Protocol (HTTP) proxy server.

10. The apparatus according to claim 6 , wherein the proxy server operates in accordance with a SOCKS protocol.

Assignments (3)
CHANGE OF NAME Recorded Apr 20, 2022
From: VERINT SYSTEMS LTD.
To: COGNYTE TECHNOLOGIES ISRAEL LTD
Reel/Frame 059710/0742 →
CHANGE OF NAME Recorded Dec 23, 2021
From: VERINT SYSTEMS LTD.
To: COGNYTE TECHNOLOGIES ISRAEL LTD
Reel/Frame 060751/0532 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2014
From: FRID, NAOMI
To: VERINT SYSTEMS LTD.
Reel/Frame 034030/0383 →
Priority Claims (1)
IL 210899 · Jan 27, 2011 · national
Continuity (1)
Related Publication 20120215927A1 · Aug 23, 2012