IP Library Granted Patent US 9,930,055
Granted Patent B2
US 9,930,055 · App. 15/228,297 · Granted Mar 27, 2018

Unwanted tunneling alert system

Inventors: Juan Ricafort (New York, NY); Harkirat Singh (New York, NY); Philip Martin (San Jose, CA)
Assignee: Palantir Technologies Inc.
H04L63/1416H04L61/2007H04L63/0272H04L63/1425H04L63/1441G06F21/556
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,930,055
App. No.
15/228,297
Granted
Mar 27, 2018
Kind
B2
Abstract

Various systems and methods are provided that detect malicious network tunneling. For example, VPN logs and data connection logs may be accessed. The VPN logs may list client IP addresses that have established a VPN connection with an enterprise network. The data connection logs may list client IP addresses that have requested connections external to the enterprise network and remote IP addresses to which connections are requested. The VPN logs and the data connection logs may be parsed to identify IP addresses that are present in the VPN logs as a client IP address and in the data connection logs as a remote IP address. If an IP address is so present, user data and traffic data associated with the IP address may be retrieved to generate a risk score. If the risk score exceeds a threshold, an alert to be displayed in a GUI is generated.

Claims (45)

1. A computing system configured to detect and handle malicious network tunneling, the computing system comprising:

a computer processor; and

a non-transitory computer readable storage medium storing program instructions configured for execution by the computer processor in order to cause the computing system to:

access a virtual private network (VPN) log including a listing of one or more client IP addresses assigned to a corresponding one or more remote users granted access to a network;

access a data connection log including a listing of one or more remote IP addresses requested via the network;

identify a first IP address included in the VPN log and in the data connection log;

generate a risk score based on at least traffic data associated with the first IP address, the risk score at least partly indicative of a likelihood that the traffic data includes one or more malicious tunneling connections; and

terminate a first connection if the risk score exceeds a threshold value.

2. The computing system of claim 1 , wherein the risk score is based on at least one of a mismatch between a geographic location of a computing device associated with the first IP address and a geographic location of the network, employment title of a user associated with the first IP address, access rights of the user associated with the first IP address, a time between when a VPN connection associated with the first IP address is established and when a tunneled connection associated with the first IP address is established, an amount of data transferred using the tunneled connection, or a type of uniform resource locator associated with the tunneled connection.

3. The computing system of claim 1 , wherein, in connection with a determination that the data connection log indicates that a tunneled connection is established over a first port, the generated risk score is lower than if the tunneled connection is established over a second port.

4. The computing system of claim 1 , wherein a VPN connection and a tunneled connection between a computing device associated with the first IP address and the network are encrypted.

5. The computing system of claim 4 , wherein the first connection is the tunneled connection.

6. The computing system of claim 1 , wherein the non-transitory computer readable storage medium further stores program instructions that cause the computing system to:

generate an alert if the risk score exceeds a threshold value; and

process feedback received regarding the generated alert, wherein the feedback affects generation of a second risk score in connection with an identification of a second IP address listed in both the VPN log and in the data connection log having one or more characteristics in a corresponding second traffic data in common with the traffic data associated with the first IP address.

7. The computing system of claim 6 , wherein the alert comprises information that at least partly indicates the traffic data that contributed to the risk score exceeding the threshold value.

8. A computer-implemented method comprising:

as implemented by one or more computer systems comprising computer hardware and memory, the one or more computer systems configured with specific executable instructions,

accessing a first log including a listing of one or more source addresses assigned to a corresponding one or more remote users granted access to a network;

accessing a second log including a listing of one or more destination addresses requested via the network;

identifying a first address included in both the first log and in the second log;

generating a risk score based on at least traffic data associated with the first address; and

terminating a first connection if the risk score exceeds a threshold value.

9. The computer-implemented method of claim 8 , wherein the risk score is based on at least one of a mismatch between a geographic location of a computing device associated with the first address and a geographic location of the network, employment title of a user associated with the first address, access rights of the user associated with the first address, a time between when a VPN connection associated with the first address is established and when a tunneled connection associated with the first address is established, an amount of data transferred using the tunneled connection, or a type of uniform resource locator associated with the tunneled connection.

10. The computer-implemented method of claim 8 , wherein, in connection with a determination that the second log indicates that a tunneled connection is established over a first port, the generated risk score is lower than if the tunneled connection is established over a second port.

11. The computer-implemented method of claim 8 , wherein a VPN connection and a tunneled connection between a computing device associated with the first address and the network are encrypted.

12. The computer-implemented method of claim 8 , further comprising:

generating an alert if the risk score exceeds a threshold value receiving feedback regarding the generated alert; and

in connection with an identification of a second address listed in both the first log and in the second log, generating a second risk score based on the received feedback.

13. The computer-implemented method of claim 12 , wherein the alert comprises information that at least partly indicates the traffic data that contributed to the risk score exceeding the threshold value.

14. The computer-implemented method of claim 12 , further comprising generating a graphical representation of the alert for display in a user interface.

15. A non-transitory computer-readable medium comprising one or more program instructions recorded thereon, the instructions configured for execution by a computing system comprising one or more processors in order to cause the computing system to:

access a first log including a listing of one or more source addresses assigned to a corresponding plurality of remote users granted access to a network;

access a second log including a listing of one or more destination addresses requested via the network;

identify a first address included in both the first log and in the second log;

generate a risk score based on at least traffic data associated with the first address; and

terminate a first connection if the risk score exceeds a threshold value.

16. The medium of claim 15 , wherein the risk score is based on at least one of a mismatch between a geographic location of a computing device associated with the first address and a geographic location of the network, employment title of a user associated with the first address, access rights of the user associated with the first address, a time between when a VPN connection associated with the first address is established and when a tunneled connection associated with the first address is established, an amount of data transferred using the tunneled connection, or a type of uniform resource locator associated with the tunneled connection.

17. The medium of claim 15 , wherein, in connection with a determination that the second log indicates that a tunneled connection is established over a first port, the generated risk score is lower than if the tunneled connection is established over a second port.

18. The medium of claim 15 , wherein the instructions are further configured to cause the computing system to:

generate an alert if the risk score exceeds a threshold value;

process feedback received regarding the generated alert; and

in connection with an identification of a second address listed in both the first log and in the second log, generate a second risk score based on the processed feedback.

19. The medium of claim 18 , wherein the alert comprises information that at least partly indicates the traffic data that contributed to the risk score exceeding the threshold value.

20. The medium of claim 18 , wherein the instructions are further configured to cause the computing system to generate a graphical representation of the alert for display in a user interface.

Assignments (8)
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENTS Recorded Jul 3, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0640 →
SECURITY INTEREST Recorded Jul 3, 2022
From: PALANTIR TECHNOLOGIES INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0506 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY LISTED PATENT BY REMOVING APPLICATION NO. 16/832267 FROM THE RELEASE OF SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 052856 FRAME 0382. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 26, 2021
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 057335/0753 →
SECURITY INTEREST Recorded Jun 4, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 052856/0817 →
RELEASE OF SECURITY INTEREST Recorded Jun 4, 2020
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 052856/0382 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 051713/0149 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: ROYAL BANK OF CANADA, AS ADMINISTRATIVE AGENT
Reel/Frame 051709/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 7, 2018
From: RICAFORT, JUAN; SINGH, HARKIRAT; MARTIN, PHILIP
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 044858/0968 →
Continuity (3)
Continuation 14823935 · Aug 11, 2015
Provisional Application 62036999 · Aug 13, 2014
Related Publication 20160344756A1 · Nov 24, 2016