IP Library Granted Patent US 10,609,046
Granted Patent B2
US 10,609,046 · App. 15/891,873 · Granted Mar 31, 2020

Unwanted tunneling alert system

Inventors: Juan Ricafort (New York, NY); Harkirat Singh (New York, NY); Philip Martin (San Jose, CA)
Assignee: Palantir Technologies Inc.
H04L63/1416H04L61/2007H04L63/0272H04L63/1425H04L63/1441G06F21/556
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,609,046
App. No.
15/891,873
Granted
Mar 31, 2020
Kind
B2
Abstract

Various systems and methods are provided that detect malicious network tunneling. For example, VPN logs and data connection logs may be accessed. The VPN logs may list client IP addresses that have established a VPN connection with an enterprise network. The data connection logs may list client IP addresses that have requested connections external to the enterprise network and remote IP addresses to which connections are requested. The VPN logs and the data connection logs may be parsed to identify IP addresses that are present in the VPN logs as a client IP address and in the data connection logs as a remote IP address. If an IP address is so present, user data and traffic data associated with the IP address may be retrieved to generate a risk score. If the risk score exceeds a threshold, an alert to be displayed in a GUI is generated.

Claims (56)

1. A computing system comprising:

a computer processor; and

a non-transitory computer readable storage medium storing program instructions configured for execution by the computer processor in order to cause the computing system to:

access a first log including a listing of one or more client IP addresses corresponding to one or more remote users granted access to a network;

access a second log including a listing of one or more remote IP addresses requested via the network;

identify a first IP address included in the first log and in the second log;

generate a risk score based on data associated with the first IP address, the risk score at least partly indicative of a likelihood that a malicious tunneling connection is present; and

generate an alert in response to the risk score satisfying a threshold.

2. The computing system of claim 1 , wherein the non-transitory computer readable storage medium further stores program instructions that cause the computing system to generate user interface data that, when executed, causes a user device to display a user interface depicting the alert.

3. The computing system of claim 2 , wherein the alert and one or more other alerts are generated periodically.

4. The computing system of claim 2 , wherein the alert comprises at least one of a number of users that are connected to a known virtual private network (VPN) client during a time period associated with the alert, an indication of whether characteristics of traffic between the network and a second user device matches a tunneled connection profile, an indication of an amount of outbound data transmitted by the second user device to a remote user device, an indication of whether suspicious file transfer protocol (FTP) activity was detected, an indication of whether a country mismatch was detected, or an indication of whether a suspected case of a VPN compromise is present.

5. The computing system of claim 2 , wherein the non-transitory computer readable storage medium further stores program instructions that cause the computing system to:

receive an indication that the alert is selected; and

update the user interface data such that the user interface includes a window depicting at least one of information of a user associated with first IP address, an indication of whether the user is a person of interest, an indication of a geographic location of the user, an indication of a geographic location to where the user tunneled, or the risk score.

6. The computing system of claim 2 , wherein the non-transitory computer readable storage medium further stores program instructions that cause the computing system to:

receive an indication that the alert is selected; and

receive an indication that the alert is a false positive; and

adjust determination of future risk scores based on the received indication that the alert is a false positive.

7. The computing system of claim 6 , wherein the non-transitory computer readable storage medium further stores program instructions that cause the computing system to adjust weights of one or more factors used to generate future risk scores based on the received indication that the alert is a false positive.

8. The computing system of claim 1 , wherein, in connection with a determination that the second log indicates that a tunneled connection is established over a first port, the generated risk score is lower than if the tunneled connection is established over a second port.

9. A computer-implemented method comprising:

as implemented by one or more computer systems comprising computer hardware and memory, the one or more computer systems configured with specific executable instructions,

accessing a first log including a listing of one or more source addresses corresponding to one or more remote users granted access to a network;

accessing a second log including a listing of one or more destination addresses requested via the network;

identifying a first address included in both the first log and in the second log;

generating a risk score based on data associated with the first address; and

generating an alert in response to the risk score satisfying a threshold.

10. The computer-implemented method of claim 9 , further comprising generating user interface data that, when executed, causes a user device to display a user interface depicting the alert.

11. The computer-implemented method of claim 10 , wherein the alert and one or more other alerts are generated periodically.

12. The computer-implemented method of claim 10 , wherein the alert comprises at least one of a number of users that are connected to a known virtual private network (VPN) client during a time period associated with the alert, an indication of whether characteristics of traffic between the network and a second user device matches a tunneled connection profile, an indication of an amount of outbound data transmitted by the second user device to a remote user device, an indication of whether suspicious file transfer protocol (FTP) activity was detected, an indication of whether a country mismatch was detected, or an indication of whether a suspected case of a VPN compromise is present.

13. The computer-implemented method of claim 10 , further comprising:

receiving an indication that the alert is selected; and

updating the user interface data such that the user interface includes a window depicting at least one of information of a user associated with first IP address, an indication of whether the user is a person of interest, an indication of a geographic location of the user, an indication of a geographic location to where the user tunneled, or the risk score.

14. The computer-implemented method of claim 10 , further comprising:

receiving an indication that the alert is selected; and

receiving an indication that the alert is a false positive; and

adjusting determination of future risk scores based on the received indication that the alert is a false positive.

15. The computer-implemented method of claim 14 , wherein adjusting determination of future risk scores further comprises adjusting weights of one or more factors used to generate future risk scores based on the received indication that the alert is a false positive.

16. The computer-implemented method of claim 8 , wherein, in connection with a determination that the second log indicates that a tunneled connection is established over a first port, the generated risk score is lower than if the tunneled connection is established over a second port.

17. A non-transitory computer-readable medium comprising one or more program instructions recorded thereon, the instructions configured for execution by a computing system comprising one or more processors in order to cause the computing system to:

access a first log including a listing of one or more source addresses corresponding to a plurality of remote users granted access to a network;

access a second log including a listing of one or more destination addresses requested via the network;

identify a first address included in both the first log and in the second log;

generate a risk score based on data associated with the first address; and

generate an alert in response to the risk score satisfying a threshold .

18. The medium of claim 17 , wherein the instructions are further configured to cause the computing system to generate user interface data that, when executed, causes a user device to display a user interface depicting the alert.

19. The medium of claim 18 , wherein the alert and one or more other alerts are generated periodically.

20. The medium of claim 18 , wherein the alert comprises at least one of a number of users that are connected to a known virtual private network (VPN) client during a time period associated with the alert, an indication of whether characteristics of traffic between the network and a second user device matches a tunneled connection profile, an indication of an amount of outbound data transmitted by the second user device to a remote user device, an indication of whether suspicious file transfer protocol (FTP) activity was detected, an indication of whether a country mismatch was detected, or an indication of whether a suspected case of a VPN compromise is present.

21. The medium of claim 18 , wherein the instructions are further configured to cause the computing system to:

receive an indication that the alert is selected; and

update the user interface data such that the user interface includes a window depicting at least one of information of a user associated with first IP address, an indication of whether the user is a person of interest, an indication of a geographic location of the user, an indication of a geographic location to where the user tunneled, or the risk score.

22. The medium of claim 18 , wherein the instructions are further configured to cause the computing system to:

receive an indication that the alert is selected; and

receive an indication that the alert is a false positive; and

adjust determination of future risk scores based on the received indication that the alert is a false positive.

23. The medium of claim 22 , wherein the instructions are further configured to cause the computing system to adjust weights of one or more factors used to generate future risk scores based on the received indication that the alert is a false positive.

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2023
From: RICAFORT, JUAN; SINGH, HARKIRAT; MARTIN, PHILIP
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 064395/0085 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENTS Recorded Jul 3, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0640 →
SECURITY INTEREST Recorded Jul 3, 2022
From: PALANTIR TECHNOLOGIES INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0506 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY LISTED PATENT BY REMOVING APPLICATION NO. 16/832267 FROM THE RELEASE OF SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 052856 FRAME 0382. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 26, 2021
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 057335/0753 →
RELEASE OF SECURITY INTEREST Recorded Jun 4, 2020
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 052856/0382 →
SECURITY INTEREST Recorded Jun 4, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 052856/0817 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: ROYAL BANK OF CANADA, AS ADMINISTRATIVE AGENT
Reel/Frame 051709/0471 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 051713/0149 →
Continuity (4)
Continuation 15228297 · Aug 4, 2016
Continuation 14823935 · Aug 11, 2015
Provisional Application 62036999 · Aug 13, 2014
Related Publication 20180159874A1 · Jun 7, 2018
Cited By (1)
US 12,192,218