IP Library › Granted Patent US 12,621,269
Granted Patent B2
US 12,621,269 · App. 18/408,096 · Granted May 5, 2026

Proxy detection systems and methods

Inventors: Elisa Chiapponi (Nice, FR); Marc Dacier (Nice, FR); Olivier Thonnard (Nice, FR); Vincent Rigal (Nice, FR); Mohamed Fangar (Nice, FR)
Assignee: AMADEUS S.A.S.
H04L63/0281H04L63/0245H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,621,269
App. No.
18/408,096
Granted
May 5, 2026
Kind
B2
Abstract

A method includes receiving, from a client device, a first request to establish a transport-layer connection between the client device and the server, the first request containing a first source port number; in response to receiving the first request, initiating a delay timer and withholding transmission of an acknowledgement to the first request until expiry of the delay timer; receiving from the client device, prior to expiry of the delay timer, a second request to establish the transport-layer connection; determining whether the second request contains a second source port number matching the first source port number; and selecting, based on the determination, a handling action for the second request.

Claims (55)

1 . A proxy detection method in a server, the method comprising:

receiving, from a client device, a first request to establish a transport-layer connection between the client device and the server, the first request containing a first source port number;

in response to receiving the first request and prior to establishing the transport-layer connection, initiating a delay timer and withholding transmission of an acknowledgement to the first request until expiry of the delay timer;

receiving from the client device, prior to expiry of the delay timer, a second request to establish the transport-layer connection;

in response to determining that the second request contains a second source port number matching the first source port number, initiating establishment of the transport-layer connection with the client device; and

selecting, based on the determination, a handling action for the second request.

2 . The method of claim 1 , wherein selecting the handling action includes:

when the determination is negative, discarding the first request and the second request, without sending an acknowledgement to the client device.

3 . The method of claim 1 , wherein selecting the handling action includes:

when the determination is negative, providing an indication that the client device is likely a proxy for a client endpoint to an auxiliary detector.

4 . The method of claim 1 , wherein the transport-layer connection is based on the Transport Control Protocol (TCP), wherein the first request includes a SYN message, and wherein initiating establishment of the transport-layer connection includes sending a SYN-ACK message to the client device.

5 . The method of claim 4 , further comprising:

determining a first time period associated with the transport-layer connection;

in response to receiving, from the client device over the transport-layer connection, a second request to establish a secure link between a client endpoint and the server, transmitting a second message to the client endpoint according to a handshake sequence for establishing the secure link;

determining a second time period associated with completion of the second handshake sequence; and

generating, based on the first time period and the second time period, a score indicating a likelihood that the client device is a proxy for the client endpoint.

6 . The method of claim 5 , wherein generating the score includes determining a difference between the first and second time periods.

7 . The method of claim 5 , wherein determining the first time period includes determining a time elapsed between transmission of the acknowledgement, and receipt of an ACK message from the client device.

8 . The method of claim 1 , wherein the first request contains a first sequence number;

and wherein the determination further comprises:

determining whether the second request contains a second sequence number matching the first sequence number.

9 . The method of claim 8 , wherein selecting the handling action includes:

when at least one of

(i) the first source port number does not match the second source port number,

or (ii) the first sequence number does not match the second sequence number,

discarding the first request and the second request, without sending an acknowledgement to the client device.

10 . The method of claim 1 , wherein the delay timer is between 1 second and 2 seconds.

11 . A computing device, comprising:

a communications interface; and

a processor configured to:

receive via the communications interface, from a client device, a first request to establish a transport-layer connection between the client device and the server, the first request containing a first source port number;

in response to receiving the first request and prior to establishing the transport-layer connection, initiate a delay timer and withhold transmission of an acknowledgement to the first request until expiry of the delay timer;

receive from the client device, prior to expiry of the delay timer, a second request to establish the transport-layer connection;

in response to determining that the second request contains a second source port number matching the first source port number, initiate establishment of the transport-layer connection with the client device; and

select, based on the determination, a handling action for the second request.

12 . The computing device of claim 11 , wherein the processor is configured to select the handling action by:

when the determination is negative, discarding the first request and the second request, without sending an acknowledgement to the client device.

13 . The computing device of claim 11 , wherein the processor is configured to select the handling action by:

when the determination is negative, providing an indication that the client device is likely a proxy for a client endpoint to an auxiliary detector.

14 . The computing device of claim 11 , wherein the transport-layer connection is based on the Transport Control Protocol (TCP), wherein the first request includes a SYN message, and wherein the processor is configured to initiate establishment of the transport-layer connection by sending a SYN-ACK message to the client device.

15 . The computing device of claim 14 , wherein the processor is further configured to:

determine a first time period elapsed between transmission of the acknowledgement, and receipt of an ACK message from the client device;

in response to receiving, from the client device over the transport-layer connection, a second request to establish a secure link between a client endpoint and the server, transmit a second message to the client endpoint according to a handshake sequence for establishing the secure link;

determine a second time period associated with completion of the second handshake sequence; and

generate, based on the first time period and the second time period, a score indicating a likelihood that the client device is a proxy for the client endpoint.

16 . The computing device of claim 15 , wherein the processor is configured to generate the score by determining a difference between the first and second time periods.

17 . The computing device of claim 15 , wherein the processor is configured to determine the first time period by determining a time elapsed between transmission of the acknowledgement, and receipt of an ACK message from the client device.

18 . The computing device of claim 11 , wherein the first request contains a first sequence number; and wherein the determination further comprises:

determining whether the second request contains a second sequence number matching the first sequence number.

19 . The computing device of claim 18 , wherein the processor is configured to select the handling action by:

when at least one of

(i) the first source port number does not match the second source port number,

or (ii) the first sequence number does not match the second sequence number,

discarding the first request and the second request, without sending an acknowledgement to the client device.

20 . The computing device of claim 11 , wherein the delay timer is between 1 second and 2 seconds.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2024
From: CHIAPPONI, ELISA; DACIER, MARC; THONNARD, OLIVIER; RIGAL, VINCENT; FANGAR, MOHAMED
To: AMADEUS S.A.S.
Reel/Frame 066183/0796 →
Continuity (2)
Provisional Application 63497053 · Apr 19, 2023
Related Publication 20240356899A1 · Oct 24, 2024
References Cited (31)
US 8332510B2 · Khosravi et al. · 2012 [cited by applicant]
US 10069837B2 · Turgeman et al. · 2018 [cited by applicant]
US 10225177B2 · Li et al. · 2019 [cited by applicant]
US 10673992B1 · Weiser · 2020 [cited by examiner]
US 10728131B2 · Jung · 2020 [cited by examiner]
US 10986109B2 · Howard et al. · 2021 [cited by applicant]
US 11196712B1 · Norbutas · 2021 [cited by applicant]
US 20020161925A1 · Munger · 2002 [cited by examiner]
US 20040210663A1 · Phillips · 2004 [cited by examiner]
US 20050180327A1 · Banerjee · 2005 [cited by examiner]
US 20060168649A1 · Venkat · 2006 [cited by examiner]
US 20090144408A1 · Wilf · 2009 [cited by examiner]
US 20110246633A1 · Khosravi et al. · 2011 [cited by applicant]
US 20170012988A1 · Turgeman et al. · 2017 [cited by applicant]
US 20170310693A1 · Howard et al. · 2017 [cited by applicant]
US 20180152375A1 · Li et al. · 2018 [cited by applicant]
AU 2003228703A1 · 2003 [cited by applicant]
CN 101895552A · 2010 [cited by applicant]
CN 109040128A · 2018 [cited by applicant]
CN 109361649A · 2019 [cited by applicant]
CN 111064827B · 2020 [cited by applicant]
CN 113395255A · 2021 [cited by applicant]
EP 2232810B1 · 2013 [cited by applicant]
WO WO03098474A1 · 2003 [cited by applicant]
Sahu, Abhijeet, et al. “Design and evaluation of a cyber-physical testbed for improving attack resilience of power systems.” IET Cyber-Physical Systems: Theory & Applications 6.4 (2021): 208-227. [cited by applicant]
U.S. Appl. No. 17/746,556, Proxy Detection Systems and Methods, filed May 17, 2022. [cited by applicant]
Cao Zechun, “Intrusion Detection: Detecting Network Intruders Behind Anonymity Networks and Identifying Intruders on the Hosts by Modeling User Behaviors”. Diss. 2020. [cited by applicant]
Hoogstraaten, J. M. “Evaluating server-side internet proxy detection methods.”, MSC thesis, Cybersecurity Academy, (2018). [cited by applicant]
Mi, Xianghang, et al. “Resident evil: Understanding residential IP proxy as a dark service.” 2019 IEEE symposium on security and privacy (SP). IEEE, 2019. [cited by applicant]
Tschacher Nikolai. “Is This a Valid Method to Detect Proxies?” Incolumitas.com, Nov. 27, 2021, downloaded on Sep. 15, 2022 from URL: https://incolumitas.com/2021/11/26/is-this-a-valid-method-to-detect-proxies/. [cited by applicant]
Webb, Allen T. et al. “Finding proxy users at the service using anomaly detection.” 2016 IEEE Conference on Communications and Network Security (CNS). IEEE, 2016. [cited by applicant]