Real-Time Reverse Tunnel Detection via Active Probing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional approaches to detecting covert communications channels, such as reverse tunnels, are ineffective in real-time, leading to delayed detection and potential network damage, and are not scalable for large networks, which can result in significant liability and reputation loss.

Innovation Solution

A real-time system that employs intermediary network devices to classify packets and apply probabilistic filters and active probing techniques to detect suspicious activity indicative of reverse tunnels, distinguishing between ordinary, suspicious, and flagged flows, and enabling countermeasures to prevent damage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If off-line analysis of communication session logs is performed to detect reverse tunnels, then detection capability is provided, but detection delay occurs and real-time protection is not achieved

Engineering Contradiction:
Improvedetection capabilityVSAvoiddetection delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by performing real-time analysis of communication packets as they traverse the network, rather than waiting for offline log analysis. The intermediary device continuously monitors and analyzes packet characteristics, protocols, and patterns during transmission, enabling detection before damage occurs. This transforms the detection process from reactive (offline) to proactive (real-time), resolving the contradiction between detection capability and detection delay.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If comprehensive packet analysis is performed to detect covert channels, then detection accuracy improves, but network performance degradation occurs

Engineering Contradiction:
Improvedetection accuracyVSAvoidnetwork performance
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent applies local quality by implementing selective analysis where the intermediary device focuses computational resources on packets exhibiting suspicious characteristics rather than analyzing every packet uniformly. The system identifies packets with unusual protocols, unusual ports, or unusual patterns and applies deeper analysis only to those, while allowing normal traffic to pass with minimal processing. This localized approach maintains high detection accuracy for covert channels while preserving overall network performance.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent applies partial action by performing comprehensive analysis only on a subset of packets that exhibit suspicious characteristics, rather than applying full analysis to all traffic. The system uses initial filtering to identify potentially malicious packets and applies intensive analysis only to those cases, accepting that some normal packets may not be fully analyzed. This partial approach balances detection accuracy with network performance by concentrating resources where they are most needed.

Inventive Principle:
Principle #16Partial or excessive action

3Speed

If real-time detection systems are implemented, then detection speed improves, but system complexity increases

Engineering Contradiction:
Improvedetection speedVSAvoidsystem complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the real-time detection system into multiple functional components: an intermediary device for packet interception, analysis engine for examining packet characteristics, classification module for identifying covert channels, and response system for taking action. Each component performs a specific function and can be independently optimized and maintained. This modular segmentation enables real-time detection speed while managing system complexity through clear separation of concerns and specialized functionality in each segment.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8151348B1Automatic detection of reverse tunnels
Publication Date: 2012.04.03 CISCO TECHNOLOGY INC
  • US8151348B1 patent drawing
  • US8151348B1 patent drawing
  • US8151348B1 patent drawing

AI summary

Presently disclosed are methods and apparatus for analyzing packets and packet flows to detect covert communications channels (including reverse tunnels) in real time. These systems actively probe a suspicious connection in ways that are not possible in prior art log-based techniques and may initiate countermeasures against discovered covert channels. The present system may be implemented in a network device, such as an intrusion detection system, content engine, or other intermediary device employing a web cache. Embodiments automatically detect suspicious activity at particular source addresses by using relatively simple tests to detect suspect packets that should receive more extensive scrutiny. After more rigorous secondary testing (optionally including active probing techniques), suspect packets are either returned to the occasionally-checked state or flagged for further action, such as raising an alert or taking automatic countermeasures against the covert channel or its originators.