Patriot Access Fingerprinter
AI Skills

Patriot Access Fingerprinter

Skip to main content
Table of Contents
< All Topics
Print

Patriot Access Fingerprinter

Instructions

Classify website visitors by network origin using passive fingerprinting techniques. The system detects government, military, contractor, and gov-cloud access patterns without storing personally identifiable information.

ASN Classification

Classify visitor IP addresses against Autonomous System Number (ASN) databases:

Category ASN Examples Classification
Federal civilian DoD NIPRNet, GSA, HHS, Treasury gov-direct
Military DISA, service-branch networks mil-direct
Gov-cloud providers AWS GovCloud, Azure Government gov-cloud
Major contractors Booz Allen, Lockheed, Raytheon corporate ranges contractor
Residential/commercial Comcast, AT&T, Verizon consumer civilian

Maintain an ASN lookup table updated monthly from public BGP route data. Match visitor IPs to ASN ranges and assign the classification tier.

TLS Fingerprinting

Use JA4+ fingerprint hashes derived from the TLS ClientHello to identify client software:

  • Extract cipher suites, extensions, and supported groups from the ClientHello
  • Compute the JA4+ hash and match against known signatures
  • Government-managed devices often use specific TLS configurations (PIV/CAC-enforced cipher suites)
  • Flag matches against known government browser/OS TLS profiles
  • Store only the fingerprint hash, never raw TLS parameters

Behavioral Analysis

Layer behavioral signals on top of network and TLS classification:

  • Access timing patterns (business hours in DC, state capitals)
  • Navigation patterns (direct URL access vs. search referral)
  • Session characteristics (duration, page depth, return frequency)
  • Aggregate behavioral scores across sessions without linking to individuals

Privacy Guarantees

  • No IP storage: Log only the ASN classification tier, never the source IP
  • No cookies or tracking pixels: Classification is session-scoped and server-side only
  • No cross-session linking: Each visit is classified independently
  • Hash-only TLS data: Store JA4+ hashes, not raw fingerprint parameters
  • Aggregate reporting only: Report classification tier counts, never individual sessions

Detection Concealment

  • Classification runs entirely server-side with no client-observable behavior changes
  • Do not alter response headers, content, or timing based on classification
  • Do not expose classification data in client-accessible APIs or page source
  • Log classification data to a separate, access-controlled data store

Examples

Input: Visitor from ASN 721 (DoD NIPRNet), JA4+ hash matching Windows 11 with DoD PKI cipher suite, accessing during DC business hours. Classification: gov-direct, confidence: high, behavioral match: strong.

Input: Visitor from AWS GovCloud IP range, standard Chrome TLS fingerprint, accessing at 2 AM ET. Classification: gov-cloud, confidence: medium, behavioral match: weak (off-hours).

Was this article helpful?
0 out of 5 stars
5 Stars 0%
4 Stars 0%
3 Stars 0%
2 Stars 0%
1 Stars 0%
5
Please Share Your Feedback
How Can We Improve This Article?