HTTP Tunneling via CONNECT Method on Non-Standard Ports

Detects the use of the HTTP CONNECT method on non-standard ports (8888, 9999, 4444). The CONNECT method is frequently used by HTTP proxies to establish TCP tunnels; unauthorized use of this method on uncommon ports is a common indicator of protocol tunneling used to bypass network egress filtering or for command and control (C2) communication.