- Hackers hide behind VPNs and proxies to look like normal, safe visitors.
- Most security tools only check one part of a visit, not the whole picture.
- A tool called Monocle adds missing details so security teams can catch more threats.
Website owners use many tools to stop hackers. But even with all these tools working together, some hackers still slip through. They hide inside traffic that looks just like real visitors.
This happens because each tool only checks one small piece of the puzzle. If a hacker uses a home internet address or a paid VPN, they can pass through several checks without setting off any alarms.
According to Spur, the real problem is that most tools don’t know enough about where the traffic is truly coming from.
Where Current Security Tools Fall Short
Website defense works in layers. Each layer answers a different question about visitors. Content delivery networks and web firewalls check requests closely. They block known threats and enforce rules. But they can’t always tell if a normal-looking visit is actually being routed through hidden infrastructure built to disguise where it came from.
Bot detection tools try to spot machines pretending to be humans. Yet not every dangerous visit comes from a bot. Hackers now mix automated tools with networks built to look like everyday, harmless traffic. That combination fools many detection systems.
Login and identity systems check if someone can prove who they say they are. But having the right username and password doesn’t always mean the real account owner is the one typing them in. Someone else could be using stolen details.
Device and browser checks look at the device sending the traffic. They build trust based on details like the browser type. Still, these checks don’t reveal anything about the network carrying that device’s traffic to the website.
Spur explains that each of these tools does its job well on its own. But hackers slip through the small gaps between them. They build sessions that look fine to any single tool, while hiding the true story of their network setup.
Researchers have long focused on closing security gaps. In 2016, Microsoft researchers Itai Grady and Tal Be’ery released SAMRi10, later evolved into NetCease, to help administrators protect enterprise networks from reconnaissance attacks and limit attackers’ ability to map networks after a compromise.
How Session Enrichment Fills the Gap
This gap creates a need for one more layer of information, real facts about the network behind each visit. A company called Spur built a tool named Monocle Session Enrichment to fill that gap.
Monocle checks every visitor session and adds real-time trust details. These include whether the visitor is hiding their identity, using a known VPN service, connecting from a home network, or linked to networks used by known attackers.
Spur states that this added context helps security and fraud teams make sharper choices at the point of entry. It aims to cut down on risky logins while making things easier for real, trustworthy users.
Monocle blends Spur’s map of internet networks with live details from each session. This builds what Spur calls a Session Trust Assessment. Rather than just marking an internet address as good or bad, it hands over specific details. Security teams then decide what to do with those details.
One sample assessment shared by Spur showed a blocked session. The system flagged the connection as hidden and tied it to a known VPN service, so the request got refused under the site’s rule against anonymous traffic.
Spur notes that this kind of report gives three main things: facts about what Monocle saw, a suggested action based on the company’s own rules, and record-keeping details so teams can trace every decision later.
Fields like whether a VPN or proxy was used tell teams about the connection itself. Newer fields also flag activity linked to AI tools, whether they’re acting like a person or simply crawling the site. Rather than leaving a website to guess what the data means, the report gives a clear yes-or-no answer and explains why.
In the sample case Spur shared, the reason given was that the site’s rules block all hidden connections. Other fields, such as timestamps and ID numbers, let a team trace any decision back to the exact moment it happened.
Spur says the whole point of this extra layer is to hand over network facts. Then, each company can decide what those facts mean for their own users, their own risk level, and their own rules.
Putting the Extra Context to Work
Picture a bank that sees a successful login from a normal-looking address inside the United States. By itself, that’s not alarming. But added context might show that the visitor is hiding their identity, connecting through a data center, and linked to a known VPN service. That extra detail helps the bank make a smarter, faster call.
In practice, a regular customer using their usual device through a VPN might get to continue as normal. But a login using new account details, an unknown device, and hidden network tools might trigger extra identity checks. A large money transfer from that same visit could need even more proof before it goes through.
Spur says this same idea works beyond just stopping stolen logins. During sign-up, network details can flag people trying to hide or repeatedly change their identity. For fake traffic and bot abuse, this extra layer works alongside bot detection tools by showing the network used to spread out the activity.
With location-based rules, companies can tell the difference between a visitor’s real location and one hidden behind a VPN. For AI-driven traffic, companies can add new AI-related flags to rules they already use for humans and bots.
Spur built Monocle to work alongside a company’s current tools, not replace them. Businesses using services like Cloudflare can add this session data straight into their existing rulebooks. Depending on the mix of details, a team might choose to let a session through, challenge it with extra checks, demand stronger proof of identity, block a risky action, send it for closer review, or stop it completely.
Share this article
About the Author
Farwa is an experienced InfoSec writer and cybersecurity journalist skilled in writing articles related to cybersecurity, AI, DevOps, Big Data, Cloud security, VPNs, IAM, and Cloud Computing. Also a contributor on Tripwire.com, Infosecurity Magazine, Security Boulevard, DevOps.com, and CPO Magazine.
More from Farwa SajjadRelated Posts
EU Puts ChatGPT, Reddit and Roblox Under Toughest Digital Safety Rules
The European Commission named ChatGPT, Reddit and Roblox as very large online services under the Dig...
Microsoft Warns Windows Users to Ignore False Defender Antivirus Alert
Microsoft is asking users to ignore a false alert saying Windows Defender is turned off. The bug has...
Signal Fixes Critical SGX Flaws that Could Expose Contact Discovery Data
V12 found two flaws in Signal’s Contact Discovery Service that could break the security boundary aro...
Ring Unveils TAKE Encryption to Strengthen Privacy for Home Camera Users
Ring will make its new TAKE encryption the default as the feature rolls out from September. TAKE giv...
Apple Reverses Plan to Change Hide My Email Domain After Privacy Concerns
Apple will not move Hide My Email addresses to a new domain. The company reversed a plan it announce...
Amazon and Twitch Face Class Action Over Alleged AI Training on Creator Videos
Streamer Warren Pandiscia filed a class-action lawsuit accusing Amazon and Twitch of using creator v...