you need to use packet sniffer to determine if there is any kind of pattern in his connection. for example when he makes the connection, the initial packets could be the same always. so copy those strings and make into a l7 filter. L7 will consume a lot of resources, because it will have to look into every packet