Hi,
When you monitor the timing of these remote connection events, have you noticed any patterns? Could it be that some software is triggering this activity? Have you conducted a full virus scan? Additionally, you might want to consider disabling the Remote Desktop connection on port 3389 through the firewall to prevent any incoming network traffic