Bouncer Device for Client IP Discovery Behind NAT
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud-hosted secure web gateways struggle to identify client devices attempting to access malicious websites due to network address translation (NAT) hiding the actual IP address, making it difficult for enterprises to take remedial action.
Innovation Solution
A system involving a Bouncer device deployed behind the NAT, which captures the IP address by redirecting the client to an error page and correlates log information with the Secure Web Gateway (SWG) to identify and record client details, enabling accurate identification and reporting of policy violations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a cloud-hosted SWG is deployed outside the enterprise network, then the SWG can enforce security policies on outbound traffic, but the NAT device hides the actual client IP address making device identification impossible
Solution Approach 1:
The patent introduces a bouncer device as an intermediary component deployed inside the enterprise network behind the NAT device. This bouncer acts as a mediator between the cloud-hosted SWG and the internal client devices. When the SWG needs to identify a client device, it queries the bouncer which then captures and returns the actual internal IP address of the requesting client, thus preserving the information that would otherwise be hidden by NAT.
Solution Approach 2:
The patent adds a new dimensional layer to the network architecture by introducing the bouncer device as a separate component in the internal network dimension. Instead of trying to obtain IP addresses directly from the cloud SWG (external dimension), the system creates an additional internal dimension where the bouncer resides, allowing IP address capture without compromising the cloud-hosted SWG architecture.
2Reliability
If a NAT device is used to separate the enterprise network from the cloud-hosted SWG, then network security is improved, but the actual client IP address is hidden from the SWG
Solution Approach 1:
The bouncer device serves as an intermediary that bridges the NAT barrier. It receives queries from the cloud SWG about client identification, captures the actual internal IP address of the requesting client through its position behind the NAT, and returns this information to the SWG. This allows precise measurement and identification of client devices without removing the NAT security layer.
3Reliability
If the SWG blocks access for a policy violation, then security is enforced, but the enterprise cannot identify the offending device for remedial action
Solution Approach 1:
The patent establishes a feedback mechanism where the bouncer device provides client identification information back to the cloud SWG after the SWG enforces a security block. This feedback loop enables the enterprise to receive both the security enforcement action and the identifying information about the offending device, allowing for subsequent remedial actions such as contacting the user or removing malware.
Data Source
AI summary
Among other things, this document describes systems, methods and devices for discovering and identifying client devices that attempt to access out-of-policy network services via a secure web gateway (or other network security gateway) that lacks visibility into the client network actual IP space. This is a common problem with cloud hosted SWG services that enforce access policy from outside of a customer network (e.g., external to an enterprise network), due to network address translation at the interface between the customer network and the public Internet where the cloud-hosted SWG resides. The teachings hereof address this problem. In one embodiment, a cloud hosted SWG can redirect a client to a bouncer device inside the customer network; that bouncer device can capture the actual client IP address.


