CDN Inline Traffic Inspection for Malware and Data Leakage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Content Delivery Networks (CDNs) are vulnerable to malware threats and data leakage due to compromised origin servers, which can infect other nodes and expose users to malicious content, leading to security incidents and legal liabilities.

Innovation Solution

A distributed security system is implemented within the CDN network, utilizing high-performance web proxies to inspect traffic for malware and data leakage, employing anti-virus controls, sandboxing, and data leakage prevention techniques to block malicious content before it enters the CDN.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If CDN networks poll customer's Origin servers to fetch content, then content delivery speed and availability are improved, but security risks from malware and data leakage increase

Engineering Contradiction:
Improvecontent delivery speedVSAvoidmalware and data leakage risks
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a security scanning system as an intermediary component between origin servers and CDN edge servers. This mediator inspects content for malware and data leakage before allowing it to enter the CDN network, thus resolving the contradiction by maintaining fast content delivery while blocking security threats through the intermediary scanning layer

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary security scanning and validation of content before it is cached or distributed through the CDN. By performing malware detection and data leakage prevention checks in advance, the system ensures that only safe content enters the CDN network, resolving the security risk while maintaining delivery speed

Inventive Principle:
Principle #10Preliminary action

2Reliability

If advanced threat protection and sandboxing technologies are deployed to detect malware, then security detection capability is improved, but system complexity and processing time increase

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the security scanning system into separate modular components including malware detection modules, data leakage prevention modules, and sandboxing environments. This segmentation allows each security function to operate independently, improving detection capability while managing system complexity through modular architecture

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a dedicated security scanning intermediary layer that handles all threat detection operations. This mediator isolates the complex security processing from the main CDN operations, allowing advanced threat protection and sandboxing to function without directly increasing the operational complexity of the core content delivery system

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If comprehensive traffic scanning for malware and data leakage is performed, then security protection is improved, but processing speed and throughput decrease

Engineering Contradiction:
Improvesecurity protectionVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary filtering and classification of traffic before comprehensive scanning. By identifying and prioritizing high-risk traffic patterns early in the process, the system applies intensive scanning only where necessary, maintaining security protection while preserving overall processing speed and throughput

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent dynamically adjusts scanning parameters such as scan depth, detection sensitivity, and processing priority based on traffic characteristics and security threats. This allows the system to maintain high security protection when threats are detected while operating at full processing speed during normal conditions, resolving the contradiction through adaptive parameter changes

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10972487B2Content delivery network protection from malware and data leakage
Publication Date: 2021.04.06 ZSCALER INC
  • US10972487B2 patent drawing
  • US10972487B2 patent drawing
  • US10972487B2 patent drawing

AI summary

A Content Delivery Network (CDN) includes one or more cache servers communicatively coupled to end users for providing content thereto; and one or more origin servers communicatively coupled to the one or more cache servers through a plurality of nodes, the one or more cache servers are configured to receive traffic related to the content from the one or more origin servers through the one or more nodes of the plurality of nodes, based on one or more of a push technique and a pull technique, and the plurality of nodes are configured to monitor the traffic between the one or more origin servers and the one or more cache servers in an inline manner, process the traffic for malware and data leakage based on policy, and block the traffic responsive to detection of one or more of the malware and the data leakage, prior to traffic entering the CDN.