Cloud Object Security Posture Management via Synthetic Request Injection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud access security brokers (CASBs) face challenges in accessing missing metadata during cloud transactions, limiting their ability to enforce appropriate policies, especially when metadata is not available in the transaction stream, and this deficiency hinders their capability to provide an improved security posture and reduce data loss and exfiltration risks across multi-cloud, web, and email environments.
Innovation Solution
The implementation of synthetic request injection by the network security system to independently retrieve missing metadata from cloud applications, allowing CASBs to operate self-sufficiently and generate metadata for policy enforcement, even in metadata-deficient transactions, thereby reducing reliance on metadata mapping transactions and enhancing policy enforcement capabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If CASBs rely on metadata mapping transactions to obtain metadata, then they can enforce security policies, but they fail when metadata is not available in the transaction stream
Solution Approach 1:
The system performs preliminary actions by injecting synthetic requests before actual transactions to proactively obtain metadata. The CASB sends synthetic requests to cloud applications to retrieve metadata in advance, storing it for later use during policy enforcement, ensuring metadata availability even when not present in transaction streams
Solution Approach 2:
The system introduces an intermediary mechanism by using synthetic requests as a mediator between the CASB and cloud applications. These synthetic requests act as intermediate transactions that facilitate metadata retrieval without disrupting actual user transactions, bridging the gap when direct metadata extraction fails
2Extent of automation
If CASBs independently retrieve metadata using synthetic requests, then they achieve self-sufficiency, but they increase system complexity
Solution Approach 1:
The CASB achieves self-service by autonomously generating and sending synthetic requests to cloud applications to retrieve its own metadata requirements. The system independently identifies missing metadata, constructs appropriate synthetic requests, processes responses, and updates its metadata store without external intervention, enabling self-sufficient operation
Solution Approach 2:
The system changes operational parameters by dynamically adjusting the level of synthetic request injection based on metadata availability and policy enforcement needs. It monitors transaction streams, identifies metadata gaps, and selectively injects synthetic requests only when necessary, optimizing the balance between automation and complexity
3Manufacturing precision
If metadata is not available in the transaction stream, then CASBs cannot enforce appropriate policies, but synthetic request injection can retrieve missing metadata
Solution Approach 1:
The system applies preliminary anti-action by preventing metadata deficiency through proactive retrieval. Instead of waiting for metadata to be missing and then failing, the CASB preemptively identifies potential metadata gaps and retrieves necessary information through synthetic requests before policy enforcement decisions are required
Solution Approach 2:
The system implements feedback mechanisms by monitoring transaction streams for metadata availability, identifying deficiencies, and triggering synthetic request injection when needed. The results from synthetic requests feed back into the metadata store, continuously improving the system's ability to enforce policies accurately
Data Source
AI summary
The technology disclosed relates to using synthetic request injection to improve cloud object security posture management.


