Cloud Object Security Posture Management via Synthetic Request Injection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud access security brokers (CASBs) face challenges in accessing missing metadata during cloud transactions, limiting their ability to enforce appropriate policies, especially when metadata is not available in the transaction stream, and this deficiency hinders their capability to provide an improved security posture and reduce data loss and exfiltration risks across multi-cloud, web, and email environments.

Innovation Solution

The implementation of synthetic request injection by the network security system to independently retrieve missing metadata from cloud applications, allowing CASBs to operate self-sufficiently and generate metadata for policy enforcement, even in metadata-deficient transactions, thereby reducing reliance on metadata mapping transactions and enhancing policy enforcement capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If CASBs rely on metadata mapping transactions to obtain metadata, then they can enforce security policies, but they fail when metadata is not available in the transaction stream

Engineering Contradiction:
Improvepolicy enforcement capabilityVSAvoidmetadata availability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by injecting synthetic requests before actual transactions to proactively obtain metadata. The CASB sends synthetic requests to cloud applications to retrieve metadata in advance, storing it for later use during policy enforcement, ensuring metadata availability even when not present in transaction streams

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary mechanism by using synthetic requests as a mediator between the CASB and cloud applications. These synthetic requests act as intermediate transactions that facilitate metadata retrieval without disrupting actual user transactions, bridging the gap when direct metadata extraction fails

Inventive Principle:
Principle #24Intermediary (Mediator)

2Extent of automation

If CASBs independently retrieve metadata using synthetic requests, then they achieve self-sufficiency, but they increase system complexity

Engineering Contradiction:
Improveself-sufficiencyVSAvoidsystem complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The CASB achieves self-service by autonomously generating and sending synthetic requests to cloud applications to retrieve its own metadata requirements. The system independently identifies missing metadata, constructs appropriate synthetic requests, processes responses, and updates its metadata store without external intervention, enabling self-sufficient operation

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes operational parameters by dynamically adjusting the level of synthetic request injection based on metadata availability and policy enforcement needs. It monitors transaction streams, identifies metadata gaps, and selectively injects synthetic requests only when necessary, optimizing the balance between automation and complexity

Inventive Principle:
Principle #35Parameter changes

3Manufacturing precision

If metadata is not available in the transaction stream, then CASBs cannot enforce appropriate policies, but synthetic request injection can retrieve missing metadata

Engineering Contradiction:
Improvepolicy enforcement accuracyVSAvoidmetadata deficiency
Core Design Contradiction:
Manufacturing precisionVSLoss of information

Solution Approach 1:

The system applies preliminary anti-action by preventing metadata deficiency through proactive retrieval. Instead of waiting for metadata to be missing and then failing, the CASB preemptively identifies potential metadata gaps and retrieves necessary information through synthetic requests before policy enforcement decisions are required

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system implements feedback mechanisms by monitoring transaction streams for metadata availability, identifying deficiencies, and triggering synthetic request injection when needed. The results from synthetic requests feed back into the metadata store, continuously improving the system's ability to enforce policies accurately

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11831683B2Cloud object security posture management
Publication Date: 2023.11.28 NETSKOPE INC
  • US11831683B2 patent drawing
  • US11831683B2 patent drawing
  • US11831683B2 patent drawing

AI summary

The technology disclosed relates to using synthetic request injection to improve cloud object security posture management.