Cloud Security Proxy for Mobile Network Traffic Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies face challenges in effectively securing user privacy and anonymity online, securely sharing access to devices, and monitoring computer activity, particularly for Internet-of-Things devices and child supervision.

Innovation Solution

A cloud-based security proxy service intercepts and modifies network traffic from mobile devices, applying security policies to detect and mitigate threats, while providing real-time visibility and decoy traffic to protect the network and maintain user anonymity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network traffic is intercepted and monitored to detect threats, then security protection is improved, but user privacy and anonymity are compromised

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser privacy and anonymity
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

A cloud-based security proxy service is introduced as an intermediary between the mobile device and the network. The proxy intercepts and monitors network traffic to detect threats while the user remains unaware of the monitoring. This resolves the contradiction by providing security protection through traffic interception without compromising user privacy, as the user does not know they are being monitored.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a sandboxed copy of the mobile application environment where network traffic can be monitored and analyzed. The original application continues to operate normally while its traffic is copied and examined by the security proxy. This allows threat detection through traffic copying without the user knowing their actual traffic is being monitored, thus maintaining privacy while improving security.

Inventive Principle:
Principle #26Copying

2Measurement precision

If a cloud-based security proxy service is introduced to monitor network traffic, then threat detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The security proxy service is extracted from the mobile device and relocated to a cloud-based infrastructure. This removes the complexity of implementing traffic interception, sandboxing, and threat analysis from the user's device, concentrating all the complex functionality in a centralized cloud service. The mobile device simply connects to the proxy, significantly reducing local system complexity while maintaining high threat detection capability.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If network traffic is modified to apply security policies, then network protection is improved, but legitimate network communication may be disrupted

Engineering Contradiction:
Improvenetwork protectionVSAvoidlegitimate network communication
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The security proxy service implements feedback mechanisms where network traffic is monitored, analyzed for threats, and selectively modified based on detected threat indicators. The system continuously adjusts its traffic modification actions based on feedback from threat detection algorithms, allowing it to protect the network while minimizing disruption to legitimate communication by only modifying traffic that exhibits suspicious patterns.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11316901B1Systems and methods for protecting users
Publication Date: 2022.04.26 GEN DIGITAL INC
  • US11316901B1 patent drawing
  • US11316901B1 patent drawing
  • US11316901B1 patent drawing

AI summary

The disclosed computer-implemented method for protecting users may include (i) intercepting, through a cloud-based security proxy service, network traffic originating from a mobile application at a mobile device connected to a local area network protected by the cloud-based security proxy service, (ii) detecting, by the cloud-based security proxy service, a threat indicator indicated by the mobile application, and (iii) modifying the network traffic originating from the mobile application at the mobile device by applying, by the cloud-based security proxy service based on detecting the threat indicator indicated by the mobile application, a security policy to protect the local area network from a candidate threat corresponding to the threat indicator. Various other methods, systems, and computer-readable media are also disclosed.