Cloud Security Platform Using API-Based Sandbox Inspection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional inline block-and-inspect systems for cloud/SaaS environments face drawbacks such as increased latency, disruption of normal operations, inability to inspect encrypted traffic, and lack of comprehensive protection against malware and data leakage, leading to compromises between inline prevention and detection-only systems.
Innovation Solution
A non-inline data security system using network application programming interfaces (APIs) to remotely control cloud-based services, preventing access to data until it is cleared by a security manager and data inspector, and performing remedial actions when necessary, thereby ensuring secure data transactions without being inline.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If inline block-and-inspect systems are used to scan data before access, then security protection against malware and data leakage is improved, but network latency increases and normal operations are disrupted
Solution Approach 1:
The system performs preliminary security scanning by copying data to a sandbox environment before allowing access. The sandbox pre-executes and analyzes the data for malicious behavior, so that by the time the original data is needed, the security assessment is already complete, eliminating latency during access operations.
Solution Approach 2:
The security system is segmented into independent components: data copying to sandbox, execution in isolated environment, analysis of behavior, and final security determination. This segmentation allows the scanning process to occur in parallel with data preparation, rather than blocking the entire data flow.
2Reliability
If inline inspection devices are introduced into the network, then security scanning capability is improved, but normal operation of network components is disrupted
Solution Approach 1:
A sandbox environment acts as an intermediary between the network and the inspection process. Data is copied to this isolated intermediate environment for analysis, allowing security scanning to occur without the inspection device directly interfering with or disrupting the normal operation of network components.
Solution Approach 2:
Instead of inspecting the original data flow directly, the system creates a copy of the data and places it in a sandbox environment for inspection. This copying approach allows security analysis to proceed on the duplicate while the original data continues to flow through the network unaffected.
3Reliability
If encrypted traffic is transmitted for cloud services, then data privacy and security are improved, but inspection capability is reduced
Solution Approach 1:
The system performs preliminary copying of encrypted data to a sandbox environment before decryption and inspection. By preparing the data copy in advance in a controlled environment, the system can later decrypt and inspect it without compromising the privacy of the original encrypted transmission during normal operations.
Data Source
AI summary
A data security system, including a security manager computer making network API calls to a service that performs data-exchange transactions for end users, the API calls remotely controlling the service so that the security manager computer accesses an outgoing transaction that has already entered the cloud-based service, by generating one or more security platform rules that are applied by the service and cause the service to automatically transmit the outgoing transaction to an inspection location prior to transmission of the outgoing transaction to a destination, and a data inspector operative to inspect data of the outgoing transaction in the inspection location for data leakage, wherein the security manager computer further controls the service so as to transmit the outgoing transaction to the destinations when the data inspector clears the data, and to perform a remedial action regarding the outgoing transaction when the data inspector does not clear the data.


