Cloud Security Platform Using API-Based Sandbox Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional inline block-and-inspect systems for cloud/SaaS environments face drawbacks such as increased latency, disruption of normal operations, inability to inspect encrypted traffic, and lack of comprehensive protection against malware and data leakage, leading to compromises between inline prevention and detection-only systems.

Innovation Solution

A non-inline data security system using network application programming interfaces (APIs) to remotely control cloud-based services, preventing access to data until it is cleared by a security manager and data inspector, and performing remedial actions when necessary, thereby ensuring secure data transactions without being inline.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If inline block-and-inspect systems are used to scan data before access, then security protection against malware and data leakage is improved, but network latency increases and normal operations are disrupted

Engineering Contradiction:
Improvesecurity protectionVSAvoidnetwork latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary security scanning by copying data to a sandbox environment before allowing access. The sandbox pre-executes and analyzes the data for malicious behavior, so that by the time the original data is needed, the security assessment is already complete, eliminating latency during access operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security system is segmented into independent components: data copying to sandbox, execution in isolated environment, analysis of behavior, and final security determination. This segmentation allows the scanning process to occur in parallel with data preparation, rather than blocking the entire data flow.

Inventive Principle:
Principle #1Segmentation

2Reliability

If inline inspection devices are introduced into the network, then security scanning capability is improved, but normal operation of network components is disrupted

Engineering Contradiction:
Improvesecurity scanning capabilityVSAvoidnormal operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

A sandbox environment acts as an intermediary between the network and the inspection process. Data is copied to this isolated intermediate environment for analysis, allowing security scanning to occur without the inspection device directly interfering with or disrupting the normal operation of network components.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of inspecting the original data flow directly, the system creates a copy of the data and places it in a sandbox environment for inspection. This copying approach allows security analysis to proceed on the duplicate while the original data continues to flow through the network unaffected.

Inventive Principle:
Principle #26Copying

3Reliability

If encrypted traffic is transmitted for cloud services, then data privacy and security are improved, but inspection capability is reduced

Engineering Contradiction:
Improvedata privacyVSAvoidinspection capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary copying of encrypted data to a sandbox environment before decryption and inspection. By preparing the data copy in advance in a controlled environment, the system can later decrypt and inspect it without compromising the privacy of the original encrypted transmission during normal operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10509917B2Cloud security platform
Publication Date: 2019.12.17 AVANAN INC
  • US10509917B2 patent drawing
  • US10509917B2 patent drawing
  • US10509917B2 patent drawing

AI summary

A data security system, including a security manager computer making network API calls to a service that performs data-exchange transactions for end users, the API calls remotely controlling the service so that the security manager computer accesses an outgoing transaction that has already entered the cloud-based service, by generating one or more security platform rules that are applied by the service and cause the service to automatically transmit the outgoing transaction to an inspection location prior to transmission of the outgoing transaction to a destination, and a data inspector operative to inspect data of the outgoing transaction in the inspection location for data leakage, wherein the security manager computer further controls the service so as to transmit the outgoing transaction to the destinations when the data inspector clears the data, and to perform a remedial action regarding the outgoing transaction when the data inspector does not clear the data.