Context Agent for Encrypted Traffic Security Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network security devices face difficulties in detecting malware and ascertaining actionable information from encrypted network traffic, due to techniques like HTTPS and certificate pinning, as well as user-agent impersonation, which hinders effective security policy implementation.
Innovation Solution
Incorporating context information into in-band communications between endpoint devices and network security devices using a context agent, which collects and inserts context headers into network traffic, enabling the network security device to apply appropriate security policies based on the ascertained information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network security devices inspect network traffic to ascertain actionable information, then security policy application is improved, but the ability to detect encrypted traffic and evade techniques deteriorates
Solution Approach 1:
The patent introduces an intermediary context sharing mechanism that operates between the endpoint device and network security device. This intermediary layer collects contextual information from the endpoint and transmits it to the network security device, enabling enhanced detection capabilities without directly inspecting encrypted traffic. The context agent acts as a mediator that bridges the gap between encrypted traffic and security analysis capabilities.
Solution Approach 2:
The patent shifts the detection dimension from traditional network traffic inspection to endpoint context collection. Instead of attempting to decrypt and inspect encrypted network traffic, the system collects contextual information at the endpoint dimension (process information, file hashes, network connections) and transmits this to the network security device for analysis. This dimensional shift enables security policies to be applied based on rich contextual data rather than encrypted packet contents.
2Measurement precision
If context information is collected and transmitted from endpoint device, then detection accuracy is improved, but communication overhead and system complexity increase
Solution Approach 1:
The patent extracts only the necessary contextual information from the endpoint device and transmits it to the network security device. The context agent selectively collects specific attributes (process information, file hashes, network connections) rather than transmitting all endpoint data. This extraction approach maintains detection accuracy while minimizing the volume of data transmitted and processed, thereby reducing system complexity.
Solution Approach 2:
The context agent performs preliminary collection and processing of contextual information at the endpoint device before transmission to the network security device. By preparing and filtering the context data locally, the system reduces the burden on the network security device and minimizes transmission overhead. This preliminary action ensures that only relevant and processed information is transmitted, enhancing detection accuracy without proportionally increasing system complexity.
Data Source
AI summary
A network security device (NSD) is connected between a network and an endpoint device configured to host a client application. The client application communicates with the network through the network security device using a request-response protocol. The NSD receives from the client application a request destined for the network and that seeks a response from the network. The request has a context header including context information about the client application. The NSD determines whether the client application or a file accessed thereby has a suspicious nature based on the context information. If it is determined that the client application or the file accessed thereby has a suspicious nature, the NSD blocks the request from the network, and sends to the client application a response indicating the block.


