Dynamic Whitelist Proxy for Encrypted Traffic Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional secure web gateways struggle to handle increasing volumes of encrypted network traffic due to CPU resource dependencies, leading to inefficiencies and security vulnerabilities when using static whitelists that bypass decryption and inspection.

Innovation Solution

A dynamic whitelist proxy that selectively decrypts outbound traffic flows to determine potential malicious activity, using machine learning and security intelligence engines to dynamically manage whitelists, thereby reducing the need for full decryption of all packets and enhancing security by continuously monitoring and updating whitelist policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If proxies decrypt all outbound encrypted traffic to inspect for malicious activity, then security detection capability is improved, but CPU resource consumption increases exponentially

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidCPU resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements dynamic whitelist management where the proxy selectively decrypts traffic based on real-time security intelligence updates. The system transitions from static to dynamic whitelist policies, adapting decryption requirements based on current threat intelligence rather than maintaining fixed decryption rules

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments traffic handling into two paths: whitelisted traffic that bypasses decryption and inspection, and non-whitelisted traffic that undergoes full security inspection. This segmentation allows the system to process only necessary traffic through resource-intensive decryption operations

Inventive Principle:
Principle #1Segmentation

2Use of energy by moving object

If organizations implement static whitelists to bypass proxy inspection, then CPU resource usage is reduced, but security vulnerabilities increase due to unmonitored traffic

Engineering Contradiction:
ImproveCPU resource usageVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Use of energy by moving objectVSObject-affected harmful factors

Solution Approach 1:

The patent implements continuous feedback loops where security intelligence engines monitor threats and automatically update whitelist policies. The system receives feedback from threat intelligence sources and adjusts whitelist status in real-time, ensuring whitelisted traffic remains under security oversight while maintaining performance benefits

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary security assessment by maintaining whitelists based on pre-analyzed trusted traffic patterns. Security intelligence engines pre-evaluate traffic destinations and proactively add trustworthy sources to whitelists before malicious activity occurs, preventing resource consumption while maintaining security

Inventive Principle:
Principle #10Preliminary action

3Reliability

If proxies inspect all encrypted traffic, then detection of malicious activity is improved, but processing speed decreases due to computational overhead

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent dynamically adjusts inspection intensity based on traffic classification. High-volume trusted traffic flows are dynamically routed through whitelist paths that bypass decryption, while suspicious or unknown traffic receives full inspection treatment, optimizing both detection accuracy and processing throughput

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10771436B2Dynamic whitelist management
Publication Date: 2020.09.08 CISCO TECHNOLOGY INC
  • US10771436B2 patent drawing
  • US10771436B2 patent drawing
  • US10771436B2 patent drawing

AI summary

In one example embodiment, a proxy for a network obtains a traffic flow. The proxy determines whether a security policy in a whitelist for the traffic flow is active. If it is determined that the security policy for the traffic flow is active, the proxy selectively decrypts the traffic flow to produce one or more traffic flow attributes and, based on the one or more traffic flow attributes, determines whether the traffic flow is potentially malicious.