Encryption-Aware Visibility Device for Encrypted Traffic Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Active SSL inspection methods introduce performance bottlenecks in monitoring encrypted network traffic due to the need for decrypting and re-encrypting SSL traffic, which is computationally expensive and resource-intensive.
Innovation Solution
An encryption-aware visibility (EAV) device receives session decryption information from a secure session management server via a secure backchannel interface, allowing it to decrypt encrypted network traffic flows without acting as a man-in-the-middle, thereby reducing processing overhead.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If active SSL inspection is used to monitor encrypted traffic, then network visibility is improved, but processing performance deteriorates due to decrypting and re-encrypting overhead
Solution Approach 1:
The patent extracts the SSL decryption function from the network monitoring device and places it on a separate SSL server. The monitoring device only receives decrypted traffic from the SSL server, eliminating the need for it to perform computationally expensive decrypting and re-encrypting operations while maintaining full network visibility.
Solution Approach 2:
The patent introduces an SSL server as an intermediary component between the encrypted traffic source and the network monitoring device. This SSL server acts as a mediator that handles all SSL decryption and re-encryption operations, allowing the monitoring device to focus solely on analyzing decrypted traffic without performance degradation.
2Loss of information
If SSL traffic is decrypted and re-encrypted by a MITM device, then clear-text copying for monitoring is achieved, but resource consumption increases
Solution Approach 1:
The patent extracts the computationally intensive SSL decryption and re-encryption operations from the network monitoring device and relocates them to a dedicated SSL server. This separation allows the monitoring device to access clear-text traffic without bearing the computational burden of SSL processing.
Solution Approach 2:
The SSL server autonomously handles all SSL decryption and re-encryption operations without requiring the network monitoring device to intervene in the SSL processing chain. The SSL server serves itself by managing the cryptographic operations and providing decrypted traffic to monitoring tools.
Data Source
AI summary
Methods, systems, and computer readable media for monitoring encrypted packet communications are disclosed. According to one method executed at an encryption aware visibility (EAV) device, the method includes receiving copies of encrypted network traffic flow records belonging to at least one communication session involving a monitored application and obtaining, from a secure session management (SSM) server, session decryption information (SDI) via a secure backchannel interface connection, wherein the session decryption information includes cryptographic keys generated by the SSM server to establish the at least one communication session. The method further includes using the cryptographic keys to decrypt the copies of encrypted network traffic flow records to produce decrypted network traffic flow records.


