Encrypted SNI Filtering Using Hostname Resolution for Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems struggle to enforce communication policies when domain names in TLS-secured communications are encrypted using ESNI, as they cannot read the encrypted Server Name Indication (SNI) values, thereby compromising network protection and policy enforcement.

Innovation Solution

Cybersecurity applications detect encrypted hostnames, resolve them to plaintext, and apply packet-filtering rules based on cyber threat intelligence to enforce network policies, using methods like EDCL and DNS-QUERY-TRACKER to determine the plaintext domain names and mitigate threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If TLS encryption with ESNI is used to protect domain names, then network security and privacy are improved, but the ability to enforce communication policies and detect threats is worsened

Engineering Contradiction:
Improvenetwork securityVSAvoidpolicy enforcement capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary actions by establishing correspondence between encrypted SNI values and plaintext domain names before policy enforcement is needed. EDCL files are pre-generated containing mappings of encrypted hostnames to their plaintext equivalents, enabling the packet filtering device to resolve and inspect domain names without breaking TLS encryption during actual policy enforcement operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism (EDCL correspondence system) that acts as a mediator between the encrypted SNI values and the policy enforcement system. Instead of directly decrypting or inspecting encrypted traffic, the system uses pre-established correspondence tables that map encrypted hostnames to plaintext domain names, allowing policy enforcement without compromising encryption or requiring full decryption capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If encrypted SNI values are used in TLS handshakes, then privacy protection is improved, but network threat detection and policy compliance monitoring are worsened

Engineering Contradiction:
Improveprivacy protectionVSAvoidthreat detection capability
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The system performs preliminary actions by establishing correspondence between encrypted SNI values and plaintext domain names before policy enforcement is needed. EDCL files are pre-generated containing mappings of encrypted hostnames to their plaintext equivalents, enabling the packet filtering device to resolve and inspect domain names without breaking TLS encryption during actual policy enforcement operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism (EDCL correspondence system) that acts as a mediator between the encrypted SNI values and the policy enforcement system. Instead of directly decrypting or inspecting encrypted traffic, the system uses pre-established correspondence tables that map encrypted hostnames to plaintext domain names, allowing policy enforcement without compromising encryption or requiring full decryption capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If packet filtering devices inspect cleartext domain names, then policy enforcement is improved, but vulnerability to eavesdropping and malicious attacks is worsened

Engineering Contradiction:
Improvepolicy enforcement efficiencyVSAvoideavesdropping vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by establishing correspondence between encrypted SNI values and plaintext domain names before policy enforcement is needed. EDCL files are pre-generated containing mappings of encrypted hostnames to their plaintext equivalents, enabling the packet filtering device to resolve and inspect domain names without breaking TLS encryption during actual policy enforcement operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism (EDCL correspondence system) that acts as a mediator between the encrypted SNI values and the policy enforcement system. Instead of directly decrypting or inspecting encrypted traffic, the system uses pre-established correspondence tables that map encrypted hostnames to plaintext domain names, allowing policy enforcement without compromising encryption or requiring full decryption capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20260046272A1Methods and Systems for Efficient Encrypted SNI Filtering for Cybersecurity Applications
Publication Date: 2026.02.12 CENTRIPETAL NETWORKS INC
  • US20260046272A1 patent drawing
  • US20260046272A1 patent drawing
  • US20260046272A1 patent drawing

AI summary

A packet-filtering system described herein may be configured to filter packets with encrypted hostnames in accordance with one or packet-filtering rules. The packet-filtering system may resolve a plaintext hostname from ciphertext comprising an encrypted Server Name Indication (eSNI) value. The packet-filtering system may resolve the plaintext hostname using a plurality of techniques. Once the plaintext hostname is resolved, the packet-filtering system may then use the plaintext hostname to determine whether the packets are associated with one or more threat indicators. If the packet-filtering system determines that the packets are associated with one or more threat indicators, the packet-filtering system may apply a packet filtering operation associated with the packet-filtering rules to the packets.