Encrypted SNI Filtering Using Hostname Resolution for Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems struggle to enforce communication policies when domain names in TLS-secured communications are encrypted using ESNI, as they cannot read the encrypted Server Name Indication (SNI) values, thereby compromising network protection and policy enforcement.
Innovation Solution
Cybersecurity applications detect encrypted hostnames, resolve them to plaintext, and apply packet-filtering rules based on cyber threat intelligence to enforce network policies, using methods like EDCL and DNS-QUERY-TRACKER to determine the plaintext domain names and mitigate threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If TLS encryption with ESNI is used to protect domain names, then network security and privacy are improved, but the ability to enforce communication policies and detect threats is worsened
Solution Approach 1:
The system performs preliminary actions by establishing correspondence between encrypted SNI values and plaintext domain names before policy enforcement is needed. EDCL files are pre-generated containing mappings of encrypted hostnames to their plaintext equivalents, enabling the packet filtering device to resolve and inspect domain names without breaking TLS encryption during actual policy enforcement operations.
Solution Approach 2:
The patent introduces an intermediary mechanism (EDCL correspondence system) that acts as a mediator between the encrypted SNI values and the policy enforcement system. Instead of directly decrypting or inspecting encrypted traffic, the system uses pre-established correspondence tables that map encrypted hostnames to plaintext domain names, allowing policy enforcement without compromising encryption or requiring full decryption capabilities.
2Loss of information
If encrypted SNI values are used in TLS handshakes, then privacy protection is improved, but network threat detection and policy compliance monitoring are worsened
Solution Approach 1:
The system performs preliminary actions by establishing correspondence between encrypted SNI values and plaintext domain names before policy enforcement is needed. EDCL files are pre-generated containing mappings of encrypted hostnames to their plaintext equivalents, enabling the packet filtering device to resolve and inspect domain names without breaking TLS encryption during actual policy enforcement operations.
Solution Approach 2:
The patent introduces an intermediary mechanism (EDCL correspondence system) that acts as a mediator between the encrypted SNI values and the policy enforcement system. Instead of directly decrypting or inspecting encrypted traffic, the system uses pre-established correspondence tables that map encrypted hostnames to plaintext domain names, allowing policy enforcement without compromising encryption or requiring full decryption capabilities.
3Ease of operation
If packet filtering devices inspect cleartext domain names, then policy enforcement is improved, but vulnerability to eavesdropping and malicious attacks is worsened
Solution Approach 1:
The system performs preliminary actions by establishing correspondence between encrypted SNI values and plaintext domain names before policy enforcement is needed. EDCL files are pre-generated containing mappings of encrypted hostnames to their plaintext equivalents, enabling the packet filtering device to resolve and inspect domain names without breaking TLS encryption during actual policy enforcement operations.
Solution Approach 2:
The patent introduces an intermediary mechanism (EDCL correspondence system) that acts as a mediator between the encrypted SNI values and the policy enforcement system. Instead of directly decrypting or inspecting encrypted traffic, the system uses pre-established correspondence tables that map encrypted hostnames to plaintext domain names, allowing policy enforcement without compromising encryption or requiring full decryption capabilities.
Data Source
AI summary
A packet-filtering system described herein may be configured to filter packets with encrypted hostnames in accordance with one or packet-filtering rules. The packet-filtering system may resolve a plaintext hostname from ciphertext comprising an encrypted Server Name Indication (eSNI) value. The packet-filtering system may resolve the plaintext hostname using a plurality of techniques. Once the plaintext hostname is resolved, the packet-filtering system may then use the plaintext hostname to determine whether the packets are associated with one or more threat indicators. If the packet-filtering system determines that the packets are associated with one or more threat indicators, the packet-filtering system may apply a packet filtering operation associated with the packet-filtering rules to the packets.


