Encrypted Traffic Inspection via Application Reputation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Maintaining a bypass list for HTTPS traffic in network security devices is cumbersome and error-prone, as it requires manual entry of server addresses to bypass inspection, which is inefficient and prone to errors.
Innovation Solution
A network security device monitors encrypted traffic between a server and client device, generates metadata for cloud security systems to determine the reputation of applications, and either decrypts and inspects traffic for browser applications or allows non-browser applications to bypass inspection based on their reputation, eliminating the need for a manual bypass list.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual bypass list maintenance is used for HTTPS traffic, then security policy enforcement is simplified, but operational efficiency deteriorates due to cumbersome and error-prone manual entry
Solution Approach 1:
The system automatically generates bypass lists by analyzing application behavior and metadata without requiring manual administrator intervention. The network security device autonomously determines which applications should bypass inspection based on their characteristics and reputation, eliminating the need for manual bypass list maintenance while improving operational efficiency
Solution Approach 2:
The system performs preliminary analysis of applications during the metadata collection phase, gathering information about application behavior, characteristics, and reputation before security policy enforcement is needed. This advance preparation enables automatic bypass list generation without time-consuming manual entry when policies need to be enforced
2Reliability
If all HTTPS traffic is inspected, then security detection capability is improved, but system performance deteriorates due to decryption and inspection overhead
Solution Approach 1:
The system applies different inspection strategies to different applications based on their specific characteristics and reputations. Browser applications with good reputations receive full inspection, while non-browser applications with good reputations receive bypass treatment. This localized quality approach ensures security where needed while maintaining performance where not required
Solution Approach 2:
The system performs partial inspection by selectively applying decryption and deep packet inspection only to applications that require it based on their reputation and type. Instead of inspecting all HTTPS traffic uniformly, the system applies inspection actions only where necessary, reducing overall system overhead while maintaining adequate security detection capability
3Reliability
If browser applications are decrypted and inspected, then security monitoring is improved, but privacy concerns increase due to encrypted traffic decryption
Solution Approach 1:
The system segments HTTPS traffic into different categories (browser applications vs. non-browser applications) and applies different inspection levels to each segment. Browser applications, which users typically expect to have higher privacy expectations, receive full inspection only when necessary, while non-browser applications receive bypass treatment by default. This segmentation allows the system to balance security monitoring needs with privacy concerns on a per-application basis
Data Source
AI summary
Encrypted network traffic between a server device and an application program running on a client device is monitored by a network security device in an enterprise computer network. Metadata of the application program is sent to a cloud security system to generate a reputation of the application program. The encrypted network traffic is decrypted and inspected for conformance with security policies when the application program is determined to be a browser application. When the application program is determined to be a non-browser application, the reputation of the application program is determined and the encrypted network traffic is blocked when the application program has a bad reputation. In a bypass mode of operation, the encrypted network traffic is allowed to pass through without inspection when the application program is determined to be a non-browser application.


