Encrypted Traffic Inspection via Application Reputation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Maintaining a bypass list for HTTPS traffic in network security devices is cumbersome and error-prone, as it requires manual entry of server addresses to bypass inspection, which is inefficient and prone to errors.

Innovation Solution

A network security device monitors encrypted traffic between a server and client device, generates metadata for cloud security systems to determine the reputation of applications, and either decrypts and inspects traffic for browser applications or allows non-browser applications to bypass inspection based on their reputation, eliminating the need for a manual bypass list.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual bypass list maintenance is used for HTTPS traffic, then security policy enforcement is simplified, but operational efficiency deteriorates due to cumbersome and error-prone manual entry

Engineering Contradiction:
Improvebypass list maintenanceVSAvoidtime for manual entry and maintenance
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system automatically generates bypass lists by analyzing application behavior and metadata without requiring manual administrator intervention. The network security device autonomously determines which applications should bypass inspection based on their characteristics and reputation, eliminating the need for manual bypass list maintenance while improving operational efficiency

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary analysis of applications during the metadata collection phase, gathering information about application behavior, characteristics, and reputation before security policy enforcement is needed. This advance preparation enables automatic bypass list generation without time-consuming manual entry when policies need to be enforced

Inventive Principle:
Principle #10Preliminary action

2Reliability

If all HTTPS traffic is inspected, then security detection capability is improved, but system performance deteriorates due to decryption and inspection overhead

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies different inspection strategies to different applications based on their specific characteristics and reputations. Browser applications with good reputations receive full inspection, while non-browser applications with good reputations receive bypass treatment. This localized quality approach ensures security where needed while maintaining performance where not required

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs partial inspection by selectively applying decryption and deep packet inspection only to applications that require it based on their reputation and type. Instead of inspecting all HTTPS traffic uniformly, the system applies inspection actions only where necessary, reducing overall system overhead while maintaining adequate security detection capability

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If browser applications are decrypted and inspected, then security monitoring is improved, but privacy concerns increase due to encrypted traffic decryption

Engineering Contradiction:
Improvesecurity monitoringVSAvoidprivacy concerns
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system segments HTTPS traffic into different categories (browser applications vs. non-browser applications) and applies different inspection levels to each segment. Browser applications, which users typically expect to have higher privacy expectations, receive full inspection only when necessary, while non-browser applications receive bypass treatment by default. This segmentation allows the system to balance security monitoring needs with privacy concerns on a per-application basis

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10805320B1Methods and systems for inspecting encrypted network traffic
Publication Date: 2020.10.13 TREND MICRO INC
  • US10805320B1 patent drawing
  • US10805320B1 patent drawing
  • US10805320B1 patent drawing

AI summary

Encrypted network traffic between a server device and an application program running on a client device is monitored by a network security device in an enterprise computer network. Metadata of the application program is sent to a cloud security system to generate a reputation of the application program. The encrypted network traffic is decrypted and inspected for conformance with security policies when the application program is determined to be a browser application. When the application program is determined to be a non-browser application, the reputation of the application program is determined and the encrypted network traffic is blocked when the application program has a bad reputation. In a bypass mode of operation, the encrypted network traffic is allowed to pass through without inspection when the application program is determined to be a non-browser application.