Endpoint-Assisted Encrypted Traffic Inspection for Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network inspection techniques, such as deep packet inspection (DPI), are ineffective against encrypted network traffic, particularly with the increasing use of encryption in malware and other malicious activities, making it difficult to distinguish between benign and malicious traffic.
Innovation Solution
A traffic inspection service, executed by an intermediary device, obtains keying information from a monitoring agent on an endpoint device to decrypt encrypted traffic sessions, applying policies based on the decrypted traffic without resorting to a man-in-the-middle approach.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If deep packet inspection (DPI) is used to inspect network traffic, then the ability to identify threats and prevent sensitive data communication is improved, but the effectiveness deteriorates when traffic is encrypted
Solution Approach 1:
The patent introduces an intermediary device positioned between the endpoint and the remote server that acts as a man-in-the-middle proxy. This intermediary establishes separate encrypted connections with both the endpoint and the server, allowing it to intercept, decrypt, inspect, and re-encrypt traffic without the endpoints being aware of the inspection process. The intermediary serves as a mediator that enables security inspection while preserving the encrypted communication channels.
Solution Approach 2:
The patent segments the communication path into multiple independent encrypted connections: one between the endpoint and the intermediary, and another between the intermediary and the remote server. This segmentation allows the intermediary to handle decryption and inspection operations independently for each connection, enabling threat detection in encrypted traffic without requiring the endpoints to modify their encryption or awareness of the inspection process.
2Reliability
If encryption is used to protect network traffic, then privacy and security are improved, but the ability to detect malware and malicious activities deteriorates
Solution Approach 1:
The intermediary device serves as a trusted mediator that both endpoints and the server can rely on for secure communication. The endpoint establishes an encrypted connection with the intermediary, and the intermediary establishes another encrypted connection with the server. This allows the intermediary to access and inspect the plaintext traffic for malware detection while both endpoints maintain their belief that they are communicating securely through end-to-end encryption.
Solution Approach 2:
The patent replaces the traditional mechanical approach of endpoint-based security inspection with a network-based intermediary inspection system. Instead of requiring endpoints to have inspection capabilities or to communicate in plaintext, the system substitutes the inspection function to a network intermediary that performs decryption, inspection, and re-encryption operations, thereby maintaining encryption end-to-end from the perspective of the endpoints while enabling effective security inspection.
3Adaptability or versatility
If man-in-the-middle inspection is implemented, then encrypted traffic inspection capability is improved, but the complexity of the system increases
Solution Approach 1:
The intermediary device is designed as a universal security appliance that combines multiple functions: it acts as an encrypted traffic inspector, a man-in-the-middle proxy, a certificate authority for establishing trusted connections, and a security policy enforcement point. By consolidating these diverse functions into a single multi-functional device, the patent reduces the need for separate specialized systems and simplifies the overall network architecture despite the advanced capabilities provided.
Data Source
AI summary
In one embodiment, a traffic inspection service executed by an intermediary device obtains, from a monitoring agent executed by an endpoint device, keying information for an encrypted traffic session between the endpoint device and a remote entity. The traffic inspection service provides a notification to the monitoring agent that acknowledges receipt of the keying information. The traffic inspection service uses the keying information to decrypt encrypted traffic from the encrypted traffic session. The traffic inspection service applies a policy to the encrypted traffic session between the endpoint device and the remote entity, based on the decrypted traffic from the session.


