Endpoint-Assisted Encrypted Traffic Inspection for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network inspection techniques, such as deep packet inspection (DPI), are ineffective against encrypted network traffic, particularly with the increasing use of encryption in malware and other malicious activities, making it difficult to distinguish between benign and malicious traffic.

Innovation Solution

A traffic inspection service, executed by an intermediary device, obtains keying information from a monitoring agent on an endpoint device to decrypt encrypted traffic sessions, applying policies based on the decrypted traffic without resorting to a man-in-the-middle approach.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deep packet inspection (DPI) is used to inspect network traffic, then the ability to identify threats and prevent sensitive data communication is improved, but the effectiveness deteriorates when traffic is encrypted

Engineering Contradiction:
Improvethreat identification accuracyVSAvoidinspection effectiveness against encrypted traffic
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary device positioned between the endpoint and the remote server that acts as a man-in-the-middle proxy. This intermediary establishes separate encrypted connections with both the endpoint and the server, allowing it to intercept, decrypt, inspect, and re-encrypt traffic without the endpoints being aware of the inspection process. The intermediary serves as a mediator that enables security inspection while preserving the encrypted communication channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the communication path into multiple independent encrypted connections: one between the endpoint and the intermediary, and another between the intermediary and the remote server. This segmentation allows the intermediary to handle decryption and inspection operations independently for each connection, enabling threat detection in encrypted traffic without requiring the endpoints to modify their encryption or awareness of the inspection process.

Inventive Principle:
Principle #1Segmentation

2Reliability

If encryption is used to protect network traffic, then privacy and security are improved, but the ability to detect malware and malicious activities deteriorates

Engineering Contradiction:
Improvetraffic privacy protectionVSAvoidmalware detection capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The intermediary device serves as a trusted mediator that both endpoints and the server can rely on for secure communication. The endpoint establishes an encrypted connection with the intermediary, and the intermediary establishes another encrypted connection with the server. This allows the intermediary to access and inspect the plaintext traffic for malware detection while both endpoints maintain their belief that they are communicating securely through end-to-end encryption.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the traditional mechanical approach of endpoint-based security inspection with a network-based intermediary inspection system. Instead of requiring endpoints to have inspection capabilities or to communicate in plaintext, the system substitutes the inspection function to a network intermediary that performs decryption, inspection, and re-encryption operations, thereby maintaining encryption end-to-end from the perspective of the endpoints while enabling effective security inspection.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If man-in-the-middle inspection is implemented, then encrypted traffic inspection capability is improved, but the complexity of the system increases

Engineering Contradiction:
Improveencrypted traffic inspection capabilityVSAvoidsystem implementation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The intermediary device is designed as a universal security appliance that combines multiple functions: it acts as an encrypted traffic inspector, a man-in-the-middle proxy, a certificate authority for establishing trusted connections, and a security policy enforcement point. By consolidating these diverse functions into a single multi-functional device, the patent reduces the need for separate specialized systems and simplifies the overall network architecture despite the advanced capabilities provided.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12375505B2Endpoint-assisted inspection of encrypted network traffic
Publication Date: 2025.07.29 CISCO TECHNOLOGY INC
  • US12375505B2 patent drawing
  • US12375505B2 patent drawing
  • US12375505B2 patent drawing

AI summary

In one embodiment, a traffic inspection service executed by an intermediary device obtains, from a monitoring agent executed by an endpoint device, keying information for an encrypted traffic session between the endpoint device and a remote entity. The traffic inspection service provides a notification to the monitoring agent that acknowledges receipt of the keying information. The traffic inspection service uses the keying information to decrypt encrypted traffic from the encrypted traffic session. The traffic inspection service applies a policy to the encrypted traffic session between the endpoint device and the remote entity, based on the decrypted traffic from the session.