Host-Gateway Interlocking via Content Tags for Encrypted Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security technologies are inadequate in effectively preventing malicious software from exploiting host computers, as they often fail to detect and filter encrypted malicious traffic, leading to unauthorized access and data theft, and overly restrictive policies can hinder legitimate business activities.
Innovation Solution
A system and method that interlock a host and a network gateway through information sharing by tagging files based on content and sharing these tags with the gateway, which filters network traffic based on the content tags and session information, using a host agent and a data-at-rest server to classify and index files, and applying network policies to ensure secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current network security technologies are used to filter malicious traffic, then unauthorized access can be blocked, but encrypted malicious traffic cannot be detected and filtered
Solution Approach 1:
The system performs preliminary classification and tagging of files before they are transmitted over the network. The host agent analyzes files locally and assigns content tags that describe the file's purpose and sensitivity. This pre-processing allows the gateway to make security decisions based on the tags without needing to decrypt or deeply inspect the actual file contents, thus resolving the contradiction between detecting malicious traffic and handling encrypted traffic.
Solution Approach 2:
The patent introduces content tags as an intermediary mechanism between the host and gateway. Instead of directly inspecting encrypted file contents at the gateway, the system uses tags as a mediator that carries essential information about the file's nature. The gateway enforces policies based on these tags without needing to decrypt the underlying encrypted data, thus maintaining security while enabling effective filtering.
2Reliability
If restrictive network policies are applied to prevent malicious activities, then security is improved, but legitimate business activities are hindered
Solution Approach 1:
The system applies different security policies based on the local quality or characteristics of each file as indicated by its content tag. Instead of applying uniform restrictive policies to all traffic, the gateway evaluates each file's tag and applies appropriate policies. For example, sensitive files may receive stricter controls while routine business files receive more permissive treatment. This granular approach maintains security for critical resources while facilitating legitimate business operations.
Solution Approach 2:
The security policy enforcement is dynamic rather than static. The gateway adjusts the level of security control based on the content tag of each file and the current network context. Files with tags indicating high sensitivity or potential malicious content receive stricter filtering, while files with tags indicating legitimate business purposes receive more permissive handling. This dynamic adaptation resolves the contradiction between security and ease of operation.
3Measurement precision
If comprehensive file analysis is performed to classify all files, then accurate content tagging is achieved, but processing time and system resources are consumed
Solution Approach 1:
The host agent performs partial analysis of files to generate content tags rather than comprehensive analysis of every file's complete contents. The system focuses on extracting key identifying features and characteristics needed for classification, rather than performing exhaustive inspection. This partial action approach achieves sufficient classification accuracy for security purposes while significantly reducing processing time and resource consumption compared to complete file analysis.
Data Source
AI summary
A method is described in example embodiments below that include receiving a content tag associated with transferring a file over a network connection. A session descriptor may also be received. The session descriptor and the content tag may be correlated with a network policy, which may be applied to the network connection. In some embodiments, the content tag may be received with the session descriptor. The file may be tainted by another file in some embodiments, and the content tag may be associated with other file.


