Host-Gateway Interlocking via Content Tags for Encrypted Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security technologies are inadequate in effectively preventing malicious software from exploiting host computers, as they often fail to detect and filter encrypted malicious traffic, leading to unauthorized access and data theft, and overly restrictive policies can hinder legitimate business activities.

Innovation Solution

A system and method that interlock a host and a network gateway through information sharing by tagging files based on content and sharing these tags with the gateway, which filters network traffic based on the content tags and session information, using a host agent and a data-at-rest server to classify and index files, and applying network policies to ensure secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current network security technologies are used to filter malicious traffic, then unauthorized access can be blocked, but encrypted malicious traffic cannot be detected and filtered

Engineering Contradiction:
Improvedetection accuracyVSAvoidencrypted malicious traffic
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary classification and tagging of files before they are transmitted over the network. The host agent analyzes files locally and assigns content tags that describe the file's purpose and sensitivity. This pre-processing allows the gateway to make security decisions based on the tags without needing to decrypt or deeply inspect the actual file contents, thus resolving the contradiction between detecting malicious traffic and handling encrypted traffic.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces content tags as an intermediary mechanism between the host and gateway. Instead of directly inspecting encrypted file contents at the gateway, the system uses tags as a mediator that carries essential information about the file's nature. The gateway enforces policies based on these tags without needing to decrypt the underlying encrypted data, thus maintaining security while enabling effective filtering.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If restrictive network policies are applied to prevent malicious activities, then security is improved, but legitimate business activities are hindered

Engineering Contradiction:
ImprovesecurityVSAvoidbusiness activities
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies different security policies based on the local quality or characteristics of each file as indicated by its content tag. Instead of applying uniform restrictive policies to all traffic, the gateway evaluates each file's tag and applies appropriate policies. For example, sensitive files may receive stricter controls while routine business files receive more permissive treatment. This granular approach maintains security for critical resources while facilitating legitimate business operations.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The security policy enforcement is dynamic rather than static. The gateway adjusts the level of security control based on the content tag of each file and the current network context. Files with tags indicating high sensitivity or potential malicious content receive stricter filtering, while files with tags indicating legitimate business purposes receive more permissive handling. This dynamic adaptation resolves the contradiction between security and ease of operation.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If comprehensive file analysis is performed to classify all files, then accurate content tagging is achieved, but processing time and system resources are consumed

Engineering Contradiction:
Improvecontent classification accuracyVSAvoidfile processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The host agent performs partial analysis of files to generate content tags rather than comprehensive analysis of every file's complete contents. The system focuses on extracting key identifying features and characteristics needed for classification, rather than performing exhaustive inspection. This partial action approach achieves sufficient classification accuracy for security purposes while significantly reducing processing time and resource consumption compared to complete file analysis.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9413785B2System and method for interlocking a host and a gateway
Publication Date: 2016.08.09 MCAFEE LLC
  • US9413785B2 patent drawing
  • US9413785B2 patent drawing
  • US9413785B2 patent drawing

AI summary

A method is described in example embodiments below that include receiving a content tag associated with transferring a file over a network connection. A session descriptor may also be received. The session descriptor and the content tag may be correlated with a network policy, which may be applied to the network connection. In some embodiments, the content tag may be received with the session descriptor. The file may be tainted by another file in some embodiments, and the content tag may be associated with other file.