In-Band CASB Observability for Real-Time Cloud Transaction Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current inline Cloud Access Security Brokers (CASBs) lack real-time visibility into application transactions within cloud application services, particularly regarding transaction risks and runtime vulnerabilities, limiting their effectiveness in securing cloud environments.

Innovation Solution

Implementing a Real-Time Transaction Integration Protocol (RTIP) for enhanced CASB functionality by integrating a CASB with an embedded application security service like RASP, enabling in-band, real-time, extensible, and secure full-duplex communications using JSON Web Tokens (JWTs) to insert and read security metadata directly within HTTP request and response headers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If CASB uses traditional out-of-band monitoring, then device complexity is reduced, but real-time visibility into application transactions is lost

Engineering Contradiction:
Improvevisibility into application transactionsVSAvoidCASB architecture complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent embeds the CASB functionality within the application runtime environment itself, nesting security monitoring capabilities inside the application execution context. This allows the CASB to access transaction data directly from within applications without requiring separate complex monitoring infrastructure, thereby gaining real-time visibility while managing complexity through integration rather than addition of separate systems.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent introduces a runtime instrumentation layer that acts as an intermediary between the application and the CASB. This intermediary captures transaction metadata and security events from within the application runtime and delivers them to the CASB, enabling real-time visibility while simplifying the overall architecture by providing a standardized interface layer that abstracts the complexity of deep application instrumentation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If CASB implements real-time monitoring, then security response capability is improved, but processing time increases

Engineering Contradiction:
Improvesecurity decision accuracyVSAvoidtransaction processing delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies security monitoring and analysis capabilities locally within the application runtime environment itself, rather than centrally processing all transactions remotely. By embedding security functions directly where transactions occur, the system achieves real-time security decisions with minimal processing delay, as security checks happen in-line during transaction execution rather than requiring separate analysis cycles.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements selective monitoring of specific security-relevant transactions and events rather than processing all application traffic uniformly. By focusing real-time analysis only on transactions that meet security criteria or involve sensitive operations, the system maintains high security response capability while reducing overall processing time for the majority of routine transactions.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If CASB integrates with embedded security services, then security coverage is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity service integration capabilityVSAvoidintegration architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal runtime instrumentation framework that can integrate multiple different security services and monitoring capabilities through a common interface. This multi-functional platform allows the CASB to connect with various embedded security services (authentication, authorization, data protection, threat detection) without requiring separate integration architectures for each service, thereby improving security coverage while managing complexity through standardization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent divides the security integration architecture into modular, independently deployable security services that can be selectively activated. Each security function operates as a separate module within the application runtime, allowing the CASB to integrate only the security capabilities needed for specific transactions or environments. This segmentation reduces overall integration complexity by enabling incremental adoption of security services rather than requiring complete system integration.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12375482B2Enhanced cloud access security broker functionality utilizing in-band application observability
Publication Date: 2025.07.29 CISCO TECHNOLOGY INC
  • US12375482B2 patent drawing
  • US12375482B2 patent drawing
  • US12375482B2 patent drawing

AI summary

Provided herein are techniques to facilitate enhanced cloud access security broker (CASB) functionality via in-band application observability in which a CASB can be implemented in-line between the client device and an embedded application security service. In one instance, a method may include, obtaining, by a CASB from a client device, a first message for an application transaction involving an application operating via the client device. The first message can be augmented to include first security metadata and can be forwarded to trigger one or more actions by an embedded application security service associated with the application. The CASB may obtain a second message from the embedded application security service that includes second security metadata, and one or more actions can be triggered at the CASB based, at least in part, on the second security metadata included in the second message.