Inline TCP Content Inspection Without Connection Termination
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional network content inspection and modification methods, such as those using network proxies, suffer from poor performance, lack of scalability, and high deployment and maintenance costs due to requirements like connection termination and re-origination, data copying, and manual configuration.
Innovation Solution
A network appliance is configured to provide inline traffic inspection and modification without connection termination and re-origination, allowing for selective interception and modification of traffic content while maintaining TCP session integrity through sequence number translations and endpoint-driven retransmission management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional network proxies are used for content inspection and modification, then content security can be provided, but performance deteriorates and scalability is limited due to connection termination and re-origination requirements
Solution Approach 1:
The patent extracts the content inspection and modification functionality from the traditional proxy architecture, allowing it to operate inline within the existing TCP session without requiring connection termination. This enables security functions to be performed while maintaining the original connection's performance characteristics and scalability.
Solution Approach 2:
The patent introduces an intermediary mechanism that allows content inspection and modification to occur transparently within the TCP session. The system acts as a mediator that can rewrite content without terminating the connection, thereby maintaining performance while providing security functions.
2Reliability
If network proxies are used for content inspection, then security functions can be performed, but device complexity and deployment costs increase due to manual configuration requirements
Solution Approach 1:
The patent implements self-service functionality where the system automatically manages TCP session state and handles content inspection without requiring manual configuration. The appliance provisions itself into cloud-based deployments and manages its own operation, significantly reducing deployment and maintenance complexity.
3Reliability
If traditional proxy architecture is used, then content inspection can be performed, but scalability is limited due to dependency on operating system resources such as network buffers, file descriptors, and TCP ports
Solution Approach 1:
The patent makes the content inspection capability universal by allowing it to operate on any TCP session without being limited by traditional proxy resource constraints. The system can handle multiple concurrent connections efficiently by leveraging the existing TCP stack's resource management mechanisms.
Solution Approach 2:
The patent changes the operational parameters of content inspection from traditional proxy-mode (connection termination, data copying) to inline-mode (session maintenance, streaming rewrite). This parameter change enables the system to scale effectively by eliminating dependencies on limited OS resources like network buffers and file descriptors.
Data Source
AI summary
A network appliance is configured to provide inline traffic inspection for all flow through the device, to selectively intercept based on traffic content or policy, and to modify intercepted traffic content, all without connection termination and re-origination. Content modification may involve substitution of traffic content with smaller or larger content, in which case the device provides appropriate sequence number translations for acknowledgements to the endpoints. This streaming rewrite may occur on a byte-at-a-time basis, while keeping the session alive and without a need to proxy it. The appliance enables transmitted TCP data to be modified inline and then reliably delivered without the overhead of forwarding packets through a full-blown TCP stack. Rather, the approach relies upon an initiator entity's TCP stack for congestion control, as well as the receiving entity's re-transmission behavior to determine how the device manages packets internally.


