Network Inspection Device Request Modification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security devices, such as intrusion protection systems, face difficulties in inspecting server-to-client traffic that is compressed or encoded, as they must first decompress or decode the data, which is not feasible at high speeds, leaving them vulnerable to malicious traffic.

Innovation Solution

An inspection device modifies the client request to prevent encoding and compression, allowing it to receive and inspect unencoded and uncompressed data, and takes appropriate action if encoded data is received, thereby enhancing the efficiency of traffic inspection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If the inspection device decompresses/decodes traffic for inspection, then inspection accuracy is improved, but processing speed deteriorates

Engineering Contradiction:
Improveinspection accuracyVSAvoidprocessing speed
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The inspection device modifies the client request header in advance to disable compression and encoding before the server processes the request. This preliminary action ensures that the server responds with uncompressed, unencoded data, eliminating the need for the inspection device to perform time-consuming decompression/decoding operations while maintaining full inspection capability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The inspection device acts as an intermediary between the client and server, modifying the request header to control the server's response format. By inserting itself into the communication flow and altering the request parameters, it ensures the server provides data in an inspectable format without requiring the inspection device to perform complex decompression operations

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the inspection device allows compression/encoding, then network performance is improved, but security inspection capability deteriorates

Engineering Contradiction:
Improvenetwork performanceVSAvoidsecurity inspection capability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The inspection device applies preliminary anti-action by modifying the client request to explicitly disable compression and encoding before the server can apply these transformations. This preemptive measure prevents malicious content from being compressed or encoded in the first place, maintaining security inspection capability while avoiding the performance overhead of decompression/decoding operations

Inventive Principle:
Principle #9Preliminary anti-action

3Measurement precision

If the inspection device inspects encoded/compressed traffic, then detection capability is improved, but processing overhead increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidprocessing overhead
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The inspection device performs preliminary action by modifying the request header to prevent compression and encoding before they occur. This ensures that the server response is already in a detectable format, maintaining full detection capability while eliminating the energy-intensive decompression/decoding process that would otherwise be required

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8037528B2Enhanced server to client session inspection
Publication Date: 2011.10.11 CISCO TECHNOLOGY INC
  • US8037528B2 patent drawing
  • US8037528B2 patent drawing
  • US8037528B2 patent drawing

AI summary

In one embodiment, a technique for enhancing the inspection of data sent from a server is provided. By modifying a client request in an effort to prevent the transformation (e.g., encoding and/or compression) of data by the server, unencoded data may be received, which can be inspected without the overhead associated with first decoding the data. Further, in the event the data is encoded despite modifying the client request to prevent such encoding, the server may be untrustworthy and one or more appropriate actions may be taken.