Network Services Platform Bypassing NAT for Remote Inspection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Smaller enterprises with fewer than 100 network devices face impracticality and unaffordability with appliance-based network security tools, and cloud-based tools struggle to inspect hidden enterprise networks due to NAT and firewalls, limiting their ability to provide detailed network services.
Innovation Solution
A method and platform that establish an Internet Protocol (IP) tunnel and bridge between a remote services platform and an enterprise network, enabling network services by providing a control module to an endpoint, which creates an IP tunnel and bridges it with the enterprise network, allowing for secure and detailed network analysis and service provision.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If appliance-based network security tools are deployed, then network security and compliance auditing are improved, but device cost and complexity increase significantly making them impractical for smaller enterprises
Solution Approach 1:
The patent introduces a router as an intermediary device that performs network address translation (NAT) and acts as a gateway between the enterprise network and external cloud-based analysis tools. The router enables remote inspection capabilities while maintaining network security boundaries, allowing smaller enterprises to access professional-grade network analysis without deploying expensive appliances on-premises.
2Device complexity
If cloud-based network analysis tools are used, then device cost is reduced, but the ability to inspect enterprise network details is limited due to NAT and firewall protection
Solution Approach 1:
The patent segments the network inspection functionality into two parts: a cloud-based analysis platform that provides the analytical engine, and a lightweight router component that provides network access and NAT capabilities. This segmentation allows the cloud platform to inspect network traffic by having the router forward relevant traffic to external analysis tools while maintaining the enterprise network's security boundaries.
Solution Approach 2:
The router serves as an intermediary that bridges the cloud-based analysis tools and the enterprise network. It performs NAT to allow external tools to reach internal network segments while maintaining security, and forwards selected traffic to cloud-based analysis platforms for detailed inspection without requiring direct access to the enterprise network infrastructure.
3Reliability
If a router performs NAT and firewall functions, then network security is improved, but remote inspection of the enterprise network becomes impossible
Solution Approach 1:
The patent implements dynamic traffic routing where the router selectively forwards specific types of traffic to cloud-based analysis tools while maintaining NAT protection for the enterprise network. The system dynamically determines which traffic should be inspected externally versus which should remain protected behind the NAT boundary, allowing flexible remote inspection capabilities while maintaining security.
Data Source
AI summary
A network services platform provides services to remote enterprise networks. The services platform provides a control module to a computer in the enterprise network. The control module executes on the computer and interacts with the services platform to establish an Internet Protocol (IP) tunnel between the services platform and the computer. The control module also establishes a bridge between the IP tunnel and the enterprise network. The services platform allocates a unique private IP address space to the enterprise network, and translates IP addresses in network communications between enterprise network addresses and corresponding services platform addresses in the allocated unique private address space. The services platform provides network services to the enterprise network via the IP tunnel and bridge.


