Network Traffic Inspection via OS Extension Service

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network traffic inspection methods face security vulnerabilities due to elevated privileges and require user-initiated launches, leading to potential breaches and performance degradation, while remote analysis introduces latency and increased costs.

Innovation Solution

A security application is installed as an operating system extension, utilizing a network extension service like the VPN stack to intercept and analyze network traffic locally, reducing latency and power consumption, and ensuring continuous protection without user intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security application is installed with enhanced privileges to access network traffic, then network traffic inspection capability is improved, but security vulnerabilities increase due to elevated privileges

Engineering Contradiction:
Improvenetwork traffic inspection capabilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a network extension service as an intermediary layer between the security application and the network traffic. This service provides a sandboxed environment that allows traffic inspection without requiring the security application to have direct elevated privileges, thus resolving the contradiction between inspection capability and security vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If a security application is installed as a standard application requiring user launch, then installation simplicity is improved, but continuous protection is compromised due to potential user neglect

Engineering Contradiction:
Improveinstallation simplicityVSAvoidcontinuous protection
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The security application is configured to launch automatically at system startup through the network extension service framework. This preliminary action ensures continuous protection is established before the user needs it, eliminating the need for manual user intervention while maintaining ease of installation.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If network traffic is sent to remote server for analysis, then analysis capability is improved, but latency increases and power consumption increases

Engineering Contradiction:
Improveanalysis capabilityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the network traffic analysis function from remote servers and implements it locally through the network extension service framework. This allows the device to perform security analysis independently without relying on remote servers, thereby eliminating latency and reducing power consumption while maintaining analysis capability.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If network traffic is sent to remote server for analysis, then analysis capability is improved, but data charges increase

Engineering Contradiction:
Improveanalysis capabilityVSAvoiddata charges
Core Design Contradiction:
ReliabilityVSLoss of substance

Solution Approach 1:

The patent extracts the analysis function locally, eliminating the need to transmit network traffic data to remote servers. This extraction of computational functionality allows the device to perform security analysis using local resources, thereby avoiding additional data charges while maintaining comprehensive analysis capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11463460B1Network traffic inspection
Publication Date: 2022.10.04 BARRACUDA NETWORKS INC
  • US11463460B1 patent drawing
  • US11463460B1 patent drawing
  • US11463460B1 patent drawing

AI summary

Techniques for inspecting network traffic are disclosed. An application executing as an operating system extension that uses a virtual private network (VPN) stack of the operating system intercepts an Internet protocol (IP) packet for delivery to a remote computer system. A determination is made of an alteration action to take in response to intercepting the packet. The determined action is taken.