Packet Stitching for Cloud Security Traffic Visibility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises lose visibility into traffic steered to cloud-based security service providers due to encryption and session keys, hindering packet analysis, storage, and auditing.
Innovation Solution
A synthetic packet stream is generated by intercepting packets at a network security system gateway, extracting session keys, and stitching them with decrypted packets to create a bidirectional traffic representation, allowing enterprises to regain visibility and analysis capabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traffic is steered to cloud-based security providers using encryption and tunneling, then security services are protected, but the enterprise loses visibility into the traffic flow
Solution Approach 1:
The patent segments the packet stream into individual packets and processes them separately. The stitcher receives fragmented packet data from cloud security providers, reconstructs complete packets by assembling fragments in the correct sequence, and restores the original traffic flow representation. This segmentation allows the system to maintain security through cloud-based processing while regaining visibility through packet reconstruction.
Solution Approach 2:
The stitcher acts as an intermediary component between the cloud-based security provider and the enterprise. It receives encrypted and fragmented packet data from the cloud provider, performs reconstruction and decryption operations, and delivers restored traffic flow information to the enterprise. This intermediary function enables the enterprise to access traffic visibility without compromising the security protections provided by cloud-based services.
2Reliability
If packets are encrypted for security, then traffic protection is improved, but the enterprise cannot decrypt and analyze the packets
Solution Approach 1:
The system performs preliminary decryption actions at the stitcher before packet analysis. The stitcher receives encrypted packets from cloud security providers, decrypts them using appropriate keys, and then makes the plaintext packets available for enterprise analysis. This preliminary decryption action removes the barrier that would otherwise prevent the enterprise from analyzing encrypted traffic.
Solution Approach 2:
The stitcher serves as an intermediary that handles the decryption process between the cloud provider and the enterprise. It receives encrypted packets, performs decryption operations, and delivers decrypted packet data to the enterprise for analysis. This intermediary function enables packet analysis capability while maintaining the security architecture of cloud-based services.
3Extent of automation
If cloud-based security services are used, then security analysis is centralized, but the enterprise cannot reliably capture traffic from client devices
Solution Approach 1:
The patent uses copying to create packet representations that can be reliably captured and transmitted. Instead of attempting to capture actual traffic at client devices, the system copies packet data from the cloud-based security provider where traffic flow is already controlled and predictable. These copied packet representations are then stitched together to create accurate traffic flow information that can be reliably captured and stored.
Solution Approach 2:
The system performs preliminary packet capture at the cloud security provider before data returns to client devices. By capturing packets at this centralized point where traffic is controlled and standardized, the system ensures reliable capture accuracy. The stitched packet representations are then made available for enterprise analysis, providing reliable traffic capture without requiring deployment at dispersed client locations.
Data Source
AI summary
A cloud-based network security system that includes a packet tap and exposes a synthetic packet stream representing the bidirectional data between enterprise client devices and cloud hosted services is disclosed. The security system intercepts packets of communication sessions and uploads a copy of the packets to cloud storage. A proxy of the security system derives session keys for the communication session and uploads the session keys to the cloud storage. An enterprise stitcher obtains the packets from the cloud storage, stitches the packets together in sequential order, and modifies the Layer 3 and Layer 4 headers to generate synthetic packet streams representing the communication sessions. The stitcher may decrypt the packets or provide the session key with the synthetic packet stream. The stitcher provides the synthetic packet streams to enterprise packet analysis systems for storage, auditing, analysis, and the like.


