Packet Stitching for Cloud Security Traffic Visibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises lose visibility into traffic steered to cloud-based security service providers due to encryption and session keys, hindering packet analysis, storage, and auditing.

Innovation Solution

A synthetic packet stream is generated by intercepting packets at a network security system gateway, extracting session keys, and stitching them with decrypted packets to create a bidirectional traffic representation, allowing enterprises to regain visibility and analysis capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traffic is steered to cloud-based security providers using encryption and tunneling, then security services are protected, but the enterprise loses visibility into the traffic flow

Engineering Contradiction:
Improvesecurity service protectionVSAvoidtraffic visibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the packet stream into individual packets and processes them separately. The stitcher receives fragmented packet data from cloud security providers, reconstructs complete packets by assembling fragments in the correct sequence, and restores the original traffic flow representation. This segmentation allows the system to maintain security through cloud-based processing while regaining visibility through packet reconstruction.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The stitcher acts as an intermediary component between the cloud-based security provider and the enterprise. It receives encrypted and fragmented packet data from the cloud provider, performs reconstruction and decryption operations, and delivers restored traffic flow information to the enterprise. This intermediary function enables the enterprise to access traffic visibility without compromising the security protections provided by cloud-based services.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If packets are encrypted for security, then traffic protection is improved, but the enterprise cannot decrypt and analyze the packets

Engineering Contradiction:
Improvetraffic protectionVSAvoidpacket analysis capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary decryption actions at the stitcher before packet analysis. The stitcher receives encrypted packets from cloud security providers, decrypts them using appropriate keys, and then makes the plaintext packets available for enterprise analysis. This preliminary decryption action removes the barrier that would otherwise prevent the enterprise from analyzing encrypted traffic.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The stitcher serves as an intermediary that handles the decryption process between the cloud provider and the enterprise. It receives encrypted packets, performs decryption operations, and delivers decrypted packet data to the enterprise for analysis. This intermediary function enables packet analysis capability while maintaining the security architecture of cloud-based services.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Extent of automation

If cloud-based security services are used, then security analysis is centralized, but the enterprise cannot reliably capture traffic from client devices

Engineering Contradiction:
Improvecentralized security analysisVSAvoidtraffic capture reliability
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent uses copying to create packet representations that can be reliably captured and transmitted. Instead of attempting to capture actual traffic at client devices, the system copies packet data from the cloud-based security provider where traffic flow is already controlled and predictable. These copied packet representations are then stitched together to create accurate traffic flow information that can be reliably captured and stored.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system performs preliminary packet capture at the cloud security provider before data returns to client devices. By capturing packets at this centralized point where traffic is controlled and standardized, the system ensures reliable capture accuracy. The stitched packet representations are then made available for enterprise analysis, providing reliable traffic capture without requiring deployment at dispersed client locations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250350580A1Stitcher for cloud-based security tapped packets
Publication Date: 2025.11.13 NETSKOPE INC
  • US20250350580A1 patent drawing
  • US20250350580A1 patent drawing
  • US20250350580A1 patent drawing

AI summary

A cloud-based network security system that includes a packet tap and exposes a synthetic packet stream representing the bidirectional data between enterprise client devices and cloud hosted services is disclosed. The security system intercepts packets of communication sessions and uploads a copy of the packets to cloud storage. A proxy of the security system derives session keys for the communication session and uploads the session keys to the cloud storage. An enterprise stitcher obtains the packets from the cloud storage, stitches the packets together in sequential order, and modifies the Layer 3 and Layer 4 headers to generate synthetic packet streams representing the communication sessions. The stitcher may decrypt the packets or provide the session key with the synthetic packet stream. The stitcher provides the synthetic packet streams to enterprise packet analysis systems for storage, auditing, analysis, and the like.