Passive SSL Traffic Routing Without Decryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for routing network traffic fail to efficiently and securely passively route SSL encoded traffic without decryption, which is necessary for load balancing and analysis, as they often require decryption or interfere with the original network stream.

Innovation Solution

A system and method for passively receiving and parsing SSL encoded network traffic, generating an identical copy without decryption, and routing it to multiple output devices using a passive duplex network capture module, TCP parsing engine, SSL parsing engine, and transmit engine, ensuring continuity of SSL sessions and load balancing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If SSL encoded network traffic is passively collected and routed to multiple recipients, then network traffic analysis and load balancing capabilities are improved, but the complexity of routing encrypted traffic without decryption increases

Engineering Contradiction:
Improvenetwork traffic analysis capabilityVSAvoidrouting complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates identical copies of SSL encoded network traffic packets and routes them to multiple recipients without decrypting the original traffic. The copying mechanism preserves the encrypted payload while enabling multiple destinations, thus improving analysis capability without requiring decryption complexity

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The routing system segments the network traffic handling by separating the copying function from the decryption function. Each packet is independently copied and routed, allowing parallel processing across multiple recipients while maintaining the integrity of the SSL encryption

Inventive Principle:
Principle #1Segmentation

2Reliability

If passive copying of network traffic is implemented, then network traffic can be analyzed without interference, but routing the copied traffic to multiple recipients requires additional processing resources

Engineering Contradiction:
Improvenetwork traffic integrityVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system creates bit-for-bit identical copies of SSL encoded packets using passive copying mechanisms that preserve the original traffic integrity. These copies are then routed to multiple recipients, enabling analysis without interfering with the original network flow while distributing processing load across multiple systems

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The routing system allows each recipient to independently process the copied traffic according to its own capabilities. The passive copying mechanism delivers complete packets that can be autonomously analyzed by each recipient without requiring centralized coordination or additional processing overhead

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7953973B2Systems, methods, and computer program products for passively routing secure socket layer (SSL) encoded network traffic
Publication Date: 2011.05.31 RADWARE LTD
  • US7953973B2 patent drawing
  • US7953973B2 patent drawing
  • US7953973B2 patent drawing

AI summary

Methods, systems, and computer program products for passively routing secure socket layer (SSL) encoded network traffic are disclosed. According to one aspect, a method includes passively receiving a copy of SSL encoded network traffic. Further, the method includes passively parsing the received network traffic and generating an identical copy of the network traffic such that the network traffic is not decrypted and without interfering with the network traffic. A target output network device can be selected for transmission of the identical copy of the network traffic. The identical copy of the network traffic can be transmitted from the selected target output network device.