Polymorphic Security Proxy for Dynamic Inspection Mode Switching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional network security inspection methods, such as TCP proxies, consume significant resources and may not be necessary for all online communication sessions, leading to inefficiencies.
Innovation Solution
Implementing polymorphic security proxies that detect and adapt to the specific applications involved in online communication sessions, determining the most efficient security mode to minimize resource consumption while ensuring necessary security inspections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional TCP proxy performs extensive security inspection by saving packets, timers, and acknowledgements, then security inspection thoroughness is improved, but resource consumption increases
Solution Approach 1:
The patent changes the operational parameters of the security proxy by identifying the specific application protocol involved in the communication session and switching between different security inspection modes (first mode with extensive packet saving and retransmission, second mode without these operations) based on the application type, thereby optimizing resource consumption while maintaining security effectiveness
Solution Approach 2:
The patent implements a dynamic security inspection system that adapts its behavior in real-time by detecting the application protocol and dynamically switching between different inspection modes, making the security proxy flexible and responsive to different communication requirements rather than applying a static uniform inspection approach
2Measurement precision
If traditional TCP proxy performs retransmissions to facilitate security inspection, then inspection accuracy is improved, but time consumption increases
Solution Approach 1:
The patent changes the inspection parameters based on application protocol identification, disabling retransmission operations for applications where they are unnecessary while maintaining them for applications that require them, thereby reducing overall time consumption without compromising inspection accuracy for critical protocols
3Reliability
If traditional TCP proxy buffers packets for security inspection, then security analysis capability is improved, but network resource efficiency deteriorates
Solution Approach 1:
The patent dynamically adjusts buffering parameters based on the identified application protocol, enabling buffering only when necessary for security analysis while allowing packets to pass through without buffering for applications where it is not needed, thereby improving network resource efficiency while maintaining security analysis capability when required
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The disclosed computer-implemented method may include (1) detecting an online communication session established between a plurality of computing devices, (2) identifying at least one application involved in the online communication session established between the plurality of computing devices, (3) determining a security mode for a security proxy that inspects the online communication session based at least in part on the application involved in the online communication session, and then (4) configuring the security proxy to inspect the online communication session in accordance with the determined security mode. Various other systems, methods, and apparatuses are also disclosed.