Polymorphic Security Proxy for Dynamic Inspection Mode Switching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional network security inspection methods, such as TCP proxies, consume significant resources and may not be necessary for all online communication sessions, leading to inefficiencies.

Innovation Solution

Implementing polymorphic security proxies that detect and adapt to the specific applications involved in online communication sessions, determining the most efficient security mode to minimize resource consumption while ensuring necessary security inspections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional TCP proxy performs extensive security inspection by saving packets, timers, and acknowledgements, then security inspection thoroughness is improved, but resource consumption increases

Engineering Contradiction:
Improvesecurity inspection thoroughnessVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent changes the operational parameters of the security proxy by identifying the specific application protocol involved in the communication session and switching between different security inspection modes (first mode with extensive packet saving and retransmission, second mode without these operations) based on the application type, thereby optimizing resource consumption while maintaining security effectiveness

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements a dynamic security inspection system that adapts its behavior in real-time by detecting the application protocol and dynamically switching between different inspection modes, making the security proxy flexible and responsive to different communication requirements rather than applying a static uniform inspection approach

Inventive Principle:
Principle #15Dynamics

2Measurement precision

If traditional TCP proxy performs retransmissions to facilitate security inspection, then inspection accuracy is improved, but time consumption increases

Engineering Contradiction:
Improveinspection accuracyVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent changes the inspection parameters based on application protocol identification, disabling retransmission operations for applications where they are unnecessary while maintaining them for applications that require them, thereby reducing overall time consumption without compromising inspection accuracy for critical protocols

Inventive Principle:
Principle #35Parameter changes

3Reliability

If traditional TCP proxy buffers packets for security inspection, then security analysis capability is improved, but network resource efficiency deteriorates

Engineering Contradiction:
Improvesecurity analysis capabilityVSAvoidnetwork resource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent dynamically adjusts buffering parameters based on the identified application protocol, enabling buffering only when necessary for security analysis while allowing packets to pass through without buffering for applications where it is not needed, thereby improving network resource efficiency while maintaining security analysis capability when required

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2963887B1System, method, and apparatus for inspecting online communication sessions via polymorphic security proxies
Publication Date: 2021.06.02 JUNIPER NETWORKS INC
  • EP2963887B1 patent drawingFigure 1
  • EP2963887B1 patent drawingFigure 2
  • EP2963887B1 patent drawingFigure 3

AI summary

The disclosed computer-implemented method may include (1) detecting an online communication session established between a plurality of computing devices, (2) identifying at least one application involved in the online communication session established between the plurality of computing devices, (3) determining a security mode for a security proxy that inspects the online communication session based at least in part on the application involved in the online communication session, and then (4) configuring the security proxy to inspect the online communication session in accordance with the determined security mode. Various other systems, methods, and apparatuses are also disclosed.