Protocol-Independent Header Injection for Secure Traffic Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security solutions fail to provide granular configuration and detailed reports for application filtering, and they do not adequately handle both unencrypted and encrypted network traffic, often requiring protocol-specific modifications that compromise security and efficiency.

Innovation Solution

A method and system that redirect network connections to a proxy for content inspection, injecting protocol-independent header information into datagrams, which includes user-specific encryption to enforce security policies without modifying the protocol, allowing for secure and efficient inspection of both encrypted and unencrypted traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If protocol-specific modifications are made for content inspection, then inspection capability is improved, but system complexity and security risks increase

Engineering Contradiction:
Improvecontent inspection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the header information into protocol-independent fields that can be universally processed. By dividing the header into standardized segments (source/destination identifiers, policy identifiers, action identifiers) rather than protocol-specific structures, the system achieves content inspection capability without requiring complex protocol-specific modifications, thus resolving the contradiction between inspection precision and system complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal header structure that works across multiple protocols without requiring protocol-specific adaptations. The protocol-independent header with standardized fields can be applied to different traffic types (encrypted and unencrypted) through a single unified mechanism, eliminating the need for separate inspection pathways and reducing overall system complexity while maintaining inspection effectiveness

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If protocol-specific modifications are made for content inspection, then inspection capability is improved, but security risks increase

Engineering Contradiction:
Improvecontent inspection capabilityVSAvoidsecurity risks
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a protocol-independent header as an intermediary layer between the original traffic and the inspection mechanism. This intermediary structure allows security policies to be enforced without directly modifying or parsing protocol-specific data, thereby maintaining security by avoiding protocol vulnerabilities while still enabling detailed content inspection through the standardized header fields

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a copy of essential traffic information in the protocol-independent header rather than directly accessing or modifying the original protocol data. This copying approach allows inspection of source/destination identifiers and policy enforcement without exposing the system to security risks associated with deep protocol parsing or modification, thus enabling inspection capability while maintaining security

Inventive Principle:
Principle #26Copying

3Manufacturing precision

If external proxy is used for content inspection, then filtering granularity is improved, but network complexity increases

Engineering Contradiction:
Improvefiltering granularityVSAvoidnetwork complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent merges the content inspection functionality directly into the existing network infrastructure through protocol-independent header injection at the gateway level, rather than requiring separate external proxy systems. This consolidation achieves fine-grained filtering capability while reducing network complexity by eliminating the need for additional external proxy components and their associated configuration management

Inventive Principle:
Principle #5Merging (Combining)

4Measurement precision

If protocol-specific inspection methods are used, then inspection accuracy is improved, but processing efficiency decreases

Engineering Contradiction:
Improveinspection accuracyVSAvoidprocessing efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent changes the parameter structure from protocol-specific variable formats to fixed protocol-independent header fields. This parameter standardization enables efficient processing through standardized field access patterns while maintaining inspection accuracy by preserving essential traffic identification information (source/destination identifiers, policy identifiers) in a uniform structure that can be processed rapidly across different protocol types

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11005659B2Protocol independent forwarding of traffic for content inspection service
Publication Date: 2021.05.11 FORCEPOINT LLC
  • US11005659B2 patent drawing
  • US11005659B2 patent drawing
  • US11005659B2 patent drawing

AI summary

A method, system, and computer-usable medium are disclosed for, responsive to an attempted connection from a client to a server for establishing communications between the client and the server, redirecting the connection to a proxy and injecting protocol-independent header information into a datagram of the traffic between the client and the server, the protocol-independent header information including information based upon which the proxy enforces a security policy.