Proxy Traffic Decoding for Identity Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing surveillance methods face challenges in correlating the identities of client computers and target servers when communication occurs through proxy servers, as proxy servers typically only convey the identity of either the client or the server, not both, in explicit form, making it difficult to intercept and monitor communication sessions effectively.

Innovation Solution

A system and method that receive communication packets from a network, identify sessions conducted via proxy servers, and correlate client and target server identities by processing these packets, even when identities are encoded or obfuscated, allowing for the reconstruction and presentation of communication sessions as if they occurred directly between the client and target server without the proxy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If communication occurs through proxy servers to protect client identity, then client anonymity is improved, but the ability to correlate client and server identities for surveillance deteriorates

Engineering Contradiction:
Improveclient anonymityVSAvoididentity correlation
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system introduces a monitoring intermediary that positions itself between the proxy server and the surveillance target, capturing traffic at a point where both client and server identities are visible in the same data stream, thus resolving the identity correlation problem while maintaining client anonymity through the proxy

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a copy of the traffic flow from the proxy server, analyzing this copy to extract and correlate client and server identities without disrupting the original anonymous communication channel, allowing surveillance while preserving client anonymity

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If proxy servers are used to communicate behind firewalls, then network access capability is improved, but traffic monitoring capability deteriorates

Engineering Contradiction:
Improvenetwork access capabilityVSAvoidtraffic monitoring capability
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The monitoring system acts as an intermediary that receives traffic copies from the firewall-protected network segment, enabling surveillance of traffic that would otherwise be inaccessible due to firewall restrictions, thus restoring traffic monitoring capability while preserving network access capability

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If identities are encoded or obfuscated in communication packets, then security is improved, but decoding complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddecoding complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system captures encoded identity information from traffic copies and creates decoded representations for analysis, maintaining the security of the original encoded traffic while enabling surveillance through the decoded copy, thus balancing security with monitoring capability

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10862869B2System and method for decoding traffic over proxy servers
Publication Date: 2020.12.08 COGNYTE TECH ISRAEL LTD
  • US10862869B2 patent drawing

AI summary

Methods and systems for applying surveillance to client computers that communicate via proxy servers. A decoding system accepts communication packets from a communication network. Based on the received packets, the decoding system identifies that a certain client computer conducts a communication session with a target server via a proxy server. The decoding system processes the packets so as to correlate the identity of the client computer with the identity of the target server. The correlated identities may comprise, for example, Internet Protocol (IP) addresses or Uniform Resource Locators (URLs).