Distributed Proxy Detection via Behavioral Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing layered security systems face inefficiencies in processing and resource usage due to lack of content intelligence sharing, difficulty in maintaining a central data store for threat classification, and limited real-time data mining capabilities, which allows surreptitious activities to go undetected, especially with the use of anonymous proxy servers and encoded resource locations.

Innovation Solution

Implementing a distributed security system with processing nodes that identify and classify embedded resource request identifiers, allowing for filtering operations based on security policies, and utilizing data inspection engines to monitor and manage content items, while also tracking and enforcing security policies across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a list of known proxy servers is blocked, then proxy server abuse is prevented, but legitimate proxy usage is also blocked and maintenance cost increases

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidproxy server maintenance
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical approach of maintaining and updating proxy server IP lists with an automated behavioral detection system. The system uses data mining and pattern recognition to identify proxy servers based on their operational characteristics (multiple clients, resource request patterns) rather than relying on manually maintained lists. This substitution eliminates the need for continuous manual updates while maintaining security policy enforcement.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables proxy servers to be automatically identified and classified through their own behavioral patterns. By monitoring resource requests and client connections, the system self-identifies proxy servers without external input or manual configuration. This self-service mechanism continuously adapts to new proxy servers appearing on the network without requiring maintenance intervention.

Inventive Principle:
Principle #25Self-service

2Reliability

If encoded resource locations are blocked, then prohibited content access is prevented, but processing overhead increases and legitimate encoded data is blocked

Engineering Contradiction:
Improveprohibited content blockingVSAvoidrequest processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial decoding or pattern matching rather than complete decoding of all encoded data. The system identifies suspicious encoded patterns that match known prohibited resource structures without fully decoding and processing every encoded request. This selective approach maintains blocking effectiveness while reducing the computational overhead of processing all encoded data.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary classification and filtering of encoded requests before full processing. By using data mining techniques to pre-identify suspicious patterns and characteristics in encoded data, the system can quickly filter out obviously malicious requests without performing expensive full decoding operations on all traffic.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If layered security systems are implemented, then security coverage is improved, but processing inefficiency and resource consumption increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges multiple security functions (proxy detection, encoded content identification, resource request monitoring, and classification) into a unified distributed system. Rather than having separate layered security components operating independently, the system combines these functions into an integrated architecture that shares data and processing logic across distributed processing nodes, reducing redundant operations and improving overall efficiency.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent segments security processing into distributed processing nodes that operate autonomously but cooperatively. Each node performs specific security functions locally while sharing intelligence with other nodes through a distributed architecture. This segmentation allows parallel processing of security tasks across multiple nodes, improving throughput and reducing the processing burden on any single node compared to a centralized layered approach.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8230506B1Proxy communication detection
Publication Date: 2012.07.24 ZSCALER INC
  • US8230506B1 patent drawing
  • US8230506B1 patent drawing
  • US8230506B1 patent drawing

AI summary

Systems, methods and apparatus for a distributed security that provides security processing external to a network edge. The system can identify requests, such as HTTP requests, and can identify embedded resource request identifiers, such as embedded URLs. The embedded resource request identifiers can be classified and appropriate security measures can be initiated based on the classifications.