Proxy Mode Switching for Network Traffic Security and Performance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Proxy devices face performance degradation due to high network traffic demands, which exceed their memory and computing capabilities, leading to compromised network transmission efficiency.
Innovation Solution
Implementing a mode-switching mechanism between lightweight monitoring and full proxy services, allowing the proxy device to dynamically transition between passive monitoring and active packet inspection based on traffic suspicion, thereby optimizing resource usage and reducing unnecessary resource expenditure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If full proxy services are applied to all network traffic, then security inspection and packet monitoring are improved, but memory consumption and device performance degradation worsen
Solution Approach 1:
The patent implements a dynamic mode-switching mechanism that allows the proxy device to transition between lightweight monitoring mode and full proxy services mode based on real-time traffic analysis. The system dynamically adjusts its operational state to match the actual security risk level of incoming traffic, applying full inspection only when necessary while using lightweight monitoring for benign traffic.
Solution Approach 2:
The patent changes the operational parameters of the proxy device by switching between two distinct modes: lightweight monitoring mode (passive, low resource consumption) and full proxy services mode (active, high security inspection). This parameter change allows the system to optimize the balance between security thoroughness and performance based on traffic characteristics.
2Reliability
If full proxy services are applied to high-volume traffic, then packet inspection and security monitoring are improved, but memory requirements and computing demands worsen
Solution Approach 1:
The patent applies partial action by providing full proxy services only to traffic that requires it (suspicious or high-risk traffic) while using lightweight monitoring for the majority of benign traffic. This selective application of full inspection avoids the excessive memory and computing resources that would be consumed if full services were applied to all traffic uniformly.
Solution Approach 2:
The patent applies different levels of inspection quality to different types of traffic. High-risk traffic receives full proxy services with comprehensive packet inspection, while low-risk traffic receives lightweight monitoring. This local differentiation of service quality optimizes resource allocation based on the actual needs of each traffic stream.
3Reliability
If the proxy device operates in full proxy mode continuously, then security coverage is improved, but device performance and transmission speed deteriorate
Solution Approach 1:
The patent makes the proxy device's operational state dynamic by switching between full proxy mode and lightweight monitoring mode based on real-time traffic analysis. This dynamic adjustment ensures that full security coverage is maintained for problematic traffic while allowing faster transmission speeds for benign traffic by avoiding unnecessary full inspection overhead.
Solution Approach 2:
The patent applies full security coverage only partially to traffic that actually requires it, rather than continuously. By reserving full proxy mode for suspicious or high-risk traffic only, the system maintains adequate security coverage for critical flows while avoiding the performance penalty of continuous full inspection on all traffic.
Data Source
AI summary
The packets of a communication session between a first device and a second device are monitored at proxy device. A determination is made that full proxy services should be applied to the communication session at the proxy device. After the determination, a packet of a first exchange, the first exchange being initiated prior to the determination, is passed through the proxy device. After the determination, full proxy services are applied to a packet of a second exchange, the second exchange being initiated after the determination.


