Proxy Mode Switching for Network Traffic Security and Performance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Proxy devices face performance degradation due to high network traffic demands, which exceed their memory and computing capabilities, leading to compromised network transmission efficiency.

Innovation Solution

Implementing a mode-switching mechanism between lightweight monitoring and full proxy services, allowing the proxy device to dynamically transition between passive monitoring and active packet inspection based on traffic suspicion, thereby optimizing resource usage and reducing unnecessary resource expenditure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If full proxy services are applied to all network traffic, then security inspection and packet monitoring are improved, but memory consumption and device performance degradation worsen

Engineering Contradiction:
Improvesecurity inspectionVSAvoidnetwork transmission efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a dynamic mode-switching mechanism that allows the proxy device to transition between lightweight monitoring mode and full proxy services mode based on real-time traffic analysis. The system dynamically adjusts its operational state to match the actual security risk level of incoming traffic, applying full inspection only when necessary while using lightweight monitoring for benign traffic.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the operational parameters of the proxy device by switching between two distinct modes: lightweight monitoring mode (passive, low resource consumption) and full proxy services mode (active, high security inspection). This parameter change allows the system to optimize the balance between security thoroughness and performance based on traffic characteristics.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If full proxy services are applied to high-volume traffic, then packet inspection and security monitoring are improved, but memory requirements and computing demands worsen

Engineering Contradiction:
Improvepacket inspectionVSAvoidmemory consumption
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies partial action by providing full proxy services only to traffic that requires it (suspicious or high-risk traffic) while using lightweight monitoring for the majority of benign traffic. This selective application of full inspection avoids the excessive memory and computing resources that would be consumed if full services were applied to all traffic uniformly.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent applies different levels of inspection quality to different types of traffic. High-risk traffic receives full proxy services with comprehensive packet inspection, while low-risk traffic receives lightweight monitoring. This local differentiation of service quality optimizes resource allocation based on the actual needs of each traffic stream.

Inventive Principle:
Principle #3Local quality

3Reliability

If the proxy device operates in full proxy mode continuously, then security coverage is improved, but device performance and transmission speed deteriorate

Engineering Contradiction:
Improvesecurity coverageVSAvoidnetwork transmission speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent makes the proxy device's operational state dynamic by switching between full proxy mode and lightweight monitoring mode based on real-time traffic analysis. This dynamic adjustment ensures that full security coverage is maintained for problematic traffic while allowing faster transmission speeds for benign traffic by avoiding unnecessary full inspection overhead.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies full security coverage only partially to traffic that actually requires it, rather than continuously. By reserving full proxy mode for suspicious or high-risk traffic only, the system maintains adequate security coverage for critical flows while avoiding the performance penalty of continuous full inspection on all traffic.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9197650B2Proxy that switches from light-weight monitor mode to full proxy
Publication Date: 2015.11.24 CISCO TECHNOLOGY INC
  • US9197650B2 patent drawing
  • US9197650B2 patent drawing
  • US9197650B2 patent drawing

AI summary

The packets of a communication session between a first device and a second device are monitored at proxy device. A determination is made that full proxy services should be applied to the communication session at the proxy device. After the determination, a packet of a first exchange, the first exchange being initiated prior to the determination, is passed through the proxy device. After the determination, full proxy services are applied to a packet of a second exchange, the second exchange being initiated after the determination.