Dynamic Proxy Policy Enforcement via Selective DPI
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Proxy connections in network environments often break firewall policy enforcement, leading to unintended access or denial of applications due to their persistent nature across multiple application types and web content categories, which results in processor-intensive deep-packet inspection and reduced throughput.
Innovation Solution
A method and network device for dynamic detection of proxy connections, where only specific packets are subjected to deep-packet inspection, and the network device re-applies access control list (ACL) lookups when a session transitions to different applications or web content categories, ensuring accurate application-based policy enforcement while minimizing CPU usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If deep-packet inspection is continuously applied to all packets in a session, then measurement precision of application classification is improved, but processor usage increases and throughput decreases
Solution Approach 1:
The patent applies deep-packet inspection only to the first few packets of a session (partial action) rather than continuously to all packets. Once the session is classified and categorized, subsequent packets are processed without DPI, reducing CPU cycles while maintaining classification accuracy. This resolves the contradiction by applying inspection only where necessary for accurate measurement.
2Ease of operation
If proxy connections are permitted to maintain persistent sessions across multiple applications, then ease of operation is improved, but firewall policy enforcement reliability deteriorates
Solution Approach 1:
The patent implements dynamic re-evaluation of firewall policies for proxy connections when application classification changes. Instead of static policy enforcement, the system continuously monitors application type changes and re-applies appropriate policies, making the firewall enforcement adaptive and reliable while preserving proxy connection persistence.
Solution Approach 2:
The system uses feedback from application classification results to dynamically adjust firewall policy enforcement. When DPI detects a change in application type for a proxy connection, the system feeds this information back to re-evaluate and re-apply the appropriate firewall policies, ensuring reliability while maintaining operational ease.
3Manufacturing precision
If application-based policy enforcement is implemented, then manufacturing precision of network control is improved, but device complexity increases
Solution Approach 1:
The patent segments the policy enforcement process into distinct phases: initial ACL lookup, application-based classification via DPI, and post-classification policy application. This segmentation allows precise control at each stage while managing complexity by handling only relevant packets at each phase, rather than applying all policies to all packets.
Data Source
AI summary
The present disclosure discloses a method and a network device for performing dynamic detection and application-based policy enforcement of proxy connections in a network. Specifically, a network device receives, from a client device, a packet in a session. The network device then determines whether the packet is transmitted to a proxy. In response to determining that the packet is associated with a different application classification or web content category during the same session, the network device re-applies network firewall policies to determine whether to allow or deny transmission of the packet to the proxy.


