Dynamic Proxy Policy Enforcement via Selective DPI

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Proxy connections in network environments often break firewall policy enforcement, leading to unintended access or denial of applications due to their persistent nature across multiple application types and web content categories, which results in processor-intensive deep-packet inspection and reduced throughput.

Innovation Solution

A method and network device for dynamic detection of proxy connections, where only specific packets are subjected to deep-packet inspection, and the network device re-applies access control list (ACL) lookups when a session transitions to different applications or web content categories, ensuring accurate application-based policy enforcement while minimizing CPU usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deep-packet inspection is continuously applied to all packets in a session, then measurement precision of application classification is improved, but processor usage increases and throughput decreases

Engineering Contradiction:
Improveapplication classification accuracyVSAvoidsystem throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent applies deep-packet inspection only to the first few packets of a session (partial action) rather than continuously to all packets. Once the session is classified and categorized, subsequent packets are processed without DPI, reducing CPU cycles while maintaining classification accuracy. This resolves the contradiction by applying inspection only where necessary for accurate measurement.

Inventive Principle:
Principle #16Partial or excessive action

2Ease of operation

If proxy connections are permitted to maintain persistent sessions across multiple applications, then ease of operation is improved, but firewall policy enforcement reliability deteriorates

Engineering Contradiction:
Improveproxy connection persistenceVSAvoidfirewall policy enforcement
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic re-evaluation of firewall policies for proxy connections when application classification changes. Instead of static policy enforcement, the system continuously monitors application type changes and re-applies appropriate policies, making the firewall enforcement adaptive and reliable while preserving proxy connection persistence.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system uses feedback from application classification results to dynamically adjust firewall policy enforcement. When DPI detects a change in application type for a proxy connection, the system feeds this information back to re-evaluate and re-apply the appropriate firewall policies, ensuring reliability while maintaining operational ease.

Inventive Principle:
Principle #23Feedback

3Manufacturing precision

If application-based policy enforcement is implemented, then manufacturing precision of network control is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork policy enforcement accuracyVSAvoidfirewall system complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent segments the policy enforcement process into distinct phases: initial ACL lookup, application-based classification via DPI, and post-classification policy application. This segmentation allows precise control at each stage while managing complexity by handling only relevant packets at each phase, rather than applying all policies to all packets.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9825909B2Dynamic detection and application-based policy enforcement of proxy connections
Publication Date: 2017.11.21 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9825909B2 patent drawing
  • US9825909B2 patent drawing
  • US9825909B2 patent drawing

AI summary

The present disclosure discloses a method and a network device for performing dynamic detection and application-based policy enforcement of proxy connections in a network. Specifically, a network device receives, from a client device, a packet in a session. The network device then determines whether the packet is transmitted to a proxy. In response to determining that the packet is associated with a different application classification or web content category during the same session, the network device re-applies network firewall policies to determine whether to allow or deny transmission of the packet to the proxy.