Proxy Traffic Policy Enforcement via Host Value Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems fail to properly enforce traffic policies when a proxy server is deployed, as the proxy server's IP address is used as the source or destination, allowing unauthorized communication between client devices and blacklisted or malicious servers.
Innovation Solution
A network appliance with components like a communication engine, host engine, proxy connection engine, classification engine, and policy engine inspects packet streams to determine if a proxy connection is present, using techniques such as IP address comparison and packet inspection to identify host values and geolocations, and enforces policies based on these determinations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a proxy server is deployed to forward network traffic, then network communication flexibility is improved, but security policy enforcement deteriorates because the proxy server's IP address masks the actual source or destination
Solution Approach 1:
The patent extracts and stores the actual source or destination IP address from the proxy traffic before the security policy decision is made. By performing this extraction action in advance, the system prepares the true identifying information needed for accurate policy enforcement, resolving the contradiction between using proxy servers and maintaining security control.
Solution Approach 2:
The patent introduces an intermediary mechanism (deep packet inspection and host value extraction) that sits between the proxy server layer and the security policy layer. This intermediary extracts the actual endpoint information from the proxy-encapsulated traffic, allowing security policies to be enforced on the true source/destination while preserving the proxy server's communication flexibility.
2Ease of operation
If IP address-based policy enforcement is used for simplicity, then ease of operation is improved, but measurement precision deteriorates when proxy servers are involved
Solution Approach 1:
The patent applies partial action by selectively extracting host values only from packets that contain proxy connections. For direct connections, the system continues to use simple IP address matching. This selective approach maintains operational simplicity for the majority of traffic while improving precision for proxy-encapsulated traffic where needed.
Solution Approach 2:
The system performs preliminary inspection to detect whether a packet is proxy-encapsulated before applying the appropriate policy enforcement method. This preliminary classification allows the system to maintain simplicity for direct traffic while applying precise host value extraction only when necessary, resolving the contradiction between operational ease and identification precision.
3Reliability
If deep packet inspection is performed to identify actual hosts through proxy connections, then security accuracy is improved, but processing time increases
Solution Approach 1:
The patent applies partial action by performing deep host value extraction only on packets that are identified as using proxy connections. For direct connections, the system uses fast IP address matching without deep inspection. This selective approach maintains high security accuracy for proxy traffic while minimizing processing time overhead for the majority of direct traffic.
Solution Approach 2:
The system performs preliminary detection to identify proxy-encapsulated packets before applying deep packet inspection. This preliminary filtering ensures that resource-intensive host value extraction is applied only when necessary, maintaining security accuracy for proxy traffic while reducing overall processing time by avoiding unnecessary deep inspection of direct traffic.
Data Source
AI summary
Examples disclosed herein relate to enforcing a policy to a packet stream based on a classification and a determination that a proxy connection is associated with the packet stream. In the example, the packet stream is received. In this example, a host value is determined for the packet stream. Also, in the example, it is determined whether the packet stream is associated with the proxy connection. Further, in the example, a classification is determined based on the host value. In this example, the policy is enforced for the packet stream based on the classification and the determination that the proxy connection is associated with the packet stream.


