Proxy Traffic Policy Enforcement via Host Value Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems fail to properly enforce traffic policies when a proxy server is deployed, as the proxy server's IP address is used as the source or destination, allowing unauthorized communication between client devices and blacklisted or malicious servers.

Innovation Solution

A network appliance with components like a communication engine, host engine, proxy connection engine, classification engine, and policy engine inspects packet streams to determine if a proxy connection is present, using techniques such as IP address comparison and packet inspection to identify host values and geolocations, and enforces policies based on these determinations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a proxy server is deployed to forward network traffic, then network communication flexibility is improved, but security policy enforcement deteriorates because the proxy server's IP address masks the actual source or destination

Engineering Contradiction:
Improvenetwork communication flexibilityVSAvoidsecurity policy enforcement
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent extracts and stores the actual source or destination IP address from the proxy traffic before the security policy decision is made. By performing this extraction action in advance, the system prepares the true identifying information needed for accurate policy enforcement, resolving the contradiction between using proxy servers and maintaining security control.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism (deep packet inspection and host value extraction) that sits between the proxy server layer and the security policy layer. This intermediary extracts the actual endpoint information from the proxy-encapsulated traffic, allowing security policies to be enforced on the true source/destination while preserving the proxy server's communication flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If IP address-based policy enforcement is used for simplicity, then ease of operation is improved, but measurement precision deteriorates when proxy servers are involved

Engineering Contradiction:
Improvepolicy enforcement simplicityVSAvoidtraffic source identification
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent applies partial action by selectively extracting host values only from packets that contain proxy connections. For direct connections, the system continues to use simple IP address matching. This selective approach maintains operational simplicity for the majority of traffic while improving precision for proxy-encapsulated traffic where needed.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary inspection to detect whether a packet is proxy-encapsulated before applying the appropriate policy enforcement method. This preliminary classification allows the system to maintain simplicity for direct traffic while applying precise host value extraction only when necessary, resolving the contradiction between operational ease and identification precision.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If deep packet inspection is performed to identify actual hosts through proxy connections, then security accuracy is improved, but processing time increases

Engineering Contradiction:
Improvesecurity accuracyVSAvoidpacket processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by performing deep host value extraction only on packets that are identified as using proxy connections. For direct connections, the system uses fast IP address matching without deep inspection. This selective approach maintains high security accuracy for proxy traffic while minimizing processing time overhead for the majority of direct traffic.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary detection to identify proxy-encapsulated packets before applying deep packet inspection. This preliminary filtering ensures that resource-intensive host value extraction is applied only when necessary, maintaining security accuracy for proxy traffic while reducing overall processing time by avoiding unnecessary deep inspection of direct traffic.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10771391B2Policy enforcement based on host value classification
Publication Date: 2020.09.08 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10771391B2 patent drawing
  • US10771391B2 patent drawing
  • US10771391B2 patent drawing

AI summary

Examples disclosed herein relate to enforcing a policy to a packet stream based on a classification and a determination that a proxy connection is associated with the packet stream. In the example, the packet stream is received. In this example, a host value is determined for the packet stream. Also, in the example, it is determined whether the packet stream is associated with the proxy connection. Further, in the example, a classification is determined based on the host value. In this example, the policy is enforced for the packet stream based on the classification and the determination that the proxy connection is associated with the packet stream.