Secure Proxy for Dynamic Endpoint Resolution and Application Layer Inspection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional transport-layer firewalls are inadequate for managing dynamically changing IP addresses associated with service endpoints and fail to detect application-level anomalies such as data leaks, making them insufficient for integrating backend enterprise environments with web-based services.
Innovation Solution
A secure proxy system that includes a secure endpoint resolver and multiple security layers across various network protocol layers, which validates and manages network traffic by applying policies to ensure data security and prevent leaks, using DNSSEC for authenticating endpoint information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If transport-layer firewalls are used to restrict network traffic to known IP addresses, then backend assets are protected, but the firewalls cannot accommodate dynamically changing IP addresses of service endpoints
Solution Approach 1:
The patent introduces a secure proxy as an intermediary component between the transport-layer firewall and service endpoints. The secure proxy maintains the firewall's protective function while independently managing dynamic IP address mappings for service endpoints, allowing the firewall to remain static while adapting to changing service infrastructure
Solution Approach 2:
The system segments the security architecture into multiple layers: the transport-layer firewall handles broad protection rules, while the secure proxy handles application-layer security and dynamic IP management. This segmentation allows each component to specialize without compromising the other's functionality
2Reliability
If transport-layer firewalls are used to protect backend environments, then network traffic is restricted, but application-level anomalies such as data leaks cannot be detected
Solution Approach 1:
The patent extends security detection from the network/transport layers to the application layer, adding a new dimensional capability for detecting data leaks and application-level anomalies. The secure proxy inspects application-layer protocols and data patterns that are invisible to traditional transport-layer firewalls
Solution Approach 2:
The system replaces the mechanical, signature-based firewall filtering with intelligent, context-aware application-layer analysis that can detect anomalies based on data patterns, protocol behavior, and security policies specific to each application
3Adaptability or versatility
If manual updates to firewalls are performed to allow dynamically changing IP addresses, then service endpoints can be accessed, but the complexity and time required for updates increases
Solution Approach 1:
The secure proxy implements self-service functionality by automatically discovering service endpoint IP addresses through DNS queries and service registration mechanisms. The system dynamically updates its own allowlists and routing tables without requiring manual administrator intervention, enabling rapid adaptation to infrastructure changes
4Difficulty of detecting and measuring
If multiple security layers are implemented to detect data leaks, then detection capability improves, but system complexity increases
Solution Approach 1:
The secure proxy is designed as a multi-functional security platform that combines application-layer firewall capabilities, data leak prevention, protocol inspection, and anomaly detection in a single unified system. This universal approach provides comprehensive detection capabilities without requiring separate specialized security appliances for each function
Data Source
AI summary
Methods and systems are provided herein to enable secure proxying of network traffic between trusted and untrusted environments. In particular, a secure proxy may be provided that includes a set of policies. The policies may be applicable to various network protocol layers (e.g., an application layer), network traffic types, and/or endpoint resolution. The set of policies may be used to inspect, restrict and/or modify traffic between the trusted and untrusted environment to ensure data and network security. A proxy device may use the set of policies, for example, to obtain current service-related information (such as the list of IP addresses) currently associated with a computing resource requested by an application. Such endpoint information may be used, in turn, to update a white list.


