Secure Proxy for Dynamic Endpoint Resolution and Application Layer Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional transport-layer firewalls are inadequate for managing dynamically changing IP addresses associated with service endpoints and fail to detect application-level anomalies such as data leaks, making them insufficient for integrating backend enterprise environments with web-based services.

Innovation Solution

A secure proxy system that includes a secure endpoint resolver and multiple security layers across various network protocol layers, which validates and manages network traffic by applying policies to ensure data security and prevent leaks, using DNSSEC for authenticating endpoint information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If transport-layer firewalls are used to restrict network traffic to known IP addresses, then backend assets are protected, but the firewalls cannot accommodate dynamically changing IP addresses of service endpoints

Engineering Contradiction:
Improveprotection of backend assetsVSAvoidaccommodation of dynamically changing IP addresses
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a secure proxy as an intermediary component between the transport-layer firewall and service endpoints. The secure proxy maintains the firewall's protective function while independently managing dynamic IP address mappings for service endpoints, allowing the firewall to remain static while adapting to changing service infrastructure

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the security architecture into multiple layers: the transport-layer firewall handles broad protection rules, while the secure proxy handles application-layer security and dynamic IP management. This segmentation allows each component to specialize without compromising the other's functionality

Inventive Principle:
Principle #1Segmentation

2Reliability

If transport-layer firewalls are used to protect backend environments, then network traffic is restricted, but application-level anomalies such as data leaks cannot be detected

Engineering Contradiction:
Improvenetwork traffic restrictionVSAvoiddetection of application-level anomalies
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent extends security detection from the network/transport layers to the application layer, adding a new dimensional capability for detecting data leaks and application-level anomalies. The secure proxy inspects application-layer protocols and data patterns that are invisible to traditional transport-layer firewalls

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The system replaces the mechanical, signature-based firewall filtering with intelligent, context-aware application-layer analysis that can detect anomalies based on data patterns, protocol behavior, and security policies specific to each application

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If manual updates to firewalls are performed to allow dynamically changing IP addresses, then service endpoints can be accessed, but the complexity and time required for updates increases

Engineering Contradiction:
Improveaccess to service endpoints with changing IPsVSAvoidtime for manual firewall updates
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The secure proxy implements self-service functionality by automatically discovering service endpoint IP addresses through DNS queries and service registration mechanisms. The system dynamically updates its own allowlists and routing tables without requiring manual administrator intervention, enabling rapid adaptation to infrastructure changes

Inventive Principle:
Principle #25Self-service

4Difficulty of detecting and measuring

If multiple security layers are implemented to detect data leaks, then detection capability improves, but system complexity increases

Engineering Contradiction:
Improvedetection capability for data leaksVSAvoidnumber of security layers
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The secure proxy is designed as a multi-functional security platform that combines application-layer firewall capabilities, data leak prevention, protocol inspection, and anomaly detection in a single unified system. This universal approach provides comprehensive detection capabilities without requiring separate specialized security appliances for each function

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9954902B1Secure proxy
Publication Date: 2018.04.24 AMAZON TECH INC
  • US9954902B1 patent drawing
  • US9954902B1 patent drawing
  • US9954902B1 patent drawing

AI summary

Methods and systems are provided herein to enable secure proxying of network traffic between trusted and untrusted environments. In particular, a secure proxy may be provided that includes a set of policies. The policies may be applicable to various network protocol layers (e.g., an application layer), network traffic types, and/or endpoint resolution. The set of policies may be used to inspect, restrict and/or modify traffic between the trusted and untrusted environment to ensure data and network security. A proxy device may use the set of policies, for example, to obtain current service-related information (such as the list of IP addresses) currently associated with a computing resource requested by an application. Such endpoint information may be used, in turn, to update a white list.