Endpoint Security Agent Injecting App ID into Packet Headers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in managing network connections, particularly with encrypted traffic, as encryption prevents both malicious and benign actors from understanding network traffic, leading to inefficiencies and burdens in identification, categorization, and management.

Innovation Solution

A computer-implemented method where a security agent on an endpoint detects connection attempts and injects identifying information into the options field of a network packet header, allowing an in-line proxy security device to manage connections based on revealed application information without decrypting the payload.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is used to secure network traffic, then security and privacy are improved, but the ability to identify, categorize, and manage network traffic deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidtraffic identification
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the network packet into two parts: encrypted payload (for security) and unencrypted header with application identification bytes (for management). This allows simultaneous achievement of security through encryption and traffic identification through the exposed header information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism (application identification bytes in the header) that mediates between the encrypted payload and the security management system. This intermediary carries sufficient information for identification and categorization without requiring decryption of the actual payload.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If decryption is performed to enable traffic management, then traffic identification capability is improved, but system complexity and authorization requirements increase

Engineering Contradiction:
Improvetraffic identificationVSAvoiddecryption complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent extracts only the necessary identification information (application identification bytes) from the encrypted payload and places it in the unencrypted header. This eliminates the need for full decryption while still enabling traffic management functions.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of performing full decryption (excessive action), the patent performs only partial action by exposing minimal necessary information in the header. This provides sufficient capability for traffic management without the overhead of complete decryption.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If application identification information is exposed in network packets, then traffic management capability is improved, but information security may be compromised

Engineering Contradiction:
Improvetraffic management efficiencyVSAvoidinformation security
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent applies local quality by exposing application identification information only in specific locations (header bytes) while keeping the actual payload encrypted. This localized exposure provides necessary management capability without compromising overall information security.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11283768B1Systems and methods for managing connections
Publication Date: 2022.03.22 GEN DIGITAL INC
  • US11283768B1 patent drawing
  • US11283768B1 patent drawing
  • US11283768B1 patent drawing

AI summary

The disclosed computer-implemented method for managing connections may include (i) detecting, by a security agent on an endpoint, an attempt by another application on the endpoint to establish a connection according to a specific Internet protocol, and (ii) injecting, by the security agent on the endpoint, into an options field within a header of a network packet within the connection, the header formatted according to the specific Internet protocol, at least one byte that reveals identifying information about the application to enable an in-line proxy security device to manage the connection according to the revealed identifying information. Various other methods, systems, and computer-readable media are also disclosed.