Selective HTTP/HTTPS Inspection Routing to Cut NSS Latency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network security systems (NSS) introduce latency and consume significant computational resources due to resource-intensive deep inspection of network traffic, particularly for high-bandwidth, low-data-loss-prevention-value content, leading to network traffic jams and diminished user experience.
Innovation Solution
Implementing an endpoint routing client (ERC) with a bypass list to classify traffic as 'loss prevention inspectable' or 'bandwidth conservable', tunneling the latter directly to web services without NSS inspection, and using server-side bypass lists to reclassify and bypass inspection for certain traffic types, reducing computational burden and latency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If deep inspection of network traffic is performed by NSS, then data security is improved, but latency increases and network performance deteriorates
Solution Approach 1:
The patent segments network traffic into different categories (loss prevention inspectable vs. bandwidth conservable) and applies different inspection policies to each segment. This allows critical traffic to receive thorough inspection while non-critical traffic bypasses inspection, resolving the contradiction between security and latency.
Solution Approach 2:
The patent applies different quality levels of inspection to different parts of the network traffic. High-value traffic receives full deep inspection for security, while low-value traffic receives minimal or no inspection, optimizing the balance between security enforcement and network performance.
2Reliability
If deep inspection of network traffic is performed by NSS, then data security is improved, but computational resources are consumed
Solution Approach 1:
The patent divides traffic into segments based on their data loss prevention value. By identifying and separating low-value traffic, the system avoids expending computational resources on inspecting traffic that contributes minimally to security objectives, thus reducing overall resource consumption.
Solution Approach 2:
The patent applies partial inspection action only to traffic that requires it. Instead of performing excessive deep inspection on all traffic, the system applies inspection selectively to high-value traffic, reducing unnecessary computational overhead while maintaining security effectiveness.
3Reliability
If deep inspection of network traffic is performed by NSS, then data security is improved, but network throughput decreases
Solution Approach 1:
The patent extracts bandwidth conservable traffic from the main inspection pipeline and routes it directly to destinations without deep inspection. This extraction removes the bottleneck caused by inspection processing, allowing high-volume traffic to flow freely and maintaining network throughput.
Solution Approach 2:
The patent segments traffic flow into inspected and non-inspected paths. By creating a separate bypass path for low-value traffic, the system maintains high network throughput for the majority of traffic while still providing security inspection for critical traffic segments.
Data Source
AI summary
The technology disclosed relates to reducing error in security enforcement by a network security system (abbreviated NSS). The NSS classifies incoming connection access requests as loss prevention inspectable or connection preserving by determining their conformance or non-conformance with semantic and content requirements of HTTP and HTTPs protocols. The NSS forwards the loss prevention inspectable connection access requests to a data inspection and loss prevention appliance (abbreviated DILPA) for deep inspection. The NSS directly sends the connection preserving connection access requests to the destination servers, preventing connection termination and error generation.


