Selective HTTP/HTTPS Inspection Routing to Cut NSS Latency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security systems (NSS) introduce latency and consume significant computational resources due to resource-intensive deep inspection of network traffic, particularly for high-bandwidth, low-data-loss-prevention-value content, leading to network traffic jams and diminished user experience.

Innovation Solution

Implementing an endpoint routing client (ERC) with a bypass list to classify traffic as 'loss prevention inspectable' or 'bandwidth conservable', tunneling the latter directly to web services without NSS inspection, and using server-side bypass lists to reclassify and bypass inspection for certain traffic types, reducing computational burden and latency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If deep inspection of network traffic is performed by NSS, then data security is improved, but latency increases and network performance deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments network traffic into different categories (loss prevention inspectable vs. bandwidth conservable) and applies different inspection policies to each segment. This allows critical traffic to receive thorough inspection while non-critical traffic bypasses inspection, resolving the contradiction between security and latency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different quality levels of inspection to different parts of the network traffic. High-value traffic receives full deep inspection for security, while low-value traffic receives minimal or no inspection, optimizing the balance between security enforcement and network performance.

Inventive Principle:
Principle #3Local quality

2Reliability

If deep inspection of network traffic is performed by NSS, then data security is improved, but computational resources are consumed

Engineering Contradiction:
Improvedata securityVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent divides traffic into segments based on their data loss prevention value. By identifying and separating low-value traffic, the system avoids expending computational resources on inspecting traffic that contributes minimally to security objectives, thus reducing overall resource consumption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial inspection action only to traffic that requires it. Instead of performing excessive deep inspection on all traffic, the system applies inspection selectively to high-value traffic, reducing unnecessary computational overhead while maintaining security effectiveness.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If deep inspection of network traffic is performed by NSS, then data security is improved, but network throughput decreases

Engineering Contradiction:
Improvedata securityVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts bandwidth conservable traffic from the main inspection pipeline and routes it directly to destinations without deep inspection. This extraction removes the bottleneck caused by inspection processing, allowing high-volume traffic to flow freely and maintaining network throughput.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments traffic flow into inspected and non-inspected paths. By creating a separate bypass path for low-value traffic, the system maintains high network throughput for the majority of traffic while still providing security inspection for critical traffic segments.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12500940B2Selective deep inspection in security enforcement by a network security system (NSS)
Publication Date: 2025.12.16 NETSKOPE INC
  • US12500940B2 patent drawing
  • US12500940B2 patent drawing
  • US12500940B2 patent drawing

AI summary

The technology disclosed relates to reducing error in security enforcement by a network security system (abbreviated NSS). The NSS classifies incoming connection access requests as loss prevention inspectable or connection preserving by determining their conformance or non-conformance with semantic and content requirements of HTTP and HTTPs protocols. The NSS forwards the loss prevention inspectable connection access requests to a data inspection and loss prevention appliance (abbreviated DILPA) for deep inspection. The NSS directly sends the connection preserving connection access requests to the destination servers, preventing connection termination and error generation.