Synthetic Request Injection for Cloud Metadata Retrieval

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud access security brokers (CASBs) face challenges in accessing metadata for cloud policy enforcement, particularly when metadata is not available in transaction streams, limiting their ability to enforce appropriate policies and resulting in inadequate security posture and increased risk of data loss and exposure across multi-cloud, web, and email environments.

Innovation Solution

The implementation of synthetic request injection mechanisms that allow network security systems to independently retrieve missing metadata from cloud applications, using synthetic requests and responses to gather necessary metadata for policy enforcement, even when it is not available in the initial transaction stream, thereby making CASBs self-sufficient and improving their intermediation protocols compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If CASBs rely on metadata mapping transactions or periodic synchronization to access metadata, then metadata availability is limited and policy enforcement is inadequate, but implementing synthetic request injection increases system complexity

Engineering Contradiction:
Improvepolicy enforcement reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The CASB system performs self-service by independently injecting synthetic requests into cloud application transaction streams to retrieve metadata without requiring external metadata mapping transactions or periodic synchronization. The system autonomously generates and processes its own metadata retrieval requests, making it self-sufficient in obtaining the information needed for policy enforcement.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary action by injecting synthetic requests proactively into transaction streams before policy enforcement decisions are required. This allows metadata to be retrieved in advance, ensuring it is available when needed for security policy evaluation and enforcement actions.

Inventive Principle:
Principle #10Preliminary action

2Loss of information

If CASBs use traditional metadata access methods, then system operation is simpler, but metadata availability is insufficient for effective policy enforcement

Engineering Contradiction:
Improvemetadata availabilityVSAvoidoperation simplicity
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The synthetic request injection mechanism acts as an intermediary between the CASB system and cloud application metadata. Instead of directly accessing metadata through traditional mapping transactions, the system uses synthetic requests as a mediating mechanism to retrieve metadata from cloud applications, bridging the information gap.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The synthetic request injection mechanism serves multiple functions: it retrieves metadata, validates transaction streams, enforces security policies, and updates metadata caches. This multi-functional approach consolidates several operations into a single mechanism, improving metadata availability without proportionally increasing operational complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If CASBs do not have access to missing metadata, then security posture is inadequate and data loss risk increases, but implementing synthetic request injection requires additional system resources

Engineering Contradiction:
Improvesecurity postureVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system applies partial action by injecting only the specific synthetic requests needed to retrieve missing metadata rather than continuously monitoring or synchronizing all metadata. This targeted approach retrieves sufficient information for policy enforcement without excessive resource consumption associated with comprehensive metadata synchronization.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11888902B2Object metadata-based cloud policy enforcement using synthetic request injection
Publication Date: 2024.01.30 NETSKOPE INC
  • US11888902B2 patent drawing
  • US11888902B2 patent drawing
  • US11888902B2 patent drawing

AI summary

The technology disclosed describes a network security system that is configured to configure a synthetic request with an object identifier, and to inject the synthetic request into an application session to transmit the synthetic request to a cloud application. The synthetic request is configured to retrieve object metadata about the object using the object identifier. The network security system is further configured to receive from the cloud application a response to the synthetic request. The response supplies the object metadata.