Synthetic Request Injection for Cloud Metadata Retrieval
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud access security brokers (CASBs) face challenges in accessing metadata for cloud policy enforcement, particularly when metadata is not available in transaction streams, limiting their ability to enforce appropriate policies and resulting in inadequate security posture and increased risk of data loss and exposure across multi-cloud, web, and email environments.
Innovation Solution
The implementation of synthetic request injection mechanisms that allow network security systems to independently retrieve missing metadata from cloud applications, using synthetic requests and responses to gather necessary metadata for policy enforcement, even when it is not available in the initial transaction stream, thereby making CASBs self-sufficient and improving their intermediation protocols compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If CASBs rely on metadata mapping transactions or periodic synchronization to access metadata, then metadata availability is limited and policy enforcement is inadequate, but implementing synthetic request injection increases system complexity
Solution Approach 1:
The CASB system performs self-service by independently injecting synthetic requests into cloud application transaction streams to retrieve metadata without requiring external metadata mapping transactions or periodic synchronization. The system autonomously generates and processes its own metadata retrieval requests, making it self-sufficient in obtaining the information needed for policy enforcement.
Solution Approach 2:
The system performs preliminary action by injecting synthetic requests proactively into transaction streams before policy enforcement decisions are required. This allows metadata to be retrieved in advance, ensuring it is available when needed for security policy evaluation and enforcement actions.
2Loss of information
If CASBs use traditional metadata access methods, then system operation is simpler, but metadata availability is insufficient for effective policy enforcement
Solution Approach 1:
The synthetic request injection mechanism acts as an intermediary between the CASB system and cloud application metadata. Instead of directly accessing metadata through traditional mapping transactions, the system uses synthetic requests as a mediating mechanism to retrieve metadata from cloud applications, bridging the information gap.
Solution Approach 2:
The synthetic request injection mechanism serves multiple functions: it retrieves metadata, validates transaction streams, enforces security policies, and updates metadata caches. This multi-functional approach consolidates several operations into a single mechanism, improving metadata availability without proportionally increasing operational complexity.
3Reliability
If CASBs do not have access to missing metadata, then security posture is inadequate and data loss risk increases, but implementing synthetic request injection requires additional system resources
Solution Approach 1:
The system applies partial action by injecting only the specific synthetic requests needed to retrieve missing metadata rather than continuously monitoring or synchronizing all metadata. This targeted approach retrieves sufficient information for policy enforcement without excessive resource consumption associated with comprehensive metadata synchronization.
Data Source
AI summary
The technology disclosed describes a network security system that is configured to configure a synthetic request with an object identifier, and to inject the synthetic request into an application session to transmit the synthetic request to a cloud application. The synthetic request is configured to retrieve object metadata about the object using the object identifier. The network security system is further configured to receive from the cloud application a response to the synthetic request. The response supplies the object metadata.


