Synthetic Request Injection for Cloud Metadata Retrieval
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud access security brokers (CASBs) face challenges in accessing missing metadata during cloud transactions, limiting their ability to enforce appropriate security policies, especially when metadata is not available in the transaction stream, and current solutions are not self-sufficient in retrieving missing metadata while adhering to exacting intermediation protocols of cloud service providers.
Innovation Solution
The implementation of a synthetic request-response mechanism that allows the network security system to generate and inject synthetic requests during application sessions to retrieve missing metadata from cloud applications, enabling self-sufficiency in metadata retrieval and policy enforcement without relying on metadata mapping transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If CASBs rely on metadata mapping transactions to retrieve metadata, then they can obtain metadata information, but they cannot access missing metadata when it is not available in the transaction stream
Solution Approach 1:
The system performs preliminary actions by injecting synthetic requests during application sessions to proactively retrieve metadata before it is needed for policy enforcement. This allows the CASB to obtain metadata that would otherwise be missing from the transaction stream, ensuring metadata availability when required for security decisions.
Solution Approach 2:
The synthetic request-response mechanism acts as an intermediary between the CASB and cloud applications. By injecting synthetic requests through this intermediary mechanism, the system can retrieve metadata from cloud applications in a manner that adheres to cloud service provider protocols while overcoming the limitation of relying solely on metadata mapping transactions.
2Adaptability or versatility
If CASBs use traditional metadata retrieval methods, then they can enforce security policies, but they are not self-sufficient and require metadata mapping transactions
Solution Approach 1:
The CASB system performs self-service by autonomously injecting synthetic requests to retrieve its own metadata needs without requiring external metadata mapping transactions. This self-sufficient approach allows the CASB to independently obtain missing metadata from cloud applications, enhancing adaptability while reducing dependency on external systems.
Solution Approach 2:
The synthetic request-response mechanism provides universal functionality by enabling the CASB to retrieve metadata through multiple pathways: both traditional metadata mapping transactions and the new synthetic request injection method. This multi-functionality makes the system more adaptable to different scenarios while maintaining operational simplicity through a unified approach.
3Reliability
If CASBs access metadata during cloud transactions, then they can enforce security policies, but they cannot retrieve metadata that is not present in the transaction stream
Solution Approach 1:
The system takes preliminary action by injecting synthetic requests to retrieve metadata before policy enforcement decisions are made. This proactive approach ensures that metadata is obtained in advance, preventing information loss and enabling accurate security policy enforcement based on complete metadata information.
Solution Approach 2:
The synthetic request-response mechanism establishes a feedback loop where the CASB can query cloud applications for metadata and receive responses that supplement or correct the metadata available in the transaction stream. This feedback ensures that the most accurate and complete metadata is used for policy enforcement decisions.
Data Source
AI summary
The technology disclosed describes a system. The system comprises a network security system interposed between clients and cloud applications. The network security system is configured to process an incoming request from a client and generate metadata. The network security system is further configured to transmit the incoming request to a cloud application. The network security system is further configured to configure the metadata to expire after an expiration window. The network security system is further configured to receive, after the expiration window, a further incoming request from the client. The further incoming request is directed towards the cloud application and subject to policy enforcement that requires the expired metadata. The network security system is further configured to hold the further incoming request and transmit a synthetic request to the cloud application. The synthetic request is configured to retrieve the expired metadata from the cloud application.


