Synthetic Request Injection for Cloud Metadata Retrieval

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud access security brokers (CASBs) face challenges in accessing missing metadata during cloud transactions, limiting their ability to enforce appropriate security policies, especially when metadata is not available in the transaction stream, and current solutions are not self-sufficient in retrieving missing metadata while adhering to exacting intermediation protocols of cloud service providers.

Innovation Solution

The implementation of a synthetic request-response mechanism that allows the network security system to generate and inject synthetic requests during application sessions to retrieve missing metadata from cloud applications, enabling self-sufficiency in metadata retrieval and policy enforcement without relying on metadata mapping transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If CASBs rely on metadata mapping transactions to retrieve metadata, then they can obtain metadata information, but they cannot access missing metadata when it is not available in the transaction stream

Engineering Contradiction:
Improvemetadata availabilityVSAvoidpolicy enforcement capability
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The system performs preliminary actions by injecting synthetic requests during application sessions to proactively retrieve metadata before it is needed for policy enforcement. This allows the CASB to obtain metadata that would otherwise be missing from the transaction stream, ensuring metadata availability when required for security decisions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The synthetic request-response mechanism acts as an intermediary between the CASB and cloud applications. By injecting synthetic requests through this intermediary mechanism, the system can retrieve metadata from cloud applications in a manner that adheres to cloud service provider protocols while overcoming the limitation of relying solely on metadata mapping transactions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If CASBs use traditional metadata retrieval methods, then they can enforce security policies, but they are not self-sufficient and require metadata mapping transactions

Engineering Contradiction:
Improvemetadata retrieval capabilityVSAvoidsystem dependency
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The CASB system performs self-service by autonomously injecting synthetic requests to retrieve its own metadata needs without requiring external metadata mapping transactions. This self-sufficient approach allows the CASB to independently obtain missing metadata from cloud applications, enhancing adaptability while reducing dependency on external systems.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The synthetic request-response mechanism provides universal functionality by enabling the CASB to retrieve metadata through multiple pathways: both traditional metadata mapping transactions and the new synthetic request injection method. This multi-functionality makes the system more adaptable to different scenarios while maintaining operational simplicity through a unified approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If CASBs access metadata during cloud transactions, then they can enforce security policies, but they cannot retrieve metadata that is not present in the transaction stream

Engineering Contradiction:
Improvepolicy enforcement accuracyVSAvoidmissing metadata
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system takes preliminary action by injecting synthetic requests to retrieve metadata before policy enforcement decisions are made. This proactive approach ensures that metadata is obtained in advance, preventing information loss and enabling accurate security policy enforcement based on complete metadata information.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The synthetic request-response mechanism establishes a feedback loop where the CASB can query cloud applications for metadata and receive responses that supplement or correct the metadata available in the transaction stream. This feedback ensures that the most accurate and complete metadata is used for policy enforcement decisions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11647052B2Synthetic request injection to retrieve expired metadata for cloud policy enforcement
Publication Date: 2023.05.09 NETSKOPE INC
  • US11647052B2 patent drawing
  • US11647052B2 patent drawing
  • US11647052B2 patent drawing

AI summary

The technology disclosed describes a system. The system comprises a network security system interposed between clients and cloud applications. The network security system is configured to process an incoming request from a client and generate metadata. The network security system is further configured to transmit the incoming request to a cloud application. The network security system is further configured to configure the metadata to expire after an expiration window. The network security system is further configured to receive, after the expiration window, a further incoming request from the client. The further incoming request is directed towards the cloud application and subject to policy enforcement that requires the expired metadata. The network security system is further configured to hold the further incoming request and transmit a synthetic request to the cloud application. The synthetic request is configured to retrieve the expired metadata from the cloud application.