Synthetic Request Injection for Cloud Metadata Retrieval

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud access security brokers (CASBs) face challenges in accessing metadata for context-based policy enforcement due to the exacting intermediation protocols of cloud service providers, leading to limited ability in enforcing appropriate policies, especially when metadata is not available in transaction streams.

Innovation Solution

The implementation of synthetic request injection by a network security system to independently retrieve missing metadata from cloud applications, using synthetic requests and responses across various network protocols, enabling self-sufficiency in metadata retrieval and policy enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud access security brokers follow exacting intermediation protocols of cloud service providers, then they can maintain proper intermediation relationships, but they face limited ability to access metadata for policy enforcement

Engineering Contradiction:
Improveintermediation protocol complianceVSAvoidmetadata accessibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a synthetic request mechanism as an intermediary approach. The CASB sends synthetic requests to cloud application servers to retrieve metadata that would otherwise be inaccessible through normal transaction streams. This synthetic request system acts as a mediator between the CASB's policy enforcement needs and the cloud provider's data access restrictions, allowing metadata retrieval without violating intermediation protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If metadata is not available in transaction streams, then cloud service provider protocols are maintained, but context-based policy enforcement becomes difficult

Engineering Contradiction:
Improveprotocol adherenceVSAvoidpolicy enforcement capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by sending synthetic requests to retrieve metadata before actual policy enforcement decisions are made. The CASB proactively obtains necessary metadata about cloud resources, users, and transactions through synthetic requests, ensuring this information is available when needed for policy evaluation, rather than attempting to extract it from existing transaction streams.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The CASB serves itself by independently retrieving metadata through synthetic requests without relying on cloud service providers to supply this information through transaction streams. The system becomes self-sufficient in obtaining the metadata it needs for policy enforcement, eliminating dependence on provider-cooperative information sharing.

Inventive Principle:
Principle #25Self-service

3Loss of information

If synthetic requests are injected to retrieve metadata, then metadata availability for policy enforcement improves, but system complexity increases

Engineering Contradiction:
Improvemetadata availabilityVSAvoidrequest-response mechanism complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The synthetic request mechanism is designed to be universally applicable across multiple cloud service providers and various types of metadata retrieval needs. Rather than implementing provider-specific or transaction-type-specific mechanisms, the patent creates a general-purpose synthetic request system that can retrieve diverse metadata (user information, resource details, transaction context) from different cloud platforms through a unified approach, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11757944B2Network intermediary with network request-response mechanism
Publication Date: 2023.09.12 NETSKOPE INC
  • US11757944B2 patent drawing
  • US11757944B2 patent drawing
  • US11757944B2 patent drawing

AI summary

The technology disclosed describes a system. The system comprises a network security system interposed between clients and cloud applications. The network security system is configured to generate a synthetic request, and inject the synthetic request into an application session to transmit the synthetic request to a cloud application and receive a response to the synthetic request from the cloud application.