Synthetic Request Injection for Cloud Metadata Retrieval

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud access security brokers (CASBs) face challenges in accessing missing metadata during transactions, limiting their ability to enforce appropriate policies, especially when metadata is not available in the transaction stream, and this deficiency hinders their capability to provide improved security posture and reduce data loss and exposure across multi-cloud, web, and email environments.

Innovation Solution

The implementation of synthetic request injection mechanisms that allow network security systems to independently retrieve missing metadata from cloud applications, using synthetic requests and responses, enabling self-sufficiency in metadata retrieval and reducing reliance on metadata mapping transactions, thereby expanding policy enforcement horizons and reducing redundant metadata synchronization and storage burdens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If CASBs rely on metadata mapping transactions to access metadata, then they can maintain system simplicity, but they face challenges in accessing missing metadata during transactions

Engineering Contradiction:
Improvemetadata accessibilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service by allowing the CASB to independently retrieve missing metadata through synthetic requests injected into the transaction stream, eliminating dependency on external metadata mapping transactions and enabling autonomous metadata acquisition

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A synthetic request mechanism acts as an intermediary between the CASB and the transaction stream, injecting specially crafted requests that elicit metadata responses from cloud applications without disrupting normal operations

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If CASBs use metadata mapping transactions to retrieve metadata, then they can obtain comprehensive metadata, but they experience redundant metadata synchronization and storage burdens

Engineering Contradiction:
Improvemetadata completenessVSAvoidsynchronization overhead
Core Design Contradiction:
Loss of informationVSLoss of energy

Solution Approach 1:

The system extracts only the specific metadata needed for policy enforcement from the transaction stream through targeted synthetic requests, rather than synchronizing and storing all available metadata, reducing redundant data handling

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary metadata retrieval by injecting synthetic requests before policy enforcement decisions are required, ensuring metadata is available when needed without last-minute synchronization overhead

Inventive Principle:
Principle #10Preliminary action

3Productivity

If CASBs access metadata in real-time during transactions, then they can enforce policies immediately, but they face limitations when metadata is not available in the transaction stream

Engineering Contradiction:
Improvepolicy enforcement speedVSAvoidmetadata availability
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The system performs preliminary metadata acquisition by injecting synthetic requests into the transaction stream to elicit metadata responses from cloud applications before policy enforcement decisions are required, ensuring both real-time enforcement and metadata availability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Synthetic requests serve as intermediaries that bridge the gap between real-time transaction processing and metadata availability, enabling the CASB to obtain necessary information without waiting for natural transaction flows

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11831685B2Application-specific data flow for synthetic request injection
Publication Date: 2023.11.28 NETSKOPE INC
  • US11831685B2 patent drawing
  • US11831685B2 patent drawing
  • US11831685B2 patent drawing

AI summary

The technology disclosed relates to application-specific data flow for synthetic request injection for cloud security enforcement. In particular, it relates to data flow logic configured to inject an incoming request directed to a cloud application in a processing path of a particular network security system.