Traffic Mirroring Correlation for Secure VPN Decryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Encrypted network traffic obstructs monitoring and analysis in cloud-based infrastructure, as existing technologies hinder efficient traffic mirroring and decryption for network traffic analysis without performance impact.
Innovation Solution
An orchestrator configures security appliances to mirror network traffic and correlate packets with cryptographic keys, decrypting them using on-the-fly random keys and re-encrypting with an organization's public key for secure conveyance to a repository, preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network traffic is encrypted using IPsec VPN tunnels, then data security and privacy are improved, but traffic monitoring and analysis capabilities deteriorate
Solution Approach 1:
The patent introduces a cloud service provider as an intermediary that establishes its own encrypted VPN tunnels between data centers. This intermediary infrastructure allows the provider to mirror and monitor traffic flowing through its network while customers maintain their encrypted communications. The provider's tunnel endpoints can correlate mirrored traffic with cryptographic keys to enable monitoring without breaking customer encryption.
2Difficulty of detecting and measuring
If traffic mirroring is implemented for monitoring purposes, then network analysis capability is improved, but performance and security of original traffic deteriorate
Solution Approach 1:
The patent segments traffic monitoring into separate mirrored copies that are independent of the original traffic flow. Cloud service providers can mirror traffic to separate analysis channels without impacting the performance of production networks. The mirroring occurs at the network infrastructure level, allowing parallel processing of original and monitored traffic.
Solution Approach 2:
The cloud service provider acts as an intermediary that handles the performance burden of traffic mirroring and analysis, isolating it from customer networks. The provider's infrastructure absorbs the overhead of copying, storing, and analyzing traffic, preventing performance degradation in the original network systems.
3Difficulty of detecting and measuring
If cryptographic keys are stored for traffic decryption, then traffic analysis capability is improved, but security against unauthorized access deteriorates
Solution Approach 1:
The patent moves cryptographic key storage to a different security dimension by implementing hierarchical key management across multiple VPN tunnel layers. Customer traffic is encrypted in customer VPN tunnels, then re-encrypted in cloud provider VPN tunnels with separate key management. This dimensional separation allows the provider to access traffic for monitoring while maintaining cryptographic security boundaries that prevent unauthorized access.
Solution Approach 2:
The cloud service provider acts as a security intermediary that manages cryptographic keys in a controlled environment. Rather than customers managing keys that could be compromised, the provider's infrastructure securely stores and manages keys for its own VPN tunnels, providing a security boundary that protects against unauthorized access while enabling authorized monitoring.
Data Source
AI summary
An orchestrator that manages security appliances for an organization determines a sink configured for traffic mirroring and correspondingly configures components for the correlation and secure conveyance. The orchestrator also configures the security appliances. The orchestrator configures the security appliances to copy cryptographic keys (hereinafter “tunnel keys”) and identifiers associated with the keys of secure VPN tunnels established by the security appliances to a repository of the cloud-service provider. The orchestrator configures a virtual machine associated with the mirroring sink with correlation logic. The virtual machine correlates sets of packets aggregated across different mirroring streams and tunnel keys with the associated identifiers. Correlating the sets of packets and the tunnel keys allows an organization to efficiently access the content of the encrypted packets or facilitates secure conveyance.


