Transparent Application Proxy for Virtual Patching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional segmentation systems fail to effectively block only malicious traffic to or from an application with known vulnerabilities without isolating the application from the network, lacking the capability to apply targeted security measures.
Innovation Solution
A system and method that configure an enforcement module on a host device to enforce a segmentation policy using a virtual patch, involving a transparent application proxy that filters traffic based on network and application layer data to block specific vulnerabilities, redirecting malicious traffic while allowing other communications to pass through.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional segmentation systems block traffic to or from an application with known vulnerabilities, then security protection is improved, but network connectivity is lost
Solution Approach 1:
The patent segments the filtering approach into two distinct layers: network layer filtering (using traditional firewalls) and application layer filtering (using the transparent application proxy). This segmentation allows the system to block malicious application layer traffic while maintaining network layer connectivity, resolving the contradiction between security protection and network connectivity.
Solution Approach 2:
The transparent application proxy acts as an intermediary between the network and the vulnerable application. It intercepts and filters application layer traffic before reaching the application, blocking malicious requests while allowing legitimate traffic to pass through. This intermediary approach enables security protection without completely isolating the application from the network.
2Reliability
If conventional segmentation systems isolate an application from the network to protect against vulnerabilities, then security protection is improved, but application functionality is reduced
Solution Approach 1:
The patent applies filtering with local quality by creating application-specific filtering rules tailored to each vulnerability. Instead of blanket isolation, the transparent application proxy applies targeted filters that block only the specific malicious traffic patterns associated with known vulnerabilities while allowing other application functionalities to operate normally. This resolves the contradiction by providing security protection without reducing overall application functionality.
3Measurement precision
If transparent application proxy filters traffic at application layer, then filtering precision is improved, but device complexity increases
Solution Approach 1:
The transparent application proxy is designed with multi-functionality, serving as both a traffic filter and a vulnerability protection mechanism. It combines application layer filtering capabilities with integration to the existing segmentation policy framework, allowing a single device to perform multiple functions. This reduces the need for separate specialized devices, thereby managing system complexity while maintaining high filtering precision.
Data Source
AI summary
A segmentation server configures and distributes rules for enforcing a segmentation policy that includes one or more virtual patches. The rules including the virtual patches are enforced by distributed enforcement modules that may execute on host devices or on network devices upstream from the host devices. An enforcement module enforces the rules using traffic filters that filter traffic based on network layer data. To implement a virtual patch, the traffic filters are configured to redirect traffic to or from an application being patched to a transparent application proxy. The transparent application proxy implements an application layer filter that filters traffic based on application layer data to block specific types of traffic associated with a vulnerability addressed by the virtual patch.


