Transparent Application Proxy for Virtual Patching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional segmentation systems fail to effectively block only malicious traffic to or from an application with known vulnerabilities without isolating the application from the network, lacking the capability to apply targeted security measures.

Innovation Solution

A system and method that configure an enforcement module on a host device to enforce a segmentation policy using a virtual patch, involving a transparent application proxy that filters traffic based on network and application layer data to block specific vulnerabilities, redirecting malicious traffic while allowing other communications to pass through.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional segmentation systems block traffic to or from an application with known vulnerabilities, then security protection is improved, but network connectivity is lost

Engineering Contradiction:
Improvesecurity protectionVSAvoidnetwork connectivity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the filtering approach into two distinct layers: network layer filtering (using traditional firewalls) and application layer filtering (using the transparent application proxy). This segmentation allows the system to block malicious application layer traffic while maintaining network layer connectivity, resolving the contradiction between security protection and network connectivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The transparent application proxy acts as an intermediary between the network and the vulnerable application. It intercepts and filters application layer traffic before reaching the application, blocking malicious requests while allowing legitimate traffic to pass through. This intermediary approach enables security protection without completely isolating the application from the network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional segmentation systems isolate an application from the network to protect against vulnerabilities, then security protection is improved, but application functionality is reduced

Engineering Contradiction:
Improvesecurity protectionVSAvoidapplication functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies filtering with local quality by creating application-specific filtering rules tailored to each vulnerability. Instead of blanket isolation, the transparent application proxy applies targeted filters that block only the specific malicious traffic patterns associated with known vulnerabilities while allowing other application functionalities to operate normally. This resolves the contradiction by providing security protection without reducing overall application functionality.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If transparent application proxy filters traffic at application layer, then filtering precision is improved, but device complexity increases

Engineering Contradiction:
Improvefiltering precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The transparent application proxy is designed with multi-functionality, serving as both a traffic filter and a vulnerability protection mechanism. It combines application layer filtering capabilities with integration to the existing segmentation policy framework, allowing a single device to perform multiple functions. This reduces the need for separate specialized devices, thereby managing system complexity while maintaining high filtering precision.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11516242B2Virtual patching in a label-based segmented network environment
Publication Date: 2022.11.29 ILLUMIO INC
  • US11516242B2 patent drawing
  • US11516242B2 patent drawing
  • US11516242B2 patent drawing

AI summary

A segmentation server configures and distributes rules for enforcing a segmentation policy that includes one or more virtual patches. The rules including the virtual patches are enforced by distributed enforcement modules that may execute on host devices or on network devices upstream from the host devices. An enforcement module enforces the rules using traffic filters that filter traffic based on network layer data. To implement a virtual patch, the traffic filters are configured to redirect traffic to or from an application being patched to a transparent application proxy. The transparent application proxy implements an application layer filter that filters traffic based on application layer data to block specific types of traffic associated with a vulnerability addressed by the virtual patch.