Transparent Relay for Email Security Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer network security measures, such as antivirus software and firewalls, are inadequate in combating the increasing sophistication of malicious activities on public networks like the Internet, including viruses, spam, and covert channels, which require enhanced detection and response mechanisms.

Innovation Solution

A transparent relay system that intercepts and examines email and HTTP communications for network security policy violations, using promiscuous mode interfaces to enforce policies and redirect or discard malicious traffic, and integrates with a Security Operations Center (SOC) server to generate and enforce dynamic security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional antivirus software and firewalls are used for network security, then basic protective measures are provided, but they are inadequate against increasingly sophisticated malicious activities

Engineering Contradiction:
Improvenetwork security effectivenessVSAvoidsophistication of malicious activities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a transparent relay as an intermediary device positioned between email clients and servers. This relay intercepts, examines, and filters email communications, acting as a mediator that detects malicious activities (spam, viruses, covert channels) without requiring changes to client or server configurations. The relay enforces security policies by discarding or redirecting malicious traffic while allowing legitimate communications to pass through.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a transparent relay system is implemented to intercept and examine email communications for security policies, then detection and mitigation of malicious activities is improved, but network infrastructure complexity increases

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidnetwork infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The transparent relay operates autonomously by automatically examining email communications against configured security policies and enforcing actions without requiring manual intervention. The system self-manages the filtering process, making decisions based on predefined policies about what constitutes malicious activity, thereby reducing the need for complex manual security management while maintaining effective policy enforcement.

Inventive Principle:
Principle #25Self-service

3Difficulty of detecting and measuring

If promiscuous mode interfaces are used to receive diverted communications, then the relay can capture all network traffic for security examination, but the relay must process significantly more data

Engineering Contradiction:
Improvenetwork traffic capture capabilityVSAvoidprocessing load on relay
Core Design Contradiction:
Difficulty of detecting and measuringVSUse of energy by moving object

Solution Approach 1:

The patent extracts and focuses security examination only on specific portions of network traffic that are actually diverted to the relay for processing. Rather than processing all network traffic, the system selectively examines only the email communications that have been diverted to it, reducing the processing burden while maintaining effective security monitoring of targeted traffic.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS7926108B2SMTP network security processing in a transparent relay in a computer network
Publication Date: 2011.04.12 TREND MICRO INC
  • US7926108B2 patent drawing
  • US7926108B2 patent drawing
  • US7926108B2 patent drawing

AI summary

In one embodiment, a transparent relay receives diverted e-mail communications between an e-mail client and an e-mail server. The transparent relay may be configured to examine the e-mail communications for network security policy violations. E-mail communications that do not violate a network security policy may be relayed to their intended destination. Policy actions, such as discarding or redirection, may be performed on those that violate one or more network security policies. The transparent relay may include a pair of communications interfaces running in promiscuous mode, one for downstream communications and another for upstream communications. The transparent relay may decompose a network communication protocol to look network security policy violations.