Transparent Relay for Email Security Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer network security measures, such as antivirus software and firewalls, are inadequate in combating the increasing sophistication of malicious activities on public networks like the Internet, including viruses, spam, and covert channels, which require enhanced detection and response mechanisms.
Innovation Solution
A transparent relay system that intercepts and examines email and HTTP communications for network security policy violations, using promiscuous mode interfaces to enforce policies and redirect or discard malicious traffic, and integrates with a Security Operations Center (SOC) server to generate and enforce dynamic security policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional antivirus software and firewalls are used for network security, then basic protective measures are provided, but they are inadequate against increasingly sophisticated malicious activities
Solution Approach 1:
The patent introduces a transparent relay as an intermediary device positioned between email clients and servers. This relay intercepts, examines, and filters email communications, acting as a mediator that detects malicious activities (spam, viruses, covert channels) without requiring changes to client or server configurations. The relay enforces security policies by discarding or redirecting malicious traffic while allowing legitimate communications to pass through.
2Reliability
If a transparent relay system is implemented to intercept and examine email communications for security policies, then detection and mitigation of malicious activities is improved, but network infrastructure complexity increases
Solution Approach 1:
The transparent relay operates autonomously by automatically examining email communications against configured security policies and enforcing actions without requiring manual intervention. The system self-manages the filtering process, making decisions based on predefined policies about what constitutes malicious activity, thereby reducing the need for complex manual security management while maintaining effective policy enforcement.
3Difficulty of detecting and measuring
If promiscuous mode interfaces are used to receive diverted communications, then the relay can capture all network traffic for security examination, but the relay must process significantly more data
Solution Approach 1:
The patent extracts and focuses security examination only on specific portions of network traffic that are actually diverted to the relay for processing. Rather than processing all network traffic, the system selectively examines only the email communications that have been diverted to it, reducing the processing burden while maintaining effective security monitoring of targeted traffic.
Data Source
AI summary
In one embodiment, a transparent relay receives diverted e-mail communications between an e-mail client and an e-mail server. The transparent relay may be configured to examine the e-mail communications for network security policy violations. E-mail communications that do not violate a network security policy may be relayed to their intended destination. Policy actions, such as discarding or redirection, may be performed on those that violate one or more network security policies. The transparent relay may include a pair of communications interfaces running in promiscuous mode, one for downstream communications and another for upstream communications. The transparent relay may decompose a network communication protocol to look network security policy violations.


