Unified Policy Enforcement for Cloud Traffic Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current policy enforcement systems struggle to securely manage and enforce access controls across diverse cloud services, including peer-to-peer file sharing, multimedia communication sessions, and web traffic, especially when dealing with dynamic and evolving cloud applications that lack predictable IP addresses and ports, leading to challenges in scaling and load balancing.

Innovation Solution

A cloud-based policy enforcement system that unifies packet-based and protocol-based access control, threat detection, and activity contextualization, using a policy manager to dynamically distribute policies and detect enforcement issues, enabling secure processing of inspectable and non-inspectable traffic across various protocols and applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a cloud-based policy enforcement system is implemented to securely manage access controls across diverse cloud services, then security coverage and policy enforcement capability are improved, but system complexity and deployment difficulty increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a unified policy enforcement point (PEP) that handles multiple cloud services (SaaS, PaaS, IaaS) and various traffic types (inspectable and non-inspectable) through a single system. This universal approach allows the system to provide comprehensive security coverage across diverse cloud environments without requiring separate enforcement mechanisms for each service type, thereby improving security coverage while managing system complexity through consolidation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces a cloud-based policy decision point (PDP) as an intermediary that centralizes policy management and distribution. This mediator component handles the complex tasks of policy validation, conversion, and dynamic distribution to multiple PEPs, effectively decoupling the complexity of policy management from the enforcement points themselves. This allows the system to achieve high security coverage while keeping individual PEP components relatively simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the system dynamically distributes policies across multiple cloud services, then adaptability to evolving cloud applications is improved, but policy management complexity increases

Engineering Contradiction:
Improveadaptability to cloud applicationsVSAvoidpolicy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic policy distribution mechanisms where the PDP can automatically validate, convert, and push policies to PEPs in real-time based on changing cloud service conditions. The system dynamically adapts to new cloud applications and services by automatically updating policy enforcement without requiring manual reconfiguration of each PEP, thereby achieving high adaptability while managing complexity through automation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent incorporates feedback mechanisms where PEPs report policy enforcement status and cloud service conditions back to the PDP. This feedback loop enables the system to automatically adjust policy distribution and enforcement strategies based on real-time conditions, improving adaptability to evolving cloud applications while reducing management complexity through automated responses to feedback information.

Inventive Principle:
Principle #23Feedback

3Reliability

If the system inspects and processes all cloud traffic, then threat detection capability is improved, but processing time and system resources increase

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements differentiated inspection strategies where the PDP makes local decisions about which traffic requires full inspection and which can use simplified processing. The system applies different levels of inspection quality to different traffic types based on their security risk profiles, thereby maintaining high threat detection capability for critical traffic while reducing processing time for lower-risk traffic through selective inspection.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent applies partial inspection actions to certain traffic types where full inspection is not necessary. The PDP can determine that some traffic flows require only basic filtering or sampling rather than complete deep packet inspection, thereby maintaining adequate threat detection capability while significantly reducing processing time and resource consumption for those specific traffic streams.

Inventive Principle:
Principle #16Partial or excessive action

4Adaptability or versatility

If the system supports multiple protocols and traffic types, then versatility of security services is improved, but device complexity increases

Engineering Contradiction:
Improveversatility of security servicesVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent designs the PEP and PDP components to handle multiple protocols (HTTP, HTTPS, FTP, SMTP, etc.) and traffic types (inspectable and non-inspectable) through unified processing mechanisms. This universal design allows a single system configuration to provide versatility across diverse cloud services without requiring separate specialized components for each protocol, thereby achieving high versatility while managing device complexity through consolidation and standardization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11848949B2Dynamic distribution of unified policies in a cloud-based policy enforcement system
Publication Date: 2023.12.19 NETSKOPE INC
  • US11848949B2 patent drawing
  • US11848949B2 patent drawing
  • US11848949B2 patent drawing

AI summary

The technology discloses a method applied by a policy manager to a cloud-based security system that unifies functions of access control and traffic inspection, threat detection and activity contextualization on inspectable and non-inspectable traffic, with a data manager coupled to the policy manager storing a superset of fields used to specify security policies across the cloud-based unified functions, including common fields shared by two or more of the functions. The method includes the manager validating, saving and distributing policy specifications applicable to respective functions among the functions, and receiving requests for policy specifications stored in common fields from each of the functions, converting the common fields into values used by a respective requesting function, and returning the values of the field used by the respective requesting function to any requesting function among the functions of access control and traffic inspection, threat detection and activity contextualization on inspectable and non-inspectable traffic.