Web Proxy Application Migration with Automated Least-Privilege Policies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face challenges in effectively managing and monitoring application traffic on web proxies due to complex and frequently changing policies, leading to inefficiencies and ineffective security measures, especially with limited human resources.
Innovation Solution
A system and method for managing application traffic on web proxies that involves obtaining enriched metadata, identifying traffic patterns, generating access control lists, and converting them into proxy policies, with automated provisioning and hygiene modules to ensure secure and efficient connectivity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If strict least privileged access policy is enforced manually for each application, then security control is improved, but management complexity and resource requirements increase significantly
Solution Approach 1:
The system enables applications to self-register and automatically generate their own proxy policies through metadata enrichment and traffic analysis, eliminating the need for manual policy creation and updates for each application while maintaining security controls
Solution Approach 2:
The system dynamically adjusts proxy policies based on enriched application metadata and observed traffic patterns, automatically updating access control parameters without manual intervention to adapt to changing application requirements
2Manufacturing precision
If frequent policy change requests are processed manually for each application, then access control accuracy is improved, but productivity and efficiency deteriorate
Solution Approach 1:
The system performs preliminary traffic analysis and metadata enrichment to pre-determine appropriate proxy policies before they are needed, automatically generating access control rules based on observed application behavior and requirements
Solution Approach 2:
The system continuously monitors application traffic through proxy logs and feedback loops, automatically adjusting policies based on observed usage patterns to maintain accurate access control without manual intervention
3Measurement precision
If comprehensive application metadata collection is implemented, then policy generation accuracy is improved, but system complexity and data processing requirements increase
Solution Approach 1:
The system segments metadata collection into modular components (application inventory, traffic analysis, proxy log processing) that can be independently implemented and managed, reducing overall system complexity while achieving comprehensive data collection
Data Source
AI summary
A computer-implemented method for management of an application on an enterprise network which accesses external networks via a web proxy. The method comprises obtaining enriched metadata concerning an application executed on the enterprise network, the enriched metadata including at least source code information and ownership information, identifying application traffic on the enterprise network based on proxy log data, source IP and destination URL, generating an access control list (ACL) based on the enriched metadata and identified application traffic, the ACL including a source address of the application and a list of allowed destination addresses, converting the ACL into a proxy policy that can be processed by a web proxy to permit access by the application to the destination addresses in the ACL, and establishing data communication between the application and an external network based on the proxy policy.


