Web Proxy Application Migration with Automated Least-Privilege Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in effectively managing and monitoring application traffic on web proxies due to complex and frequently changing policies, leading to inefficiencies and ineffective security measures, especially with limited human resources.

Innovation Solution

A system and method for managing application traffic on web proxies that involves obtaining enriched metadata, identifying traffic patterns, generating access control lists, and converting them into proxy policies, with automated provisioning and hygiene modules to ensure secure and efficient connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If strict least privileged access policy is enforced manually for each application, then security control is improved, but management complexity and resource requirements increase significantly

Engineering Contradiction:
Improvesecurity controlVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables applications to self-register and automatically generate their own proxy policies through metadata enrichment and traffic analysis, eliminating the need for manual policy creation and updates for each application while maintaining security controls

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically adjusts proxy policies based on enriched application metadata and observed traffic patterns, automatically updating access control parameters without manual intervention to adapt to changing application requirements

Inventive Principle:
Principle #35Parameter changes

2Manufacturing precision

If frequent policy change requests are processed manually for each application, then access control accuracy is improved, but productivity and efficiency deteriorate

Engineering Contradiction:
Improveaccess control accuracyVSAvoidpolicy management efficiency
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The system performs preliminary traffic analysis and metadata enrichment to pre-determine appropriate proxy policies before they are needed, automatically generating access control rules based on observed application behavior and requirements

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors application traffic through proxy logs and feedback loops, automatically adjusting policies based on observed usage patterns to maintain accurate access control without manual intervention

Inventive Principle:
Principle #23Feedback

3Measurement precision

If comprehensive application metadata collection is implemented, then policy generation accuracy is improved, but system complexity and data processing requirements increase

Engineering Contradiction:
Improvepolicy generation accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments metadata collection into modular components (application inventory, traffic analysis, proxy log processing) that can be independently implemented and managed, reducing overall system complexity while achieving comprehensive data collection

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12388829B1Enterprise application management and migration on a web proxy
Publication Date: 2025.08.12 MORGAN STANLEY SERVICES GROUP INC
  • US12388829B1 patent drawing
  • US12388829B1 patent drawing
  • US12388829B1 patent drawing

AI summary

A computer-implemented method for management of an application on an enterprise network which accesses external networks via a web proxy. The method comprises obtaining enriched metadata concerning an application executed on the enterprise network, the enriched metadata including at least source code information and ownership information, identifying application traffic on the enterprise network based on proxy log data, source IP and destination URL, generating an access control list (ACL) based on the enriched metadata and identified application traffic, the ACL including a source address of the application and a list of allowed destination addresses, converting the ACL into a proxy policy that can be processed by a web proxy to permit access by the application to the destination addresses in the ACL, and establishing data communication between the application and an external network based on the proxy policy.