Web Application Security Protocol for Network-Application Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security products for web applications face challenges in integrating with network operations, with network-based security products struggling to efficiently correlate and communicate with application-based security viewpoints, leading to inefficiencies in maintaining service performance and user experience.
Innovation Solution
A communication protocol that inserts instructions and transaction IDs into HTTP headers of application messages, enabling reactive actions between application-based and network-based security products, allowing for enhanced web application security by piggybacking on existing application transactions and providing granular application context to network security solutions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network-based security products (firewalls, WAFs) are used to provide security context from a network perspective, then security coverage is improved, but the ability to correlate and communicate with application-based security viewpoints efficiently deteriorates
Solution Approach 1:
The patent introduces an intermediary communication protocol that acts as a mediator between network-based security products (firewalls, WAFs) and application-based security products (RASP). This protocol enables efficient correlation and communication by translating and standardizing interactions between the two different security viewpoints, resolving the integration complexity while maintaining comprehensive security coverage
Solution Approach 2:
The communication protocol is designed to be universal, enabling network-based security products to interact with multiple types of application-based security products through a standardized interface. This multi-functionality allows the same protocol to handle various security scenarios and product combinations, reducing integration complexity across different security architectures
2Measurement precision
If application-based security products (RASP) are implemented in the application runtime, then application security monitoring is improved, but integration with network operations efficiently deteriorates
Solution Approach 1:
The protocol serves as an intermediary that connects application-based security products with network operations, enabling precise application security monitoring to be effectively integrated with network-level security activities. This mediator translates application-specific security events into network-understandable formats, maintaining monitoring precision while improving integration efficiency
Solution Approach 2:
The communication protocol establishes a feedback mechanism where application-based security products can send security events and receive instructions from network-based security products, and vice versa. This bidirectional feedback loop enables precise application monitoring to be coordinated with network operations, resolving the integration efficiency problem while maintaining monitoring accuracy
3Device complexity
If security products operate independently at network and application levels, then product simplicity is maintained, but security event correlation and reactive actions deteriorate
Solution Approach 1:
The patent segments the security system into distinct network-based and application-based components that operate independently with well-defined interfaces. Each component maintains its simplicity while the segmentation enables standardized interaction through the communication protocol, improving security event correlation without compromising product simplicity
Solution Approach 2:
The communication protocol acts as an intermediary layer that enables correlation between independently operating security products. This mediator handles the complexity of event correlation and reactive actions, allowing individual products to remain simple while achieving effective security event correlation through standardized messaging and event exchange
Data Source
AI summary
In one embodiment, a device of a first security type obtains an application message for an application transaction along with a transaction ID. The device inserts an instruction related to the application transaction into a first header of the application message, and sends the application message downstream. The device may then receive an application response message from a downstream device in response to the application message, the downstream device of a second security type different from the first security type, the application response message having a reply to the instruction in a second header of the application response message and the transaction ID correlating the application response message to the application transaction. As such, the device may then perform one or more reactive actions in response to the reply to the instruction. In another embodiment, the downstream device conversely receives the instruction and inserts the reply.


