Web Application Security Protocol for Network-Application Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security products for web applications face challenges in integrating with network operations, with network-based security products struggling to efficiently correlate and communicate with application-based security viewpoints, leading to inefficiencies in maintaining service performance and user experience.

Innovation Solution

A communication protocol that inserts instructions and transaction IDs into HTTP headers of application messages, enabling reactive actions between application-based and network-based security products, allowing for enhanced web application security by piggybacking on existing application transactions and providing granular application context to network security solutions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network-based security products (firewalls, WAFs) are used to provide security context from a network perspective, then security coverage is improved, but the ability to correlate and communicate with application-based security viewpoints efficiently deteriorates

Engineering Contradiction:
Improvesecurity coverageVSAvoidintegration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary communication protocol that acts as a mediator between network-based security products (firewalls, WAFs) and application-based security products (RASP). This protocol enables efficient correlation and communication by translating and standardizing interactions between the two different security viewpoints, resolving the integration complexity while maintaining comprehensive security coverage

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The communication protocol is designed to be universal, enabling network-based security products to interact with multiple types of application-based security products through a standardized interface. This multi-functionality allows the same protocol to handle various security scenarios and product combinations, reducing integration complexity across different security architectures

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If application-based security products (RASP) are implemented in the application runtime, then application security monitoring is improved, but integration with network operations efficiently deteriorates

Engineering Contradiction:
Improveapplication security monitoringVSAvoidintegration efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The protocol serves as an intermediary that connects application-based security products with network operations, enabling precise application security monitoring to be effectively integrated with network-level security activities. This mediator translates application-specific security events into network-understandable formats, maintaining monitoring precision while improving integration efficiency

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The communication protocol establishes a feedback mechanism where application-based security products can send security events and receive instructions from network-based security products, and vice versa. This bidirectional feedback loop enables precise application monitoring to be coordinated with network operations, resolving the integration efficiency problem while maintaining monitoring accuracy

Inventive Principle:
Principle #23Feedback

3Device complexity

If security products operate independently at network and application levels, then product simplicity is maintained, but security event correlation and reactive actions deteriorate

Engineering Contradiction:
Improveproduct simplicityVSAvoidsecurity event correlation
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the security system into distinct network-based and application-based components that operate independently with well-defined interfaces. Each component maintains its simplicity while the segmentation enables standardized interaction through the communication protocol, improving security event correlation without compromising product simplicity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The communication protocol acts as an intermediary layer that enables correlation between independently operating security products. This mediator handles the complexity of event correlation and reactive actions, allowing individual products to remain simple while achieving effective security event correlation through standardized messaging and event exchange

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11343281B2Enhanced web application security communication protocol
Publication Date: 2022.05.24 CISCO TECHNOLOGY INC
  • US11343281B2 patent drawing
  • US11343281B2 patent drawing
  • US11343281B2 patent drawing

AI summary

In one embodiment, a device of a first security type obtains an application message for an application transaction along with a transaction ID. The device inserts an instruction related to the application transaction into a first header of the application message, and sends the application message downstream. The device may then receive an application response message from a downstream device in response to the application message, the downstream device of a second security type different from the first security type, the application response message having a reply to the instruction in a second header of the application response message and the transaction ID correlating the application response message to the application transaction. As such, the device may then perform one or more reactive actions in response to the reply to the instruction. In another embodiment, the downstream device conversely receives the instruction and inserts the reply.