Granular offloading of a proxied secure session
Abstract
A device may receive encrypted traffic associated with a secure session. The device may determine, based on the encrypted traffic, information associated with an offload service to be applied to the encrypted traffic associated with the secure session. The information associated with the offload service may indicate whether the encrypted traffic is permitted to bypass inspection by one or more security services. The device may selectively permit the encrypted traffic, associated with the secure session, to bypass inspection by the one or more security services based on the information associated with the offload service.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A method comprising:
determining, by a device, that no security service, of one or more security services, is to inspect all traffic of a session; determining, by the device and based on determining that no security services is to inspect all traffic of the session, that a security service, of the one or more security services, is to inspect traffic in a client-to-server (C2S) direction; determining, by the device and based on determining that the security service is to inspect traffic in the C2S direction, that an offload service includes inspecting traffic traveling in the C2S direction; identifying, by the device, the offload service based on determining that the offload service includes inspecting the traffic traveling in the C2S direction; and applying, by the device, the offload service based on identifying the offload service.
22 . The method of claim 21 ,
wherein the session is a secure session, and wherein the traffic traveling in the C2S direction includes encrypted traffic.
23 . The method of claim 21 , further comprising:
determining, based on determining that no security services is to inspect all traffic of the session, that no security service, of the one or more security services, is to inspect traffic in a server-to-client (S2C) direction,
wherein determining that the offload service includes inspecting the traffic traveling in the C2S direction includes:
determining, based on determining that the security service is to inspect traffic in the C2S direction and based on determining that no security service, of the one or more security services, is to inspect the traffic in the S2C direction, that the offload service includes inspecting the traffic traveling in the C2S direction.
24 . The method of claim 21 , wherein the offload service is identified during an establishment of the session.
25 . The method of claim 21 , wherein the offload service is identified after an establishment of the session.
26 . The method of claim 21 , wherein the offload service is identified based on a request provided by a client device or a service device.
27 . The method of claim 21 , wherein the offload service is identified based on a change to at the one or more security services.
28 . The method of claim 21 , further comprising:
storing information associated with the offload service after identifying the offload service.
29 . The method of claim 28 , wherein the information associated with the offload service comprises one or more of:
information that describes the manner in which encrypted traffic may bypass decryption and re-encryption by the device, information that identifies the session, information that identifies at least one of a client device or a server device, or information that identifies a threshold amount of encrypted traffic to be inspected in one or more of the C2S direction or the S2C directions.
30 . A system, comprising:
one or more memories; and one or more processors communicatively coupled to the one or more memories, configured to:
determine that no security service, of one or more security services, is to inspect all traffic of a session;
determine, based on determining that no security services is to inspect all traffic of the session, that a security service, of the one or more security services, is to inspect traffic in a client-to-server (C2S) direction;
determine, based on determining that the security service is to inspect traffic in the C2S direction, that an offload service includes inspecting traffic traveling in the C2S direction;
identify the offload service based on determining that the offload service includes inspecting the traffic traveling in the C2S direction; and
apply the offload service based on identifying the offload service.
31 . The system of claim 30 , wherein the one or more processors are further configured to:
determine, based on determining that no security services is to inspect all traffic of the session, that no security service, of the one or more security services, is to inspect traffic in a server-to-client (S2C) direction,
wherein, when determining that the offload service includes inspecting the traffic traveling in the C2S direction, the one or more processors are configured to:
determine, based on determining that the security service is to inspect traffic in the C2S direction and based on determining that no security service, of the one or more security services, is to inspect the traffic in the S2C direction, that the offload service includes inspecting the traffic traveling in the C2S direction.
32 . The system of claim 30 , wherein the offload service is identified during an establishment of the session.
33 . The system of claim 30 , wherein the offload service is identified based on a change to at the one or more security services.
34 . The system of claim 30 , wherein the one or more processors are further configured to:
store information associated with the offload service after identifying the offload service.
35 . A non-transitory computer-readable medium storing instructions, the instructions comprising:
one or more instructions that, when executed by one or more processors, cause the one or more processors to:
determine that no security service, of one or more security services, is to inspect all traffic of a session;
determine, based on determining that no security services is to inspect all traffic of the session, that a security service, of the one or more security services, is to inspect traffic in a client-to-server (C2S) direction;
determine, based on determining that the security service is to inspect traffic in the C2S direction, that an offload service includes inspecting traffic traveling in the C2S direction;
identify the offload service based on determining that the offload service includes inspecting the traffic traveling in the C2S direction; and
apply the offload service based on identifying the offload service.
36 . The non-transitory computer-readable medium of claim 35 , wherein the one or more instructions, when executed by the one or more processors, further cause the one or more processors to:
determine, based on determining that no security services is to inspect all traffic of the session, that no security service, of the one or more security services, is to inspect traffic in a server-to-client (S2C) direction,
wherein the one or more instructions to determine that the offload service includes inspecting the traffic traveling in the C2S direction comprise one or more instructions to:
determine, based on determining that the security service is to inspect traffic in the C2S direction and based on determining that no security service, of the one or more security services, is to inspect the traffic in the S2C direction, that the offload service includes inspecting the traffic traveling in the C2S direction.
37 . The non-transitory computer-readable medium of claim 35 , wherein the offload service is identified after an establishment of the session.
38 . The non-transitory computer-readable medium of claim 35 , wherein the offload service is identified based on a request provided by a client device or a service device.
39 . The non-transitory computer-readable medium of claim 35 , wherein the offload service is identified based on a change to at the one or more security services.
40 . The non-transitory computer-readable medium of claim 35 , wherein the one or more instructions, when executed by the one or more processors, further cause the one or more processors to:
store information associated with the offload service after identifying the offload service.Join the waitlist — get patent alerts
Track US2020028822A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.