发明名称 Inline inspection of security protocols
摘要 Systems and methods for inline security protocol inspection are provided. According to one embodiment, a security device receives an encrypted raw packet from a first network appliance and buffers the encrypted raw packet in a buffer. An inspection module accesses the encrypted raw packet from the buffer, decrypts the encrypted raw packet to produce a plain text and scans the plain text by the inspection module.
申请公布号 US9602498(B2) 申请公布日期 2017.03.21
申请号 US201314056870 申请日期 2013.10.17
申请人 Fortinet, Inc. 发明人 Wang Wei David;Jia Junfeng;Lu Hongbin
分类号 H04L29/06 主分类号 H04L29/06
代理机构 Hamilton, DeSanctis & Cha LLP 代理人 Hamilton, DeSanctis & Cha LLP
主权项 1. A method comprising: receiving, by a security device, a handshake message from a security protocol client; transmitting, by the security device, the handshake message to a security protocol server; receiving, by the security device, a response including a certificate of the security protocol server; transmitting, by the security device, a response including a certificate of the security device to the security protocol client; receiving, by the security device, an encrypted packet from the security protocol client, wherein application data contained in the encrypted packet is encrypted with a cipher suite deliberately caused to be selected for use in connection with both (i) a first security protocol session established between the security protocol client and the security device and (ii) a second security protocol session established between the security protocol server to which the encrypted packet is destined and the security device; buffering, by the security device, the encrypted packet in a buffer; accessing, by an inspection module of the security device, the encrypted packet from the buffer; decrypting the encrypted packet, by the inspection module, to produce a plain text version of the application data; scanning, by the inspection module, the plain text version of the application data; when a Transmission Control Protocol (TCP) sequence number of the first security protocol session is equivalent to a TCP sequence number of the second security protocol session, transmitting, by the security device, the encrypted packet to the security protocol server; and when a size of the certificate of the security device is smaller than a size of the certificate of the security protocol server, transmitting at least one more Secure Sockets Layer (SSL) record from the security device to the security protocol client so that the TCP sequence number of the first security protocol session is equivalent to the TCP sequence number of the second security protocol session.
地址 Sunnyvale CA US