IP Library Granted Patent US 12,034,752
Granted Patent B2
US 12,034,752 · App. 17/505,973 · Granted Jul 9, 2024

System and method for traffic-based computing interface misconfiguration detection

Inventors: Shay Levi (Tel Aviv, IL); Oz Golan (Ramat Gan, IL); Oren Shpigel (Tel Aviv, IL); Aner Morag (Tel Aviv, IL); Dor Dankner (Tel Aviv, IL); Ron Martziano (Ramat Gan, IL); Pavel Vaks (Tel Aviv, IL); Hila Zigman (Ramat Gan, IL); Netanel Maman (Mazkeret Batia, IL); Yuval Alkalai Tavori (Ramat Gan, IL)
Assignee: NONAME GATE LTD
H04L63/1425H04L63/0236H04L63/1416H04L63/145H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,034,752
App. No.
17/505,973
Granted
Jul 9, 2024
Kind
B2
Abstract

A system and method for traffic-based misconfiguration detection. A method includes analyzing a first set of computing interface traffic data to identify types of data included among traffic to and from a computing interface; creating at least one computing interface schema based on the analysis, wherein each computing interface schema defines a plurality of schema fields and a plurality of corresponding schema values, wherein each schema value indicates a normal behavior for the computing interface with respect to the corresponding schema field; and identifying a misconfiguration of the computing interface based on the at least one computing interface schema and a second set of computing interface traffic data.

Claims (35)

1. A method for traffic-based misconfiguration detection, comprising:

duplicating traffic to and from a computing interface, wherein duplicating the traffic includes extracting data from a plurality of communication protocol layers used for communications with the computing interface and converting the extracted data into a unified data modeling format;

analyzing a first set of computing interface traffic data including the duplicated traffic in order to identify types of data included among the traffic to and from the computing interface;

creating at least one computing interface schema based on the analysis, wherein each computing interface schema defines a plurality of schema fields and a plurality of corresponding schema values, wherein each schema value indicates a normal behavior for the computing interface with respect to the corresponding schema field; and

identifying a misconfiguration of the computing interface based on the at least one computing interface schema and a second set of computing interface traffic data.

2. The method of claim 1 , further comprising:

performing at least one mitigation action with respect to the computing interface based on the identified misconfiguration.

3. The method of claim 1 , wherein the at least one computing interface schema includes at least one request schema and at least one response schema.

4. The method of claim 1 , wherein the duplicated traffic is a first set of duplicated traffic, wherein the second set of computing interface traffic data includes a second set of duplicated traffic.

5. The method of claim 1 , wherein the duplicated traffic is created based on the extracted data by building at least one of the plurality of communication protocol layers based on data extracted from other layers of the plurality of communication protocol layers.

6. The method of claim 1 , wherein the plurality of schema fields for each computing interface schema includes at least one field having a predetermined optional marker indicating that the respective schema field is optionally included in any given request or response of traffic to and from the computing interface.

7. The method of claim 1 , wherein the misconfiguration is identified based further on at least one predetermined kind of protected data for which additional precautions are required.

8. The method of claim 1 , wherein each of the at least one computing interface schema includes a first schema value for a corresponding first schema field representing authentication status, wherein the identified misconfiguration is based on a combination of the first schema value for one of the at least one computing interface schema indicating a lack of required authentication and a portion of the second set of computing interface traffic data including one of the at least one predetermined kind of protected data.

9. The method of claim 1 , wherein the plurality of schema fields includes at least one of: authentication status, channel by which data is communicate, protocol used for communicating data, communication method, email address, mailing address, social security number, and phone number.

10. A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

duplicating traffic to and from a computing interface, wherein duplicating the traffic includes extracting data from a plurality of communication protocol layers used for communications with the computing interface and converting the extracted data into a unified data modeling format;

analyzing a first set of computing interface traffic data including the duplicated traffic in order to identify types of data included among the traffic to and from the computing interface;

creating at least one computing interface schema based on the analysis, wherein each computing interface schema defines a plurality of schema fields and a plurality of corresponding schema values, wherein each schema value indicates a normal behavior for the computing interface with respect to the corresponding schema field; and

identifying a misconfiguration of the computing interface based on the at least one computing interface schema and a second set of computing interface traffic data.

11. A system for traffic-based misconfiguration detection, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

duplicate traffic to and from a computing interface, wherein duplicating the traffic includes extracting data from a plurality of communication protocol layers used for communications with the computing interface and converting the extracted data into a unified data modeling format;

analyze a first set of computing interface traffic data including the duplicated traffic in order to identify types of data included among the traffic to and from the computing interface;

create at least one computing interface schema based on the analysis, wherein each computing interface schema defines a plurality of schema fields and a plurality of corresponding schema values, wherein each schema value indicates a normal behavior for the computing interface with respect to the corresponding schema field; and

identify a misconfiguration of the computing interface based on the at least one computing interface schema and a second set of computing interface traffic data.

12. The system of claim 11 , wherein the system is further configured to:

perform at least one mitigation action with respect to the computing interface based on the identified misconfiguration.

13. The system of claim 11 , wherein the at least one computing interface schema includes at least one request schema and at least one response schema.

14. The system of claim 11 , wherein the duplicated traffic is a first set of duplicated traffic, wherein the second set of computing interface traffic data includes a second set of duplicated traffic.

15. The system of claim 11 , wherein the duplicated traffic is created based on the extracted data by building at least one of the plurality of communication protocol layers based on data extracted from other layers of the plurality of communication protocol layers.

16. The system of claim 11 , wherein the plurality of schema fields for each computing interface schema includes at least one field having a predetermined optional marker indicating that the respective schema field is optionally included in any given request or response of traffic to and from the computing interface.

17. The system of claim 11 , wherein the misconfiguration is identified based further on at least one predetermined kind of protected data for which additional precautions are required.

18. The system of claim 11 , wherein each of the at least one computing interface schema includes a first schema value for a corresponding first schema field representing authentication status, wherein the identified misconfiguration is based on a combination of the first schema value for one of the at least one computing interface schema indicating a lack of required authentication and a portion of the second set of computing interface traffic data including one of at least one predetermined kind of protected data.

19. The system of claim 11 , wherein the plurality of schema fields includes at least one of: authentication status, channel by which data is communicate, protocol used for communicating data, communication method, email address, mailing address, social security number, and phone number.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 27, 2025
From: NONAME GATE LTD.
To: AKAMAI TECHNOLOGIES, INC.
Reel/Frame 070344/0362 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 10TH CONVEYING PARTY'S NAME PREVIOUSLY RECORDED ON REEL 57897 FRAME 754. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 31, 2024
From: LEVI, SHAY; GOLAN, OZ; SHPIGEL, OREN; MORAG, ANER; DANKNER, DOR; MARTZIANO, RON; VAKS, PAVEL; ZIGMAN, HILA; MAMAN, NETANEL; ALKALAI TAVORI, YUVAL
To: NONAME GATE LTD
Reel/Frame 067592/0637 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2021
From: LEVI, SHAY; GOLAN, OZ; SHPIGEL, OREN; MORAG, ANER; DANKNER, DOR; MARTZIANO, RON; VAKS, PAVEL; ZIGMAN, HILA; MAMAN, NETANEL; ALKALAI, YUVAL
To: NONAME GATE LTD
Reel/Frame 057897/0754 →
Continuity (1)
Related Publication 20230123196A1 · Apr 20, 2023