IP Library Patent Application 18680336
Patent Application
App. No. 18/680,336

SYSTEM AND METHOD FOR TRAFFIC-BASED COMPUTING INTERFACE MISCONFIGURATION DETECTION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/680,336
Abstract

A system and method for traffic-based misconfiguration detection. A method includes analyzing a first set of computing interface traffic data to identify types of data included among traffic to and from a computing interface; creating at least one computing interface schema based on the analysis, wherein each computing interface schema defines a plurality of schema fields and a plurality of corresponding schema values, wherein each schema value indicates a normal behavior for the computing interface with respect to the corresponding schema field; and identifying a misconfiguration of the computing interface based on the at least one computing interface schema and a second set of computing interface traffic data.

Claims (34)

1 . A method for traffic-based misconfiguration detection, comprising:

analyzing a first set of computing interface traffic data to identify types of data included among traffic to and from a computing interface;

creating at least one computing interface schema based on the analysis, wherein each computing interface schema defines a plurality of schema fields and a plurality of corresponding schema values, wherein each schema value indicates a normal behavior for the computing interface with respect to the corresponding schema field; and

identifying a misconfiguration of the computing interface based on the at least one computing interface schema and a second set of computing interface traffic data.

2 . The method of claim 1 , further comprising:

performing at least one mitigation action with respect to the computing interface based on the identified misconfiguration.

3 . The method of claim 1 , wherein the at least one computing interface schema includes at least one request schema and at least one response schema.

4 . The method of claim 1 , wherein at least one of the first set of computing interface traffic data and the second set of computing interface traffic data includes duplicated traffic.

5 . The method of claim 4 , wherein the duplicated traffic is created based on data extracted from a communications session by building at least one of a plurality of communication protocol layers based on data extracted from other layers of the plurality of communication protocol layers.

6 . The method of claim 1 , wherein the plurality of schema fields for each computing interface schema includes at least one field having a predetermined optional marker indicating that the respective schema field is optionally included in any given request or response of traffic to and from the computing interface.

7 . The method of claim 1 , wherein the misconfiguration is identified based further on at least one predetermined kind of protected data for which additional precautions are required.

8 . The method of claim 7 , wherein each of the at least one computing interface schema includes a first schema value for a corresponding first schema field representing authentication status, wherein the identified misconfiguration is based on a combination of the first schema value for one of the at least one computing interface schema indicating a lack of required authentication and a portion of the second set of computing interface traffic data including one of the at least one predetermined kind of protected data.

9 . The method of claim 1 , further comprising:

duplicating traffic to and from a computing interface, wherein duplicating the traffic includes extracting data from a plurality of communication protocol layers used for communications with the computing interface, wherein the first set of computing interface traffic data includes the duplicated traffic.

10 . A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

analyzing a first set of computing interface traffic data to identify types of data included among traffic to and from a computing interface;

creating at least one computing interface schema based on the analysis, wherein each computing interface schema defines a plurality of schema fields and a plurality of corresponding schema values, wherein each schema value indicates a normal behavior for the computing interface with respect to the corresponding schema field; and

identifying a misconfiguration of the computing interface based on the at least one computing interface schema and a second set of computing interface traffic data.

11 . A system for traffic-based misconfiguration detection, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

analyze a first set of computing interface traffic data to identify types of data included among traffic to and from a computing interface;

create at least one computing interface schema based on the analysis, wherein each computing interface schema defines a plurality of schema fields and a plurality of corresponding schema values, wherein each schema value indicates a normal behavior for the computing interface with respect to the corresponding schema field; and

identify a misconfiguration of the computing interface based on the at least one computing interface schema and a second set of computing interface traffic data.

12 . The system of claim 11 , wherein the system is further configured to:

perform at least one mitigation action with respect to the computing interface based on the identified misconfiguration.

13 . The system of claim 11 , wherein the at least one computing interface schema includes at least one request schema and at least one response schema.

14 . The system of claim 11 , wherein at least one of the first set of computing interface traffic data and the second set of computing interface traffic data includes duplicated traffic.

15 . The system of claim 14 , wherein the duplicated traffic is created based on data extracted from a communications session by building at least one of a plurality of communication protocol layers based on data extracted from other layers of the plurality of communication protocol layers.

16 . The system of claim 11 , wherein the plurality of schema fields for each computing interface schema includes at least one field having a predetermined optional marker indicating that the respective schema field is optionally included in any given request or response of traffic to and from the computing interface.

17 . The system of claim 11 , wherein the misconfiguration is identified based further on at least one predetermined kind of protected data for which additional precautions are required.

18 . The system of claim 17 , wherein each of the at least one computing interface schema includes a first schema value for a corresponding first schema field representing authentication status, wherein the identified misconfiguration is based on a combination of the first schema value for one of the at least one computing interface schema indicating a lack of required authentication and a portion of the second set of computing interface traffic data including one of the at least one predetermined kind of protected data.

19 . The system of claim 11 , wherein the system is further configured to:

duplicating traffic to and from a computing interface, wherein duplicating the traffic includes extracting data from a plurality of communication protocol layers used for communications with the computing interface, wherein the first set of computing interface traffic data includes the duplicated traffic.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2025
From: LEVI, SHAY; GOLAN, OZ; SHPIGEL, OREN; MORAG, ANER; DANKNER, DOR; MARTZIANO, RON; VAKS, PAVEL; ZIGMAN, HILA; MAMAN, NETANEL; ALKALAI, YUVAL
To: NONAME GATE LTD.
Reel/Frame 070495/0037 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 27, 2025
From: NONAME GATE LTD.
To: AKAMAI TECHNOLOGIES, INC.
Reel/Frame 070344/0362 →