Cookie Anonymization via Lexical Analysis in FMITM Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for controlling the disclosure of private information over internet-connected devices lack fine-grained controls, leading to unintended leakage of sensitive data through cookies and beacons, which traditional packet inspectors fail to inspect at the content level, resulting in vulnerabilities to privacy breaches.
Innovation Solution
Implementing a centralized, intelligent layer, such as a friendly man-in-the-middle (FMITM) device, that performs lexical analysis on cookies and beacons within data streams to detect and block or anonymize sensitive information, employing blocking or masking mechanisms to protect private data from escaping the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional packet inspection methods are used, then network traffic can be monitored at basic levels, but content-level inspection of cookies and beacons is not achieved, resulting in privacy leakage
Solution Approach 1:
The patent introduces a friendly man-in-the-middle (FMITM) device as an intermediary component between the source and destination. This FMITM performs lexical analysis on cookies and beacons, enabling content-level inspection without requiring complex modifications to existing endpoint devices. The intermediary handles the sophisticated analysis that would otherwise be too complex for traditional packet inspectors.
2Loss of information
If centralized intelligent layer with lexical analysis is implemented, then content-aware detection of sensitive information is achieved, but device complexity increases
Solution Approach 1:
The patent segments the privacy protection function into a dedicated centralized lexical analysis component. Instead of distributing complex analysis capabilities across multiple devices, the system concentrates the lexical analysis functionality in a single FMITM device, while other components handle simpler tasks like policy enforcement and data forwarding. This segmentation makes the overall system more manageable despite the sophistication of the analysis.
3Reliability
If fine-grained control policies are established, then unauthorized disclosure is prevented, but ease of operation decreases due to policy management complexity
Solution Approach 1:
The patent implements self-service mechanisms where the FMITM automatically performs lexical analysis, detects sensitive information patterns, and enforces privacy policies without requiring manual intervention for each decision. The system autonomously evaluates cookies and beacons against established policies, reducing the operational burden on users while maintaining fine-grained control.
4Measurement precision
If lexical analysis is performed on all cookies, then detection precision improves, but processing time increases
Solution Approach 1:
The patent applies partial action by performing lexical analysis selectively based on privacy policies and the nature of the data being transmitted. Rather than uniformly analyzing every single cookie with the same depth, the system adjusts the analysis intensity according to policy requirements and risk levels, achieving sufficient detection accuracy while reducing unnecessary processing time for low-risk items.
Data Source
AI summary
Example embodiments of the present invention provide a method, an apparatus and a computer program product for cookie anonymization and rejection. The method includes receiving a cookie included in a data stream transmitted from a source intended for a destination. A lexical analysis of the cookie included in the data stream is then performed to determine state information associated with the cookie. The state information associated with the cookie then may be forwarded to the destination according to the lexical analysis. Example embodiments of the present invention specifically targets cookies and beacons that flow through a system, and historically track cookie and beacon traffic in order to perform drill-down inspection on the contents. This inspection allows for detection of sensitive information such as credit cards, location, and any other personal info, as well as the potential presence of malware which is performing unusual behavior within the private system.


