Selective MITM Gateway Inspection for Smart Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Smart devices on home and business networks are vulnerable to hacking, with users often unaware of compromised devices until they fail, and existing solutions do not effectively detect or thwart malicious activity targeting these devices.

Innovation Solution

The implementation of crowdsourced Bayesian packet analysis for anomaly detection, selective Man-In-The-Middle (MITM) gateway inspection of network traffic, and smart device fingerprinting to identify services and predict vulnerabilities, utilizing Bayesian priors and crowdsourced data to analyze network traffic and device metadata for early threat identification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MITM gateway performs inspection of all network traffic associated with smart devices, then network security detection capability is improved, but network performance and device operation are adversely affected

Engineering Contradiction:
Improvenetwork security detection capabilityVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The MITM gateway performs packet capture and inspection selectively rather than on all traffic. It captures packets from smart devices and analyzes them for anomalies, but only inspects a subset of traffic based on device classification and anomaly detection needs, rather than performing full-depth inspection on every packet flowing through the network

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system segments network traffic analysis by classifying smart devices into different categories and applying different inspection strategies. The gateway divides traffic into segments based on device type, priority, and risk level, allowing focused inspection on high-risk traffic while minimizing interference with low-risk communications

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If MITM gateway captures and inspects packets from all smart devices, then anomaly detection accuracy is improved, but device operation is adversely affected

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoiddevice operation
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The MITM gateway acts as an intermediary between smart devices and the network, capturing packets at the gateway level rather than installing monitoring software on each device. This intermediary approach allows comprehensive packet capture and analysis while keeping the actual devices unaware and unaffected by the monitoring process

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs partial packet inspection by analyzing packet headers and metadata rather than full packet contents in all cases. It captures all packets from classified devices but applies different levels of inspection depth based on anomaly indicators, device classification, and risk assessment

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12081518B1Selective inspection of network traffic associated with a plurality of network-connected smart devices using man-in-the-middle (MITM) gateway
Publication Date: 2024.09.03 EVERYTHING SET INC
  • US12081518B1 patent drawing
  • US12081518B1 patent drawing
  • US12081518B1 patent drawing

AI summary

A method is provided for performing selective inspection of network traffic associated with a plurality of network-connected smart devices using a Man-In-The-Middle (MITM) gateway. The MITM gateway operate in a first mode or a second mode for each of the network-connected smart devices. The first mode configures the MITM gateway to perform inspection of network traffic associated with the respective network-connected smart device, and the second mode configures the MITM gateway to not perform any inspection of network traffic associated with the respective network-connected smart device. The MITM gateway is changed to operate in the second mode for a respective network-connected smart device when it is detected that the MITM gateway operating in the first mode is adversely affecting the operation of the respective network-connected smart device.