HyperBridge.Art — Inline DUT Validation Tap¶
One-page datasheet for customer trials. Plain-English, no acronym soup. Hand to network engineers, security architects, and procurement.
What it is¶
A 1U commodity appliance that slots inline between an upstream device and a Next-Generation Firewall (NGFW / IDS / IPS / TLS-inspecting middlebox), transparently forwards every packet at wire rate, and simultaneously feeds the full TLSStress.Art 6-pillar inspection-effectiveness validation framework — without requiring you to configure a single SPAN session on your switch.
Why it matters¶
Today, measuring whether your TLS-decrypting middlebox is actually doing what it claims requires a switch SPAN port. That requirement excludes:
- SMB / managed-services customers running prosumer switches without SPAN
- Enterprise data centers with every SPAN slot already taken by SIEM / DLP
- Regulated environments (finance, gov, health) under change-control lock
- 30-day proof-of-value trials that can't disrupt production switch config
HyperBridge.Art removes the SPAN dependency. Drop the appliance in the cable path; everything else just works.
Hardware tiers — pick your envelope¶
| Tier | NIC | Failover on service crash | Throughput | Cost target | Production-ready |
|---|---|---|---|---|---|
| T1 production HW-FTW | Silicom PE-series / Napatech / Endace | Hardware relay, 5–50 ms | up to 100 Gbps | $1k–$15k | ✅ |
| T2 software FTW | Mellanox ConnectX / Intel | Kernel bridge, 200 ms–1 s | up to 100 Gbps | $400–$2k | ✅ (non-critical paths) |
| T3 lab / test-bench | Any dual-port NIC | None — link drops | up to 10 Gbps | $50–$500 | ❌ lab only |
⚠ T3 must NOT be deployed in production. The orchestrator hard-stops if the configured tier does not match the loaded driver — your operations team cannot accidentally degrade.
How it slots in¶
Upstream switch / router DUT (NGFW / IDS / IPS)
│ ▲
▼ │
┌────────────────────────────────────────────────────┐
│ HyperBridge.Art appliance │
│ ─ NIC port A ←── HW bypass relay ──→ NIC port B ─ │
│ │ │ │
│ └──── packet copy ──────┘ │
│ ▼ │
│ SPAN-1 / 6-pillar framework │
└─────────────────────────────────────────────────────┘
The packet copy stream is bit-identical to a switch-SPAN-fed deployment. You can run a mixed deployment (some flows via SPAN, some via HyperBridge) with a single instance of the 6-pillar framework consuming both.
What it delivers¶
- Per-flow inspection-effectiveness verdicts — pass / fail / inconclusive per DUT inspection feature (TLS decryption, signature matching, app-ID, malware scanning)
- Fast-path detection — flags when the DUT is silently dropping inspection on fast-path / flow-offload traffic
- Decryption coverage — measures the fraction of TLS sessions the DUT is actually decrypting, broken down by certificate issuer
- Wire-versus-syslog cross-correlation — flags per-flow disagreements between what hit the wire and what the DUT logged
- Bypass-event tamper-evident timeline — every fail-to-wire engagement / recovery written to a SHA-256 hash chain; dashboard surfaces a verifier button
Deployment posture¶
- Bare metal: 2 systemd services (
hyperbridge-orchestrator+hyperbridge-watchdog); shipped as a small Docker image - Kubernetes: DaemonSet pinned to the node with the bypass NIC via
hyperbridge.art/tier=<T1|T2|T3>label - Observability: Prometheus
/metricson both binaries;/statusJSON for dashboards - Audit: bypass-event JSONL → sealed audit hash-chain (ADR 0029)
Operator UI¶
/admin/hyperbridge-art— config + live status; pick driver vendor at runtime/admin/hyperbridge-art/bypass-history— tamper-evident timeline of every bypass engagement, filtered by tier / vendor / reason, with a chain-verify button
What we don't claim¶
- Not a replacement for HW firewalls — HyperBridge.Art measures the firewall, it doesn't perform inspection
- Not a packet broker (Gigamon, Ixia) — single inline path, not a many-to-many fan-out
- Ultra-low-latency workloads (HFT, RDMA, voice/video) — measured per-packet added latency is 2–5 µs on T1, 10–50 µs on T2; fitness envelope is documented per tier
Patent posture¶
Patent Family D — Inline DUT Validation Tap via Bypass-Capable NIC with Integrated Effectiveness Measurement — provisional filing target 2026-Q4. The novel combination is the inline tap + the 6-pillar effectiveness framework (Families A, B, C). Hardware bypass primitives are well-trodden prior art; the combination is what's new.
Get started¶
| Tier | Setup time | What you need |
|---|---|---|
| T1 | 30 min | Silicom PE-series NIC + Silicom SDK installed |
| T2 | 15 min | Mellanox ConnectX NIC (any model) |
| T3 | 5 min | Any dual-port NIC + lab DUT — for evaluation only |
Contact the TLSStress.Art team for the 30-day trial appliance.
References¶
- ADR 0036 — Authoritative design
- Module docs — Operator runbook
- Patent Family D draft