Skip to content

HyperBridge.Art — Inline DUT Validation Tap

One-page datasheet for customer trials. Plain-English, no acronym soup. Hand to network engineers, security architects, and procurement.

What it is

A 1U commodity appliance that slots inline between an upstream device and a Next-Generation Firewall (NGFW / IDS / IPS / TLS-inspecting middlebox), transparently forwards every packet at wire rate, and simultaneously feeds the full TLSStress.Art 6-pillar inspection-effectiveness validation framework — without requiring you to configure a single SPAN session on your switch.

Why it matters

Today, measuring whether your TLS-decrypting middlebox is actually doing what it claims requires a switch SPAN port. That requirement excludes:

  • SMB / managed-services customers running prosumer switches without SPAN
  • Enterprise data centers with every SPAN slot already taken by SIEM / DLP
  • Regulated environments (finance, gov, health) under change-control lock
  • 30-day proof-of-value trials that can't disrupt production switch config

HyperBridge.Art removes the SPAN dependency. Drop the appliance in the cable path; everything else just works.

Hardware tiers — pick your envelope

Tier NIC Failover on service crash Throughput Cost target Production-ready
T1 production HW-FTW Silicom PE-series / Napatech / Endace Hardware relay, 5–50 ms up to 100 Gbps $1k–$15k
T2 software FTW Mellanox ConnectX / Intel Kernel bridge, 200 ms–1 s up to 100 Gbps $400–$2k ✅ (non-critical paths)
T3 lab / test-bench Any dual-port NIC None — link drops up to 10 Gbps $50–$500 ❌ lab only

T3 must NOT be deployed in production. The orchestrator hard-stops if the configured tier does not match the loaded driver — your operations team cannot accidentally degrade.

How it slots in

   Upstream switch / router                         DUT (NGFW / IDS / IPS)
              │                                              ▲
              ▼                                              │
       ┌────────────────────────────────────────────────────┐
       │  HyperBridge.Art appliance                          │
       │  ─ NIC port A ←── HW bypass relay ──→ NIC port B ─  │
       │              │                       │              │
       │              └──── packet copy ──────┘              │
       │                          ▼                          │
       │              SPAN-1 / 6-pillar framework            │
       └─────────────────────────────────────────────────────┘

The packet copy stream is bit-identical to a switch-SPAN-fed deployment. You can run a mixed deployment (some flows via SPAN, some via HyperBridge) with a single instance of the 6-pillar framework consuming both.

What it delivers

  • Per-flow inspection-effectiveness verdicts — pass / fail / inconclusive per DUT inspection feature (TLS decryption, signature matching, app-ID, malware scanning)
  • Fast-path detection — flags when the DUT is silently dropping inspection on fast-path / flow-offload traffic
  • Decryption coverage — measures the fraction of TLS sessions the DUT is actually decrypting, broken down by certificate issuer
  • Wire-versus-syslog cross-correlation — flags per-flow disagreements between what hit the wire and what the DUT logged
  • Bypass-event tamper-evident timeline — every fail-to-wire engagement / recovery written to a SHA-256 hash chain; dashboard surfaces a verifier button

Deployment posture

  • Bare metal: 2 systemd services (hyperbridge-orchestrator + hyperbridge-watchdog); shipped as a small Docker image
  • Kubernetes: DaemonSet pinned to the node with the bypass NIC via hyperbridge.art/tier=<T1|T2|T3> label
  • Observability: Prometheus /metrics on both binaries; /status JSON for dashboards
  • Audit: bypass-event JSONL → sealed audit hash-chain (ADR 0029)

Operator UI

  • /admin/hyperbridge-art — config + live status; pick driver vendor at runtime
  • /admin/hyperbridge-art/bypass-history — tamper-evident timeline of every bypass engagement, filtered by tier / vendor / reason, with a chain-verify button

What we don't claim

  • Not a replacement for HW firewalls — HyperBridge.Art measures the firewall, it doesn't perform inspection
  • Not a packet broker (Gigamon, Ixia) — single inline path, not a many-to-many fan-out
  • Ultra-low-latency workloads (HFT, RDMA, voice/video) — measured per-packet added latency is 2–5 µs on T1, 10–50 µs on T2; fitness envelope is documented per tier

Patent posture

Patent Family D — Inline DUT Validation Tap via Bypass-Capable NIC with Integrated Effectiveness Measurement — provisional filing target 2026-Q4. The novel combination is the inline tap + the 6-pillar effectiveness framework (Families A, B, C). Hardware bypass primitives are well-trodden prior art; the combination is what's new.

Get started

Tier Setup time What you need
T1 30 min Silicom PE-series NIC + Silicom SDK installed
T2 15 min Mellanox ConnectX NIC (any model)
T3 5 min Any dual-port NIC + lab DUT — for evaluation only

Contact the TLSStress.Art team for the 30-day trial appliance.

References