System and method for identifying and preventing malicious api attacks
Abstract
A system and method for identifying and preventing malicious application programming interface attacks is configured to, during a learning stage: monitor all requests sent to and from the server API; identify one or more first characteristic data points of each request and response sent during the learning stage; and determine, based at least in part on the identified one or more first characteristic data points, one or more characteristic data models, wherein a characteristic data model represents at least one of an expected input to the API and an expected output of the API; and during a protection stage: monitor all requests sent to and from the server API; identify one or more second characteristic data points of each request and response sent during the protection stage; and one of validate and invalidate the identified one or more second characteristic data points against the one or more characteristic data models.
Claims
exact text as granted — not AI-modified1 . A method for identifying and preventing malicious application programming interface (API) attacks in a client-server architecture, performed on a computer having a processor, a memory, and one or more code sets stored in the memory and executed by the processor, the method comprising:
during a learning stage:
monitoring, by the processor, all requests sent to a server API and all responses sent from the server API;
identifying, by the processor, one or more first characteristic data points of each request and response sent during the learning stage; and
determining, by the processor, based at least in part on the identified one or more first characteristic data points, one or more characteristic data models, wherein a characteristic data model represents at least one of an expected input to the API and an expected output of the API; and
during a protection stage:
monitoring, by the processor, all requests sent to the server API and all responses sent from the server API;
identifying, by the processor, one or more second characteristic data points of each request and response sent during the protection stage; and
one of validating and invalidating, by the processor, the identified one or more second characteristic data points against the one or more characteristic data models.
2 . The method as in claim 1 , further comprising:
passing to the server, by the processor, requests having no invalidated one or more second characteristic data points; and passing from the server, by the processor, responses having no invalidated one or more second characteristic data points.
3 . The method as in claim 1 , further comprising:
blocking to the server, by the processor, requests having invalidated one or more second characteristic data points; and blocking from the server, by the processor, responses having invalidated one or more second characteristic data points.
4 . The method as in claim 1 , further comprising:
generating, by the processor, an alert for each request having invalidated one or more second characteristic data points; and generating, by the processor, and alert for each response having invalidated one or more second characteristic data points.
5 . The method as in claim 4 , further comprising:
generating, by the processor, an alert timeline, wherein the alert timeline represents a selection of one or more aggregations of alerts, the alerts in each of the one or more aggregations having a predefined similarity, the one or more aggregations being organized in a predefined order; and displaying, by the processor, the alert timeline on a visual display.
6 . The method as in claim 1 , further comprising:
generating, by the processor, one or more attacker profiles based at least in part on the validating step; determining, by the processor, one or more suspicion scores for each attacker profile; and identifying, by the processor, one or more suspicious profiles based at least in part on respective suspicion scores, wherein all future requests and responses related to an identified suspicious profile are flagged with an alert irrespective of validity.
7 . The method of claim 1 , further comprising: updating, by the processor, the one or more characteristic data models based at least in part on the identified one or more second characteristic data points of each request and response sent during the protection stage.
8 . The method as in claim 1 , wherein the server API is one of a RESTful API, a SOAP API, an XML-RPC API, and a WSDL API.
9 . The method as in claim 1 , further comprising generating, by the processor, documentation comprising information reflecting a complete structure of the server API.
10 . A system for identifying and preventing malicious application programming interface (API) attacks in a client-server architecture, comprising:
a computer having a processor and a memory; and one or more code sets stored in the memory and executed by the processor, which configure the processor to: during a learning stage:
monitor all requests sent to a server API and all responses sent from the server API;
identify one or more first characteristic data points of each request and response sent during the learning stage; and
determine based at least in part on the identified one or more first characteristic data points, one or more characteristic data models, wherein a characteristic data model represents at least one of an expected input to the API and an expected output of the API; and
during a protection stage:
monitor all requests sent to the server API and all responses sent from the server API;
identify one or more second characteristic data points of each request and response sent during the protection stage; and
one of validate and invalidate the identified one or more second characteristic data points against the one or more characteristic data models.
11 . The system as in claim 10 , the processor further configured to:
pass to the server requests having no invalidated one or more second characteristic data points; and pass from the server responses having no invalidated one or more second characteristic data points.
12 . The system as in claim 10 , the processor further configured to:
block to the server requests having invalidated one or more second characteristic data points; and block from the server responses having invalidated one or more second characteristic data points.
13 . The system as in claim 10 , the processor further configured to:
generate an alert for each request having invalidated one or more second characteristic data points; and generate and alert for each response having invalidated one or more second characteristic data points.
14 . The system as in claim 13 , the processor further configured to:
generate an alert timeline, wherein the alert timeline represents a selection of one or more aggregations of alerts, the alerts in each of the one or more aggregations having a predefined similarity, the one or more aggregations being organized in a predefined order; and display the alert timeline on a visual display.
15 . The system as in claim 10 , the processor further configured to:
generate one or more attacker profiles based at least in part on the validating step; determine one or more suspicion scores for each attacker profile; and identify one or more suspicious profiles based at least in part on respective suspicion scores, wherein all future requests and responses related to an identified suspicious profile are flagged with an alert irrespective of validity.
16 . The system as in claim 10 , the processor further configured to: update the one or more characteristic data models based at least in part on the identified one or more second characteristic data points of each request and response sent during the protection stage.
17 . The system as in claim 10 , wherein the server API is one of a RESTful API, a SOAP API, an XML-RPC API, and a WSDL API.
18 . The system as in claim 10 , the processor further configured to generate documentation comprising information reflecting a complete structure of the server API.Join the waitlist — get patent alerts
Track US2018324208A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.