Adaptive API Anomaly Detection via Machine Learning Baselines
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for detecting API abuse face challenges in adapting to new and constantly evolving threats, necessitating improved accuracy and flexibility in abnormality detection.
Innovation Solution
A method and system that utilize machine learning techniques to create a baseline for computing interface usage metrics, detect anomalies based on deviations from the baseline, and mitigate identified threats, allowing for adaptive threat detection and response.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional anomaly detection methods are used to detect API abuse, then the system can identify abnormal traffic patterns, but the system cannot adapt to new and constantly evolving threats
Solution Approach 1:
The patent implements dynamic adaptation by continuously updating the baseline computing interface behavior through machine learning models. The system learns from new traffic patterns and evolves its detection capabilities over time, allowing it to adapt to emerging threats while maintaining reliable detection through probabilistic anomaly scoring based on deviations from the learned baseline
Solution Approach 2:
The system performs self-learning by automatically training machine learning models on incoming traffic data to establish and update baselines for normal computing interface behavior. This self-service capability enables the system to improve its own detection accuracy without external intervention, adapting to new threats while maintaining reliable detection through continuous learning
2Measurement precision
If machine learning models are trained on historical data to establish baselines, then detection accuracy improves, but the system complexity increases
Solution Approach 1:
The patent replaces complex rule-based detection mechanisms with machine learning models that automatically learn patterns from data. The ML models substitute for manual threshold setting and complex detection logic, achieving high detection accuracy while managing system complexity through automated learning rather than manual configuration
Solution Approach 2:
The system dynamically adjusts detection parameters by training models on historical data to establish baselines, then using probabilistic scoring to identify anomalies. The model parameters are updated continuously as new data arrives, allowing the system to maintain high detection accuracy while adapting to changing traffic patterns without manual intervention
Data Source
AI summary
A system and method for mitigating cyber threats based on excessive computing interface usage behaviors. A method includes creating a baseline with respect to at least one computing interface usage metric, wherein each computing interface usage metric is defined with respect to computing interface usage by a user, wherein creating the baseline further comprises training an anomaly detection machine learning model using a training set including a plurality of training values for the at least one computing interface metric; detecting an anomaly in calls made by the user based on at least one deviation from the baseline above a threshold, wherein detecting the anomaly further comprises applying the anomaly detection machine learning model to a plurality of features including values of the at least one computing interface usage metric for the calls made by the user; and mitigating the detected anomaly.


