Automated Cyber Security Monitoring for API Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Implementing and consistently enforcing industry-standard security best practices across an organization's APIs is challenging, especially in ensuring compliance and preventing future regressions, due to the complexity of learning and validating these standards across technology teams and individual developers.

Innovation Solution

An automated cyber security and control monitoring system that uses a cyber audit tool to receive API standards, identify expected controls, scan for API runtime control data, and generate reports on compliance, missing, and unexpected controls, with the ability to modify APIs by implementing missing controls through scripts or code.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If technology teams manually learn and implement security best practices, then they can understand the standards, but consistency across the organization deteriorates

Engineering Contradiction:
Improvesecurity standards complianceVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service by allowing the cyber audit tool to automatically retrieve API standards from sources like OWASP and NIST, extract expected controls, scan runtime data, and generate compliance reports without requiring manual intervention from technology teams. This automation maintains consistent security standards enforcement across the organization while reducing the complexity of manual implementation and validation processes.

Inventive Principle:
Principle #25Self-service

2Reliability

If security controls are manually validated, then compliance can be ensured, but time consumption increases

Engineering Contradiction:
Improvecompliance validationVSAvoidvalidation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The cyber audit tool performs continuous monitoring and validation of API security controls by automatically scanning runtime control data against expected controls from industry standards. This continuous automation ensures compliance validation is ongoing without interruption, eliminating the time-consuming manual validation process while maintaining reliable compliance assurance.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system generates feedback through automated compliance reports that identify missing or non-conforming security controls. These reports provide immediate feedback to technology teams about compliance status, enabling rapid corrective action without the time delays associated with manual validation processes.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If comprehensive security controls are implemented, then protection improves, but system complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidcontrol system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system extracts and isolates security control validation logic into a separate cyber audit tool that operates independently from the API systems being monitored. By extracting the auditing function, the patent reduces the complexity burden on the API systems themselves while maintaining comprehensive security protection through standardized controls from OWASP and NIST.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20220014545A1Systems and methods for automated cyber security and control monitoring
Publication Date: 2022.01.13 JPMORGAN CHASE BANK NA
  • US20220014545A1 patent drawing
  • US20220014545A1 patent drawing

AI summary

Systems and methods for automated cyber security and control monitoring are disclosed. In one embodiment, a method for automated cyber security and control monitoring may include: (1) receiving, by a cyber audit tool computer program executed by a computer processor, Application Programmable Interface (API) standards from a source; (2) identifying, by the cyber audit tool computer program, a plurality of expected API controls for the API standards; (3) receiving, by the cyber audit tool computer program, API runtime control data for an API; and (4) generating, by the cyber audit tool computer program, a report identifying expected API controls present in the API runtime control data, expected controls missing from the API runtime control data, and unexpected controls in the API runtime control data.