API Endpoint Exposure Detection Behind Gateways and Proxies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The lack of visibility in detecting API endpoints due to their dynamic nature and obstruction by API gateways and proxies, which hinder effective cybersecurity threat detection and data protection.
Innovation Solution
A system and method for detecting API endpoints in a cloud computing environment using a combination of runtime data analysis and static inspection, involving sensors to collect API call data, generate network access instructions, and execute these instructions to verify exposed endpoints, allowing for precise and accurate detection and mitigation actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If API gateways and proxies are used to manage network traffic, then network traffic management and routing are improved, but visibility and detection of actual API endpoints deteriorate
Solution Approach 1:
The patent introduces sensors as intermediary components deployed within the cloud computing environment that act as detectors between the API gateways/proxies and the actual API endpoints. These sensors capture runtime data and enable indirect detection of endpoints that are otherwise hidden behind the gateway layer, resolving the visibility problem while maintaining the traffic management benefits of gateways
Solution Approach 2:
The patent shifts the detection approach from direct network traffic analysis at the gateway level to runtime data collection from multiple dimensions including application logs, system calls, and sensor data from within the cloud environment. This multi-dimensional approach allows endpoint detection through alternative pathways that bypass the obstruction caused by API gateways
2Measurement precision
If sensors and runtime data analysis are used to detect API endpoints, then detection precision is improved, but system complexity and resource consumption increase
Solution Approach 1:
The patent designs sensors with multi-functional capabilities that simultaneously perform multiple tasks: collecting runtime data, detecting API endpoints, monitoring network traffic patterns, and gathering information about exposed endpoints. This consolidation of multiple detection functions into single sensor units reduces overall system complexity while maintaining high detection precision through diverse data collection
Data Source
AI summary
A system and method for initiating a mitigation action for an exposed Application Programming Interface (API) endpoint in a cloud computing environment is presented. The method includes detecting an API endpoint of a plurality of API endpoints in a cloud computing environment; executing a network access instruction on the API endpoint, wherein the network access instruction is provided over at least an external network; determining that the API endpoint is an exposed API endpoint in response to receiving a predetermined result of executing the network access instruction; initiating a mitigation action in response to the detection of the exposed API endpoint.


