API Proxy Adaptive Security for Real-Time Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing API security solutions face challenges in handling big data characteristics such as velocity, volume, and veracity, and are inadequate for real-time security threat detection at the server level, as they rely on receiving client requests before identifying potential threats, which can lead to server damage.

Innovation Solution

Implementing an API proxy-based system that extracts and analyzes API traffic, discards unauthorized messages, and uses a proxy cluster with security servers to identify indicators of compromise, generating metrics and anomalies, thereby enhancing API server security and data analytics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If server-level security analysis is implemented, then security threat detection capability is improved, but security threats may already damage the server before detection

Engineering Contradiction:
Improveserver securityVSAvoidthreat detection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements security analysis at the proxy level before requests reach the server. The proxy node performs API traffic monitoring, authentication, and security threat detection in advance, blocking malicious requests before they can damage the server. This preliminary security enforcement resolves the contradiction by detecting threats early in the request flow without requiring server-level analysis.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If API traffic monitoring is performed at the server level, then security detection accuracy is improved, but server processing load and response time worsen

Engineering Contradiction:
Improvesecurity detection accuracyVSAvoidserver processing throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent segments the security analysis function from the server by implementing it at the proxy level. The proxy node handles API traffic monitoring, authentication, and security detection, while the server focuses on processing legitimate requests. This segmentation maintains high detection accuracy through dedicated security processing while preserving server throughput by offloading security responsibilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The proxy node acts as an intermediary between clients and servers, performing security analysis on API traffic before forwarding legitimate requests to the server. This intermediary role enables comprehensive security monitoring without burdening the server, as the proxy filters and validates traffic in advance, maintaining both detection accuracy and server productivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If comprehensive API traffic analysis is implemented, then data analytics reliability is improved, but processing velocity and volume handling capability worsen

Engineering Contradiction:
Improvedata analytics reliabilityVSAvoidtraffic processing velocity
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The proxy node performs preliminary API traffic analysis and filtering before requests reach the server. By conducting authentication, validation, and security checks in advance, the system ensures reliable data analytics on legitimate traffic while maintaining processing velocity through efficient pre-filtering that blocks malicious or invalid requests early in the flow.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11641343B2Methods and systems for API proxy based adaptive security
Publication Date: 2023.05.02 PING IDENTITY CORP
  • US11641343B2 patent drawing
  • US11641343B2 patent drawing
  • US11641343B2 patent drawing

AI summary

The invention concerns API proxy based adaptive security. The invention implements adaptive security for API servers, while avoiding data bottlenecks and maintaining client experience. The invention provides methods and configurations for API security that may be employed at proxies for implementing routing decisions involving client messages received at said proxies. The invention also involves generating or collecting at proxies, log information that captures data corresponding to received client messages and responses from API servers—which log information correlates communications between clients, proxies and backend API servers, and includes data relevant for purposes generating API metrics and identifying anomalies and/or indicators of compromise. The invention yet further provides security server clusters configured for generating API metrics and/or identify anomalies or indicators of compromise—which may be used by proxies to terminate existing connections and block subsequent requests or messages from clients associated with the identified anomalies or indicators of compromise.