API Risk Assessment via Content Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack effective methods to detect and defend against various types of attacks on computer systems, particularly those hosting cloud services, which remain vulnerable despite the availability of tools for HTML interface web applications, leading to potential significant consequential harm if compromised.

Innovation Solution

A method and equipment for API risk assessment that generate a risk assessment score based on comparisons of API transaction requests, controlling deliverability by identifying clusters of similar requests from source nodes, analyzing network addresses, geographic locations, and other information to determine the trustworthiness of transactions, using a non-linear analytical model such as a neural network to evaluate and mitigate risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security tools are applied only to HTML interface web applications, then detection and defense against web attacks is improved, but vulnerability to attacks on cloud service systems remains

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidapplicability to different system types
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extends security assessment capabilities from HTML interface web applications to API transaction requests, creating a universal security solution that applies to both web applications and cloud service systems. The system performs security assessments on API transactions regardless of the underlying application type, enabling consistent security protection across diverse system architectures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If comprehensive security assessments are performed on all API transactions, then detection of sophisticated attacks is improved, but processing overhead and system performance deteriorate

Engineering Contradiction:
Improveattack detection accuracyVSAvoidtransaction processing throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs security assessments in advance of transaction processing by evaluating API transaction requests before they reach the destination node. Risk assessment scores are generated preliminarily based on content comparison with earlier requests, allowing the destination node to make informed decisions about whether to process transactions without performing exhaustive checks on all transactions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies differentiated security assessment intensity based on risk levels. Instead of uniform comprehensive assessment, the system uses risk assessment scores to determine the level of scrutiny applied to each transaction, allowing lighter processing for low-risk transactions and more thorough assessment for high-risk transactions.

Inventive Principle:
Principle #3Local quality

3Reliability

If destination nodes perform extensive security checks on all incoming requests, then security protection is improved, but node resource consumption and processing delay increase

Engineering Contradiction:
Improvesystem security protectionVSAvoiddestination node resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by stationary object

Solution Approach 1:

The patent introduces an intermediary security assessment component that sits between the source node and the destination node. This intermediary performs the heavy lifting of security assessments and generates risk scores, which are then communicated to the destination node. This mediator approach protects the destination node from resource-intensive local security checks while maintaining strong security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9386078B2Controlling application programming interface transactions based on content of earlier transactions
Publication Date: 2016.07.05 CA TECH INC
  • US9386078B2 patent drawing
  • US9386078B2 patent drawing
  • US9386078B2 patent drawing

AI summary

Some aspects of the present disclosure operate an application programming interface (API) risk assessment equipment. An API transaction request is received from an application processed by a source node. A risk assessment score is generated based on comparison of content of the API transaction request to content of earlier API transaction requests. The risk assessment score indicates trustworthiness of the API transaction request. Deliverability of the API transaction request to a destination node for processing is controlled based on the risk assessment score.