Automated API Security Assessment System with Risk Profiling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current API security assessment methods are inefficient, inaccurate, and not scalable, requiring multiple approaches that lead to low confidence remediation and are time-consuming, prone to errors, and complex, necessitating a holistic and automated system for comprehensive security analysis.

Innovation Solution

An API assessment system utilizing a processor, data corpus builder, data classifier, risk profiler, and data rectifier with cognitive learning operations to create a sequence classification model, risk profile, and rectification model for real-time security assessment and remediation, enabling automated detection and mitigation of security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple API security assessment approaches are deployed, then coverage of security concerns is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity assessment effectivenessVSAvoidassessment system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple API security assessment approaches (penetration testing, design document review, source code analysis, and runtime monitoring) into a single unified platform that orchestrates all these methods through a common architecture, reducing overall system complexity while maintaining comprehensive security coverage

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The assessment platform is designed as a universal system that can perform multiple security assessment functions (static analysis, dynamic analysis, penetration testing, and monitoring) through a single integrated architecture, eliminating the need for separate complex systems for each assessment type

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If traditional API security assessment methods are used, then security issues can be detected, but assessment time and resource consumption increase

Engineering Contradiction:
Improvesecurity issue detection accuracyVSAvoidassessment time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary static analysis and source code review during the API development phase before deployment, enabling early detection of security issues without requiring time-consuming penetration testing and monitoring in production environments

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual security assessment processes (human code review, manual penetration testing) with automated computational analysis systems that can rapidly analyze API code and behavior, significantly reducing assessment time while maintaining or improving detection accuracy

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If API security assessment is performed manually, then detailed analysis can be conducted, but error rate increases and scalability decreases

Engineering Contradiction:
Improvesecurity analysis accuracyVSAvoidassessment scalability
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The assessment platform incorporates automated self-correction capabilities where the system can automatically remediate certain security issues without human intervention, and automatically learn from assessment results to improve future analyses, enabling scalable operation without proportional increases in human resources

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces manual security analysis with automated computational methods including static code analysis, dynamic runtime monitoring, and machine learning-based threat detection that can process large numbers of APIs simultaneously without human error and with consistent accuracy

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Ease of manufacture

If security assessment is performed late in the development cycle, then fewer changes are needed, but remediation complexity increases

Engineering Contradiction:
Improveremediation easeVSAvoidtime to remediation
Core Design Contradiction:
Ease of manufactureVSLoss of time

Solution Approach 1:

The system performs security assessments during the API design and development phases before deployment to production, enabling security issues to be identified and remediated early when changes are simplest and most cost-effective

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The assessment platform provides continuous feedback to developers during the API creation process, enabling real-time correction of security issues as they are introduced, rather than requiring complex remediation after deployment

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10740164B1Application programming interface assessment
Publication Date: 2020.08.11 ACCENTURE GLOBAL SOLUTIONS LTD
  • US10740164B1 patent drawing
  • US10740164B1 patent drawing
  • US10740164B1 patent drawing

AI summary

Examples of an API assessment system are provided. The system may obtain a security assessment requirement from a user for surveillance of a plurality of application programming interfaces. The system may create a data corpus from the assessment data associated with the query. The system may create a sequence classification model from the data corpus. The system may identify a plurality of risk parameters and a plurality of risk mapping levels associated with the query. The system may create a risk profile for the plurality of application programming interfaces based on mapping the plurality of risk parameters to the plurality of risk mapping levels and the sequence classification model. The system may create a rectification corpus and a data rectification model comprising a plurality of remediations for automated healing of a risk identified by the risk profile. The system may generate a security assessment result for the resolution of the query.