Self-adaptive API Security Microscope for Cloud Visibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security monitors are inadequate in providing fine-grained security control at the API level, struggling to keep pace with changing application APIs and are ineffective in monitoring inter-instance communications in modern enterprise application architectures, especially in cloud environments, where they lack visibility and flexibility.

Innovation Solution

The application security microscope captures and classifies API call data in real-time without prior knowledge of the API, using a data receptor component to access transaction data and a data processor component to perform classification and security control functions, enabling continuous updating of API specifications for precise security monitoring and policy implementation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional network security monitors use predefined rules and protocol specifications, then basic standard protocols can be monitored, but they cannot keep pace with changing application APIs and sophisticated hacking attempts

Engineering Contradiction:
Improveadaptability to changing APIsVSAvoidsecurity monitoring effectiveness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system dynamically adapts to changing APIs by automatically learning and updating API specifications in real-time. The API classification module continuously monitors API calls and updates the API specification database without requiring manual intervention, allowing the security monitor to keep pace with evolving application interfaces while maintaining reliable security monitoring through automated adaptation mechanisms

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The security monitoring system performs self-updating by automatically classifying and learning new API specifications from observed traffic. The API classification module autonomously updates the API specification database based on learned patterns, enabling the system to adapt to changing APIs without external assistance while maintaining security effectiveness through self-improving classification accuracy

Inventive Principle:
Principle #25Self-service

2Measurement precision

If API security tools are built into the application code, then full access to application data is achieved, but deployment becomes unwieldy and developer flexibility is limited

Engineering Contradiction:
Improvevisibility at API levelVSAvoiddeployment complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system separates security monitoring functionality from application code by deploying an external API security monitor that independently classifies and monitors API calls. This segmentation allows the monitor to achieve full visibility at the API level without requiring integration into application code, thereby reducing deployment complexity while maintaining precise API-level monitoring capabilities

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The API classification module acts as an intermediary between network traffic and security analysis, automatically learning and classifying API specifications without requiring application code modification. This intermediary approach provides full API-level visibility while keeping deployment simple, as the classifier operates independently in the network path rather than embedded in application code

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If system administrators manually analyze application transactions to classify APIs, then accurate classification can be achieved, but the process is time-consuming and cannot keep pace with frequent application updates

Engineering Contradiction:
ImproveAPI classification accuracyVSAvoidclassification time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The API classification module autonomously performs classification by automatically learning API specifications from observed traffic patterns. This self-service approach eliminates the need for manual administrator intervention, achieving both high classification accuracy through machine learning and rapid adaptation to frequent application updates without time-consuming manual analysis

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces manual mechanical classification processes with automated machine learning-based API classification. The API classification module uses automated pattern recognition and learning algorithms to achieve accurate API classification instantly, substituting the slow manual analysis process with rapid automated classification that keeps pace with frequent application updates

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Ease of operation

If conventional network security monitors are used in cloud environments, then basic network security can be provided, but fine-grained security control at API level and visibility in inter-instance communications are lacking

Engineering Contradiction:
Improvesecurity control granularityVSAvoidvisibility in cloud environment
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The system adds a new dimension of API-level classification and monitoring capability to traditional network security. By introducing automated API specification learning and classification, the monitor achieves fine-grained security control at the API level while maintaining full visibility in cloud environments, effectively adding functional dimensionality to conventional network security monitoring

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10795992B2Self-adaptive application programming interface level security monitoring
Publication Date: 2020.10.06 ARECABAY INC
  • US10795992B2 patent drawing
  • US10795992B2 patent drawing
  • US10795992B2 patent drawing

AI summary

Systems and methods for providing visibility in application transactions between users and an application. In some embodiments, an application security microscope is deployed at network locations to capture and analyze application transaction data and to identify API call data. The application security microscope includes an API classifier to classify captured API call data. The API classifier generates API specifications which are then used to aid in the capture and identification of API call data in the application transaction data, thereby improving the capture efficiency and accuracy of policy actions.