Continuous API Security Auditing via Trust Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods fail to effectively detect and protect against API attacks such as injection attacks, denial of service attacks, and man in the middle attacks, as they do not adequately monitor and ensure the security compliance of API usage relationships between API users and providers.

Innovation Solution

A computer-implemented method that establishes a connection between API users and providers, continuously monitors connection security and trustworthiness, generates scores for security and trustworthiness factors, and performs actions based on risk levels to mitigate potential API attacks by employing a system that includes connection security assessors, trustworthiness assessors, and risk analyzers to enforce security compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional API security methods are used, then basic authentication is provided, but they fail to detect and protect against advanced API attacks such as injection attacks, denial of service attacks, and man in the middle attacks

Engineering Contradiction:
ImproveAPI security protection capabilityVSAvoidsecurity monitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security monitoring system is segmented into multiple specialized assessors: connection security assessors evaluate cryptographic implementation and protocol compliance, while trustworthiness assessors evaluate API user and provider behavior. This segmentation allows each component to focus on specific security aspects, improving detection capability without requiring a monolithic complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary security monitoring system that continuously audits API usage relationships between API users and providers. This intermediary layer generates scores for connection security and trustworthiness, enabling detection of attacks without requiring direct modification of the core API communication infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If continuous monitoring of connection security and trustworthiness is implemented, then real-time detection of API attacks is achieved, but the complexity of the security assessment system increases

Engineering Contradiction:
Improvesecurity compliance detection accuracyVSAvoidmonitoring system structure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system monitors changes in security parameters such as cryptographic implementation quality, protocol compliance, and behavioral patterns of API users and providers. By tracking parameter changes over time and comparing them against established thresholds, the system achieves precise detection of security violations without requiring overly complex monitoring infrastructure.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

Different parts of the system evaluate different aspects of security with specialized quality metrics: connection security assessors focus on cryptographic and protocol-level properties, while trustworthiness assessors focus on behavioral properties. This local quality approach allows each component to use simplified evaluation logic for its specific domain, reducing overall system complexity.

Inventive Principle:
Principle #3Local quality

3Reliability

If multiple assessors are used to evaluate connection security and trustworthiness, then comprehensive security coverage is achieved, but the computational overhead and system complexity increase

Engineering Contradiction:
Improvesecurity assessment comprehensivenessVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system uses multiple assessors to evaluate different aspects of security, but each assessor performs partial evaluation of its specific domain rather than complete evaluation of all security aspects. This partial action approach achieves comprehensive coverage through coordinated assessment while reducing the computational burden on each individual component.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

Connection security assessors evaluate cryptographic implementation and protocol compliance preliminarily before trustworthiness assessors evaluate behavioral patterns. This preliminary action allows the system to quickly filter out obviously secure or insecure connections, reducing the computational resources needed for more intensive behavioral analysis.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12028351B2Protecting against API attacks by continuous auditing of security compliance of API usage relationship
Publication Date: 2024.07.02 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12028351B2 patent drawing
  • US12028351B2 patent drawing
  • US12028351B2 patent drawing

AI summary

A computer-implemented method, system and computer program product for protecting against application programming interface (API) attacks. A connection is established between an API user and an API provider. The established connection is then monitored to assess connection security and trustworthiness of the connection as well as trustworthiness of the API user and/or API provider. A score is then generated for each factor used in assessing the connection security and trustworthiness of the connection as well as the trustworthiness of the API user and/or API provider based on the monitoring. A level of risk for an API attack with respect to the API user and/or API provider is then generated based on such scores. An action (e.g., blocking traffic) is then performed with respect to the API user and/or API provider based on the level of risk for an API attack with respect to the API user and/or API provider, respectively.