Dynamic API Transaction Aggregation for Real-Time Security Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

API security systems do not efficiently leverage their distributed streaming platforms to inhibit unwanted API behavior, and they fail to effectively aggregate and track API behavior logged by these platforms based on user-defined parameters.

Innovation Solution

A method and system for aggregating transactions logged by a distributed streaming platform, involving the extraction of named properties from API infrastructure transactions using identifiers, generation of data aggregation keys, and providing aggregation data to a security policy generation system, allowing for real-time security policy creation and enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If distributed streaming platforms are used to track API traffic, then the ability to monitor API transactions is improved, but the efficiency of leveraging this data to inhibit unwanted behavior deteriorates

Engineering Contradiction:
ImproveAPI transaction tracking capabilityVSAvoidEfficiency in inhibiting unwanted behavior
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts specific properties from API transaction data that are relevant to security policy enforcement. Rather than processing all transaction data, the system identifies and extracts only the necessary properties (such as API endpoint, authentication tokens, request parameters) that are needed for security analysis, thereby improving processing efficiency while maintaining reliable tracking capability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system transforms raw transaction data into aggregated security metrics by changing the parameters of data representation. Transactions are aggregated based on extracted properties to create meaningful security indicators, transforming voluminous raw data into concise security-relevant parameters that enable efficient unwanted behavior detection and inhibition

Inventive Principle:
Principle #35Parameter changes

2Loss of information

If distributed streaming platforms log all API transactions, then comprehensive tracking is improved, but the ability to effectively aggregate and track behavior based on user-defined parameters deteriorates

Engineering Contradiction:
ImproveComprehensiveness of transaction trackingVSAvoidEffectiveness of aggregation and tracking
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The system performs preliminary aggregation of transaction data as it streams through the platform, rather than waiting for complete data collection. By aggregating data in real-time based on user-defined parameters, the system maintains comprehensive tracking capability while improving the effectiveness of behavior analysis through timely aggregation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The aggregation parameters and groupings are made dynamic and adaptable to user-defined criteria. The system can dynamically adjust aggregation keys, time windows, and grouping criteria based on security requirements, enabling effective tracking and aggregation flexibility without compromising comprehensive transaction monitoring

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20260012488A1Near real time aggregation using dynamic data extraction
Publication Date: 2026.01.08 CEQUENCE SECURITY INC
  • US20260012488A1 patent drawing
  • US20260012488A1 patent drawing
  • US20260012488A1 patent drawing

AI summary

Various embodiments include a system to aggregate transactions logged by a distributed streaming platform. The system comprises processing circuitry. The processing circuitry obtains an identifier that indicates a data item associated with an API infrastructure. The processing circuitry processes the transactions of the API infrastructure logged by the distributed streaming platform to extract a named property from the transactions based on the identifier. The processing circuitry generates a data aggregation key based on the extracted named property. The processing circuitry aggregates the transactions based on the data aggregation key. The processing circuitry provides aggregation data that characterizes the aggregated transactions to a security policy generation system.