Methods and systems for API-level intrusion detection
US8990942B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | May 14, 2013 |
| Grant date | Mar 24, 2015 |
| Priority date | — |
| Expiry date | Jul 9, 2033 |
Classification
- Technology area (CPC G)Physics
- CPC primaryG06F21/554
- WIPO fieldComputer technology
- WIPO sectorElectrical engineering
Abstract
This disclosure generally relates to computer security, and more particularly to methods and systems for application programming interface (API)-level intrusion detection. In some embodiments, a computer-readable medium is disclosed, storing instructions for: receiving an API call for a service at an API sandbox module; parsing the API call to extract at least one of: an API call name; and or one or more API call parameters; generating a copy of the at least one of: the API call name and or the one or more API call parameters; determining, via an intrusion detection rules execution engine, whether the API call violates one or more security rules obtained from a security rules object, using the copy of the at least one of: the API call name and or the one or more API call parameters; and providing an indication of whether the API call violates the one or more security rules.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.