Patent · US Active

Methods and systems for API-level intrusion detection

US8990942B2 · kind B2 · utility

20Cited by
11References
29Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMay 14, 2013
Grant dateMar 24, 2015
Priority date
Expiry dateJul 9, 2033

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F21/554
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

This disclosure generally relates to computer security, and more particularly to methods and systems for application programming interface (API)-level intrusion detection. In some embodiments, a computer-readable medium is disclosed, storing instructions for: receiving an API call for a service at an API sandbox module; parsing the API call to extract at least one of: an API call name; and or one or more API call parameters; generating a copy of the at least one of: the API call name and or the one or more API call parameters; determining, via an intrusion detection rules execution engine, whether the API call violates one or more security rules obtained from a security rules object, using the copy of the at least one of: the API call name and or the one or more API call parameters; and providing an indication of whether the API call violates the one or more security rules.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.