IP Library Granted Patent US 12,307,361
Granted Patent B2
US 12,307,361 · App. 17/349,942 · Granted May 20, 2025

Detecting threats based on API service business logic abuse

Inventors: Ravindra Guntar (Hyderabad, IN); Ranaji Krishna (Berkeley, CA)
Assignee: Traceable Inc
G06N3/08G06F9/541G06F9/543G06F9/547G06F16/9027G06F16/9566G06F21/552G06N3/04H04L63/1425H04L67/133G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,307,361
App. No.
17/349,942
Granted
May 20, 2025
Kind
B2
Abstract

Behaviors in the form of API strings for each of a plurality of users are determined for each user interacting with an API for a particular time. The behavior strings are converted to a numerical format, and clustering algorithms are applied to the numerical format data. The type of cluster is then determined for each cluster. Types of clusters can include an attacking user, bots, speed of access, and outlier type. The results of clustering and a statistical analysis can be reported to a user through a dashboard. The dashboard may provide graphical information, for example in the form of a sankey diagram, as well as statistical analysis data for each cluster.

Claims (36)

1. A method for automatically detecting service attackers based on application program interface (API) service business logic analysis, comprising:

determining a total behavior as a total sequence of API activity for a plurality of users accessing a network service over a period of time;

determining a plurality of micro-behavior strings for each user, wherein each micro-behavior includes a subset of the user's total behavior;

converting each micro-behavior sting to a numerical vector using a minhash;

associating each numerical vector with metadata including a session the vector occurred, IP address, and API name;

attaching a user identifier to each numerical vector;

clustering the numerical vector behaviors in clusters which match a similarity threshold and merge the metadata associated with each numerical vector for clustered vectors, wherein each numerical vector behavior is associated with a user ID associated with the user that performed the sequence of API activity for a particular behavior;

determining a type of each cluster, wherein determining the type of cluster includes categorizing a cluster as associated with an attack, a bot, speed of access, and an anomaly; and

reporting the cluster type.

2. The method of claim 1 , wherein the micro-behaviors are determined with a moving window.

3. The method of claim 1 , wherein the clustering includes generating a graph with distances between each numerical vector, wherein nodes are clustered together when contents of the node satisfy a threshold.

4. The method of claim 3 , wherein the threshold is satisfied by a distance between neighboring nodes.

5. The method of claim 1 , wherein determining a cluster as an attack or a bot includes partitioning the cluster into at least two partitions, maintaining the cluster type for at least one partitions, and identifying the remaining cluster as a normal cluster.

6. A non-transitory computer readable storage medium having embodied thereon a program, the program being executable by a processor to perform a method for automatically detecting service attackers based on application program interface (API) service business logic analysis, the method comprising:

determining a total behavior as a total sequence of API activity for a plurality of users accessing a network service over a period of time;

determining a plurality of micro-behavior strings for each user, wherein each micro-behavior includes a subset of the user's total behavior;

converting each micro-behavior sting to a numerical vector using a minhash; associating each numerical vector with metadata including a session the vector

occurred, IP address, and API name;

attaching a user identifier to each numerical vector;

clustering the numerical vector behaviors in clusters which match a similarity threshold and merge the metadata associated with each numerical vector for clustered vectors,

wherein each numerical vector behavior is associated with a user ID associated with the user that performed the sequence of API activity for a particular behavior;

determining a type of each cluster, wherein determining the type of cluster includes categorizing a cluster as associated with an attack, a bot, speed of access, and an anomaly; and

reporting the cluster type.

7. The non-transitory computer readable storage medium of claim 6 , wherein the micro-behaviors are determined with a moving window.

8. The non-transitory computer readable storage medium of claim 6 , wherein the clustering includes generating a graph with distances between each numerical vector, wherein nodes are clustered together when contents of the node satisfy a threshold.

9. The non-transitory computer readable storage medium of claim 8 , wherein the threshold is satisfied by a distance between neighboring nodes.

10. The non-transitory computer readable storage medium of claim 6 , wherein determining a cluster as an attack or a bot includes partitioning the cluster into at least two partitions, maintaining the cluster type for at least one partitions, and identifying the remaining cluster as a normal cluster.

11. A system for automatically detecting service attackers based on application program interface (API) service business logic analysis, comprising:

a server including a memory and a processor; and

one or more modules stored in the memory and executed by the processor to determine a total behavior as a total sequence of API activity for a plurality of users accessing a network service over a period of time,

determine a plurality of micro-behavior strings for each user, wherein each micro-behavior includes a subset of the user's total behavior,

convert each micro-behavior sting to a numerical vector using a minhash,

associate each numerical vector with metadata including a session the vector occurred, IP address, and API name, attaching a user identifier to each numerical vector,

cluster the numerical vector behaviors in clusters which match a similarity threshold and merge the metadata associated with each numerical vector for clustered vectors,

wherein each numerical vector behavior is associated with a user ID associated with the user that performed the sequence of API activity for a particular behavior,

determine a type of each cluster, wherein determining the type of cluster includes categorizing a cluster as associated with an attack, a bot, speed of access, and an anomaly, and report the cluster type.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Aug 18, 2026
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK & TRUST COMPANY
To: HARNESS INC.; HARNESS INTERNATIONAL, INC.
Reel/Frame 075689/0062 →
RELEASE OF SECURITY INTEREST Recorded Aug 18, 2026
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK & TRUST COMPANY, AS AGENT
To: HARNESS INC.; HARNESS INTERNATIONAL, INC.
Reel/Frame 075689/0281 →
SECURITY INTEREST Recorded Mar 31, 2026
From: HARNESS INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 074240/0665 →
SECURITY INTEREST Recorded Mar 31, 2026
From: HARNESS INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY, AS AGENT
Reel/Frame 074240/0707 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2025
From: TRACEABLE INC.
To: HARNESS INC.
Reel/Frame 071911/0025 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2023
From: GUNTUR, RAVINDRA; KRISHNA, RANAJI
To: TRACEABLE INC.
Reel/Frame 064757/0374 →
Continuity (2)
Provisional Application 63167649 · Mar 30, 2021
Related Publication 20220318378A1 · Oct 6, 2022
References Cited (23)
US 6226408B1 · Sirosh · 2001 [cited by examiner]
US 7058633B1 · Gnagy et al. · 2006 [cited by applicant]
US 9215212B2 · Reddy et al. · 2015 [cited by applicant]
US 9516053B1 · Muddu · 2016 [cited by examiner]
US 9667704B1 · Sonawane · 2017 [cited by applicant]
US 10747505B1 · Lester et al. · 2020 [cited by applicant]
US 10764041B2 · Saxena · 2020 [cited by examiner]
US 10873618B1 · Mittal et al. · 2020 [cited by applicant]
US 10917401B1 · Mantin et al. · 2021 [cited by applicant]
US 20070250624A1 · Wexler et al. · 2007 [cited by applicant]
US 20080034424A1 · Overcash et al. · 2008 [cited by applicant]
US 20080184340A1 · Nakamura et al. · 2008 [cited by applicant]
US 20100235918A1 · Mizrahi et al. · 2010 [cited by applicant]
US 20100325588A1 · Reddy et al. · 2010 [cited by applicant]
US 20110145930A1 · Gnech et al. · 2011 [cited by applicant]
US 20150180745A1 · Horn et al. · 2015 [cited by applicant]
US 20160057107A1 · Call et al. · 2016 [cited by applicant]
US 20160099963A1 · Mahaffey · 2016 [cited by examiner]
US 20180196643A1 · Dolby et al. · 2018 [cited by applicant]
US 20200286112A1 · Zhou · 2020 [cited by examiner]
US 20210211486A1 · Mittal et al. · 2021 [cited by applicant]
WO WO2017151515A1 · 2017 [cited by examiner]
Mingxin Wang, A Moving Window Principal Components Analysis Based Anomaly Detection and Mitigation Approach in SDN Network, Aug. 31, 2018, National Laboratory of Next Generation Internet Interconnection Devices, 3951-39… [cited by examiner]