IP Library Granted Patent US 11,924,170
Granted Patent B2
US 11,924,170 · App. 17/375,695 · Granted Mar 5, 2024

Methods and systems for API deception environment and API traffic control and security

Inventors: Udayakumar Subbarayan (Bangalore, IN); Bernard Harguindeguy (Atherton, CA); Anoop Krishnan Gopalakrishnan (Bangalore, IN); Nagabhushana Angadi (Bengaluru, IN); Ashwani Kumar (Bengaluru, IN); Santosh Sahu (Bangalore, IN); Abdu Raheem Poonthiruthi (Bangalore, IN); Avinash Kumar Sahu (Bangalore, IN); Yasar Kundottil (Bangalore, IN)
Assignee: Ping Identity Corporation
H04L63/0281G06F21/55G06F21/554G06F21/6281G06N20/00H04L63/02H04L63/04H04L63/0807H04L63/0876H04L63/1425H04L63/1458H04L63/1491
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,924,170
App. No.
17/375,695
Granted
Mar 5, 2024
Kind
B2
Abstract

The present invention relates to the field of networking and API/application security. In particular, the invention is directed towards methods, systems and computer program products for Application Programming Interface (API) based flow control and API based security at the application layer of the networking protocol stack. The invention additionally provides an API deception environment to protect a server backend from threats, attacks and unauthorized access.

Claims (24)

1. A method, comprising:

receiving, at a proxy and from a client device, a client message intended for a server backend;

identifying a target application programming interface (API) from the client message;

in response to identifying that the target API is not hosted by the server backend, dynamically generating a decoy API associated with the target API; and

in response to identifying that the target API is not hosted by the server backend, routing the client message via the decoy API such that network communication is initiated with the client device via the decoy API.

2. The method of claim 1 , further comprising:

recording information associated with the network communication with the client device.

3. The method of claim 1 , wherein the decoy API and the target API have identical names.

4. The method of claim 1 , wherein the decoy API emulates the target API and precludes access to the server backend.

5. The method of claim 1 , wherein the decoy API is configured to identify an attack pattern associated with the client device and store an indication of the attack pattern in a library of attack patterns.

6. The method of claim 1 , further comprising:

in response to identifying that the target API is hosted by the server backend, routing the client message to the server backend.

7. An apparatus, comprising:

a memory; and

a processor of a proxy operatively coupled to the memory, the processor configured to:

receive, from a client device, a client message intended for a server backend;

identify a target application programming interface (API) from the client message;

identify the target API as a decoy API; and

in response to identifying the target API as the decoy API, route the client message via the decoy API such that network communication is initiated with the client device via the decoy API.

8. The apparatus of claim 7 , wherein the processor is configured to record information associated with the network communication with the client device.

9. The apparatus of claim 7 , wherein the target API and the decoy API have identical names.

10. The apparatus of claim 7 , wherein the decoy API emulates the target API and precludes access to the server backend.

11. The apparatus of claim 7 , wherein the decoy API is one of an out-of-context API or an in-context API.

12. The apparatus of claim 7 , wherein the routing the client message via the decoy API is at a first time, the processor configured to discard a subsequent client message from the client device at a second time after the first time without sending the client message to the server backend.

Assignments (6)
RELEASE OF SECURITY INTEREST AT R/F 61703/0988 Recorded Nov 14, 2025
From: BLUE OWL CAPITAL CORPORATION
To: PING IDENTITY CORPORATION
Reel/Frame 073570/0777 →
SECURITY INTEREST Recorded Nov 13, 2025
From: PING IDENTITY CORPORATION; PING IDENTITY INTERNATIONAL, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 073557/0093 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Oct 18, 2022
From: PING IDENTITY CORPORATION
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 061703/0988 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 15, 2021
From: ELASTIC BEAM, LLC
To: PING IDENTITY CORPORATION
Reel/Frame 056867/0919 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 15, 2021
From: SUBBARAYAN, UDAYAKUMAR; HARGUINDEGUY, BERNARD; GOPALAKRISHNAN, ANOOP KRISHNAN; ANGADI, NAGABHUSHANA; KUMAR, ASHWANI; SAHU, SANTOSH; POONTHIRUTHI, ADBU RAHEEM; SAHU, AVINASH KUMAR; KUNDOTTIL, YASAR
To: ELASTIC BEAM, INC.
Reel/Frame 056889/0271 →
CHANGE OF NAME Recorded Jul 15, 2021
From: ELASTIC BEAM INC.
To: ELASTIC BEAM, LLC
Reel/Frame 057364/0565 →
Priority Claims (1)
IN 201611036787 · Oct 26, 2016 · national
Continuity (3)
Continuation 16788059 · Feb 11, 2020
Continuation 15792850 · Oct 25, 2017
Related Publication 20220045990A1 · Feb 10, 2022