IP Library Granted Patent US 12,155,679
Granted Patent B2
US 12,155,679 · App. 17/567,785 · Granted Nov 26, 2024

Session based anomaly dectection

Inventors: Avinash Kolluru (Bangalore, IN); Inon Shkedy (Fort Myers, FL); Ravindra Guntur (Hyderabad, IN); Shubham Jindal (Neemrana, IN)
Assignee: Traceable Inc.
H04L63/1425H04L63/102H04L63/1416H04L63/1433H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,155,679
App. No.
17/567,785
Granted
Nov 26, 2024
Kind
B2
Abstract

A system that intercepts and analyzes application program interface (API) traffic, identifies correlations between components of API traffic, and uses those correlations to detect anomalous behaviors. API traffic, including requests and responses, is intercepted and analyzed to identify correlations in the API traffic. The correlations may be based on API traffic and can include a sequence of APIs, parameters passed between earlier and subsequent APIs, user roles within a user session and APIs accessed by the user roles, and other correlations. Correlation data for user sessions is generated and stored, and later compared to subsequent user session traffic. If the subsequent user session traffic does not comply with the correlations detected in earlier user sessions, an anomaly may be triggered.

Claims (32)

1. A method for performing session-based anomaly detection, comprising:

intercepting Application Program Interface (API) traffic between a client and a server, the API traffic associated with multiple user sessions;

identifying a first user session identifier associated with one of the multiple user sessions, the first user session associated with a subset of the intercepted API traffic;

detecting correlations between a subset of the API traffic associated with the first user session, wherein the correlation includes a request that includes an input derived from an output included in a previous response during the session;

storing correlation data based on the detected correlations;

comparing the correlation data to subsequently intercepted API traffic associated with a second user session; and

determining whether the intercepted API traffic includes an anomaly based on the comparison with the correlation data.

2. The method of claim 1 , wherein identifying the first user session identifier includes extracting a user identifier from a JSON object in an http header.

3. The method of claim 1 , wherein identifying the first user session identifier includes retrieving the user identifier from a response received by the client, the response being subsequent to the first response received in the user session.

4. The method of claim 1 , wherein identifying the first user session identifier includes retrieving an http header associated with an API associated with the user session.

5. The method of claim 1 , wherein the correlation includes a sequence of APIs occurring in the session.

6. The method of claim 1 , wherein the correlation includes role data for the user identifier associated with the session.

7. The method of claim 1 , further comprising generating an alert based on the anomaly determination.

8. A non-transitory computer readable storage medium having embodied thereon a program, the program being executable by a processor to perform a method for performing session-based anomaly detection, the method comprising:

intercepting Application Program Interface (API) traffic between a client and a server, the API traffic associated with multiple user sessions;

identifying a first user session identifier associated with one of the multiple user sessions, the first user session associated with a subset of the intercepted API traffic;

detecting correlations between a subset of the API traffic associated with the first user session, wherein the correlation includes a request that includes an input derived from an output included in a previous response during the session;

storing correlation data based on the detected correlations;

comparing the correlation data to subsequently intercepted API traffic associated with a second user session; and

determining whether the intercepted API traffic includes an anomaly based on the comparison with the correlation data.

9. The non-transitory computer readable storage medium of claim 8 , wherein identifying the first user session identifier includes extracting a user identifier from a JSON object in an http header.

10. The non-transitory computer readable storage medium of claim 8 , wherein identifying the first user session identifier includes retrieving the user identifier from a response received by the client, the response being subsequent to the first response received in the user session.

11. The non-transitory computer readable storage medium of claim 8 , wherein identifying the first user session identifier includes retrieving an http header associated with an API associated with the user session.

12. The non-transitory computer readable storage medium of claim 8 , wherein the correlation includes a sequence of APIs occurring in the session.

13. The non-transitory computer readable storage medium of claim 8 , wherein the correlation includes role data for the user identifier associated with the session.

14. The non-transitory computer readable storage medium of claim 8 , further comprising generating an alert based on the anomaly determination.

15. A system for automatically forecasting values for system metric time series, comprising:

a server including a memory and a processor; and

one or more modules stored in the memory and executed by the processor to intercept Application Program Interface (API) traffic between a client and a server, the API traffic associated with multiple user sessions, identify a first user session identifier associated with one of the multiple user sessions, the first user session associated with a subset of the intercepted API traffic, detect correlations between a subset of the API traffic associated with the first user session, wherein the correlation includes a request that includes an input derived from an output included in a previous response during the session; store correlation data based on the detected correlations, compare the correlation data to subsequently intercepted API traffic associated with a second user session, and determine whether the intercepted API traffic includes an anomaly based on the comparison with the correlation data.

16. The system of claim 15 , wherein identifying the first user session identifier includes extracting a user identifier from a JSON object in an http header.

17. The system of claim 15 , wherein identifying the first user session identifier includes retrieving the user identifier from a response received by the client, the response being subsequent to the first response received in the user session.

18. The system of claim 15 , wherein the correlation includes a sequence of APIs occurring in the session.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Aug 18, 2026
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK & TRUST COMPANY
To: HARNESS INC.; HARNESS INTERNATIONAL, INC.
Reel/Frame 075689/0062 →
RELEASE OF SECURITY INTEREST Recorded Aug 18, 2026
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK & TRUST COMPANY, AS AGENT
To: HARNESS INC.; HARNESS INTERNATIONAL, INC.
Reel/Frame 075689/0281 →
SECURITY INTEREST Recorded Mar 31, 2026
From: HARNESS INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 074240/0665 →
SECURITY INTEREST Recorded Mar 31, 2026
From: HARNESS INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY, AS AGENT
Reel/Frame 074240/0707 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2025
From: TRACEABLE INC.
To: HARNESS INC.
Reel/Frame 071911/0025 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 24, 2024
From: KOLLURU, AVINASH; SHKEDY, INON; GUNTUR, RAVINDRA; JINDAL, SHUBHAM
To: TRACEABLE INC.
Reel/Frame 068995/0887 →
Continuity (1)
Related Publication 20230224314A1 · Jul 13, 2023