IP Library Granted Patent US 12,632,551
Granted Patent B2
US 12,632,551 · App. 18/224,451 · Granted May 19, 2026

Identifying command and control attacks using API calls

Inventors: Jason Falivene (Kingston, WA); Ivo Ivanov (Kenmore, WA); Carlos Fuentes Bermejo (Dublin, IE)
Assignee: Dropbox, Inc.
G06F21/566G06F9/54G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,632,551
App. No.
18/224,451
Granted
May 19, 2026
Kind
B2
Abstract

A collaborative content management system identifies an application installed on one or more client devices that is susceptible to an attack by using the API calls of the application. The collaborative content management system obtains API calls made by the application and derives API call features. The collaborative content management system inputs the API call features into a machine learning model and receives, as output from the model, a determination of whether the set of API calls represents a C2 attack. In some embodiments, the collaborative content management system, responsive to determining that the set of API calls represents a C2 attack, may take a security action.

Claims (41)

1 . A method comprising:

identifying an application installed on one or more client devices by selecting the application from a set of applications, wherein selecting the application comprises filtering the set of applications based on preliminary application protocol interface (API) call features, including the application having a development state that is not approved or verified by a content management system and based on the development state, the application being susceptible to an attack by API calls of the application;

obtaining a set of API calls made by the application;

extracting a vector of API call features derived from the set of API calls;

inputting the vector of API call features into a machine learning model; and

receiving, as output from the machine learning model, a determination as to whether the set of API calls represent a command and control attack.

2 . The method of claim 1 , wherein identifying the application installed on the one or more client devices that is susceptible to an attack by using API calls of the application comprises identifying the application from a set of development state applications.

3 . The method of claim 1 , wherein:

identifying the application installed on the one or more client devices that is susceptible to an attack by using API calls of the application comprises filtering the set of applications with preliminary API call features based on respective patterns of events corresponding to the respective applications of the set of applications,

the preliminary API call features comprise the application performing a pattern of events, and

the pattern of events includes a set of events performed in an order within a time range.

4 . The method of claim 1 , wherein identifying the application installed on the one or more client devices that is susceptible to an attack by using API calls of the application comprises identifying the application from a set of development state applications with preliminary API call features.

5 . The method of claim 1 , wherein obtaining the set of API calls made by the application comprises obtaining a set of API calls that occurred within a predefined range of time.

6 . The method of claim 1 , wherein the machine learning model is trained with training data comprising sets of API calls labelled by whether they represent a C 2 attack.

7 . The method of claim 1 , further comprising, responsive to receiving a determination that the set of API calls represents a command and control attack, taking a security action.

8 . The method of claim 7 , wherein the security action comprises adding the application to a deny list.

9 . The method of claim 1 , further comprising, responsive to receiving a determination that the set of API calls does not represent a command and control attack, adding the application to an allow list.

10 . The method of claim 9 , wherein identifying the application comprises identifying the application from a set of applications that excludes applications on the allow list.

11 . The method of claim 9 , wherein identifying the application comprises identifying the application from a set of applications that excludes applications on the allow list.

12 . A non-transitory computer-readable medium comprising memory with instructions encoded thereon, the instructions, when executed by one or more processors, causing the one or more processors to perform operations, the instructions comprising instructions to:

identify an application installed on one or more client devices by selecting the application from a set of applications, wherein selecting the application comprises filtering the set of applications based on preliminary application protocol interface (API) call features, including the application having a development state that is not approved or verified by a content management system and based on the development state, the application being susceptible to an attack by using API calls of the application;

obtain a set of API calls made by the application;

extract a vector of API call features from the set of API calls;

input the vector of API call features into a machine learning model; and

receive, as output from the machine learning model, a determination as to whether the set of API calls represent a command and control attack.

13 . The non-transitory computer-readable medium of claim 12 , wherein the instructions for identifying the application installed on the one or more client devices that is susceptible to an attack by using API calls of the application comprise instructions to identify the application from a set of development state applications.

14 . The non-transitory computer-readable medium of claim 12 , wherein:

the instructions for identifying the application installed on the one or more client devices that is susceptible to an attack by using API calls of the application comprise instructions to filter the set of applications with preliminary API call features based on respective patterns of events corresponding to the respective applications of the set of applications,

the preliminary API call features comprise the application performing a pattern of events, and

the pattern of events includes a set of events performed in an order within a time range.

15 . The non-transitory computer-readable medium of claim 12 , wherein the instructions for identifying the application installed on the one or more client devices that is susceptible to an attack by using API calls of the application comprise instructions to identify the application from a set of development state applications with preliminary API call features.

16 . The non-transitory computer-readable medium of claim 12 , wherein the instructions for obtaining the set of API calls made by the application comprise instructions to obtain a set of API calls that occurred within a predefined range of time.

17 . The non-transitory computer-readable medium of claim 12 , wherein the machine learning model is trained with training data comprising sets of API calls labelled by whether they represent a C2 attack.

18 . A system comprising:

memory with instructions encoded thereon; and

one or more processors that, when executing the instructions, are caused to perform operations comprising:

identifying an application installed on one or more client devices by selecting the application from a set of applications, wherein selecting the application comprises filtering the set of applications based on preliminary application protocol interface (API) call features, including the application having a development state that is not approved or verified by a content management system and based on the development state, the application being susceptible to an attack by using API calls of the application;

obtaining a set of API calls made by the application;

extracting a vector of API call features derived from the set of API calls;

inputting the vector of API call features into a machine learning model; and

receiving, as output from the machine learning model, a determination as to whether the set of API calls represent a command and control attack.

Assignments (2)
SECURITY INTEREST Recorded Dec 12, 2024
From: DROPBOX, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069604/0611 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2023
From: FALIVENE, JASON; IVANOV, IVO; BERMEJO, CARLOS FUENTES
To: DROPBOX, INC.
Reel/Frame 064343/0042 →