IP Library › Granted Patent US 12,563,014
Granted Patent B2
US 12,563,014 · App. 18/303,359 · Granted Feb 24, 2026

Application programming interface (API) security

Inventors: Azzedine Benameur (Fairfax, VA); Yun Shen (Bristol, GB)
Assignee: NetApp, Inc.
H04L63/0236G06F9/547H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,563,014
App. No.
18/303,359
Granted
Feb 24, 2026
Kind
B2
Abstract

Systems and methods for enhancing API security by identifying anomalous activities in a cloud environment are provided. In one embodiment, the lack of awareness of an external API with respect to how calls to the external API may affect a cluster of a container orchestration platform is addressed. For instance, the views of the external and internal APIs may be combined to achieve better API security by correlating external API calls with undesirable behavior or other anomalies arising in the internal API. Responsive to identifying such undesirable behavior, information (e.g., a host, a source IP, a user, a specific payload) associated with the offending external API call may be added to a network security feature (e.g., a deny list, an IPS, or a WAF) utilized by the external API to facilitate performance of enhanced filtering of subsequent external API calls by the external API on behalf of the internal API.

Claims (43)

1 . A non-transitory machine readable medium storing instructions, which when executed by one or more processing resources of a cluster of a container orchestration platform, cause the cluster to:

determine, by a master node of the cluster, an impact on the cluster resulting from one or more internal application programming interface (API) calls to an API server of the cluster, wherein the one or more internal API calls are associated with an external API call made to an API gateway;

determine the impact satisfies one or more criteria; and

after the determining the impact satisfies the one or more criteria, facilitate performance of enhanced filtering by the API gateway by providing feedback to the API gateway, wherein the feedback comprises inclusion of a source Internet Protocol (IP) address associated with the external API call on a deny list in which the deny list contains one or more IP addresses from which subsequent external API calls are to be blocked by the API gateway.

2 . The non-transitory machine readable medium of claim 1 , wherein the API gateway comprises an ingress controller associated with the container orchestration platform.

3 . The non-transitory machine readable medium of claim 1 , wherein the API gateway is associated with a cloud provider in which the container orchestration platform is running.

4 . The non-transitory machine readable medium of claim 3 , wherein the API gateway includes one or more of a web application firewall (WAF) deployment and an intrusion prevention system (IPS) deployment.

5 . A method comprising:

determining, by a master node of a cluster of a container orchestration platform, an impact on the cluster resulting from one or more internal application programming interface (API) calls to an API server of the cluster, wherein the one or more internal API calls are associated with an external API call made to an API gateway;

determining, by the master node, the impact satisfies one or more criteria; and

after the determining the impact satisfies the one or more criteria, facilitating, by the master node, performance of enhanced filtering by the API gateway by providing feedback to the API gateway, wherein the feedback comprises one or more of:

inclusion of a source Internet Protocol (IP) address associated with the external API call on a deny list in which the deny list contains one or more IP addresses from which subsequent external API calls are to be blocked by the API gateway;

inclusion of information regarding a host or a user associated with the external API call on the deny list in which the deny list identifies one or more hosts or users from which subsequent external API calls are to be blocked by the API gateway; or

inclusion of content from a payload associated with the external API call on the deny list in which the deny list contains content from one or more payloads that when received as part of subsequent external API calls are to be blocked by the API gateway.

6 . The method of claim 5 , wherein the API gateway comprises an ingress controller associated with the container orchestration platform.

7 . The method of claim 5 , wherein the API gateway is associated with a cloud provider in which the container orchestration platform is running.

8 . The method of claim 7 , wherein the API gateway includes one or more of a web application firewall (WAF) deployment and an intrusion prevention system (IPS) deployment.

9 . A system comprising:

one or more processing resources;

instructions that when executed by the one or more processing resources, cause the system to:

determining, by a master node of a cluster of a container orchestration platform, an impact on the cluster resulting from one or more internal application programming interface (API) calls to an API server of the cluster, wherein the one or more internal API calls are associated with an external API call made to an API gateway;

determining, by the master node, the impact satisfies one or more criteria; and

after the determining the impact satisfies the one or more criteria, facilitating, by the master node, performance of enhanced filtering by the API gateway by providing feedback to the API gateway, wherein the feedback comprises one or more of:

inclusion of a source Internet Protocol (IP) address associated with the external API call on a deny list in which the deny list contains one or more IP addresses from which subsequent external API calls are to be blocked by the API gateway;

inclusion of information regarding a host or a user associated with the external API call on the deny list in which the deny list identifies one or more hosts or users from which subsequent external API calls are to be blocked by the API gateway; or

inclusion of content from a payload associated with the external API call on the deny list in which the deny list contains content from one or more payloads that when received as part of subsequent external API calls are to be blocked by the API gateway.

10 . The system of claim 9 , wherein the API gateway comprises an ingress controller associated with the container orchestration platform.

11 . The system of claim 9 , wherein the API gateway is associated with a cloud provider in which the container orchestration platform is running.

12 . The system of claim 11 , wherein the API gateway includes one or more of a web application firewall (WAF) deployment and an intrusion prevention system (IPS) deployment.

13 . A non-transitory machine readable medium storing instructions, which when executed by one or more processing resources of a cluster of a container orchestration platform, cause the cluster to:

determine, by a master node of the cluster, an impact on the cluster resulting from one or more internal application programming interface (API) calls to an API server of the cluster, wherein the one or more internal API calls are associated with an external API call made to an API gateway;

determine the impact satisfies one or more criteria; and

after the determining the impact satisfies the one or more criteria, facilitate performance of enhanced filtering by the API gateway by providing feedback to the API gateway, wherein the feedback comprises inclusion of information regarding a host or a user associated with the external API call on a deny list in which the deny list identifies one or more hosts or users from which subsequent external API calls are to be blocked by the API gateway.

14 . The non-transitory machine readable medium of claim 13 , wherein the API gateway comprises an ingress controller associated with the container orchestration platform.

15 . The non-transitory machine readable medium of claim 13 , wherein the API gateway is associated with a cloud provider in which the container orchestration platform is running.

16 . The non-transitory machine readable medium of claim 15 , wherein the API gateway includes one or more of a web application firewall (WAF) deployment and an intrusion prevention system (IPS) deployment.

17 . A non-transitory machine readable medium storing instructions, which when executed by one or more processing resources of a cluster of a container orchestration platform, cause the cluster to:

determine, by a master node of the cluster, an impact on the cluster resulting from one or more internal application programming interface (API) calls to an API server of the cluster, wherein the one or more internal API calls are associated with an external API call made to an API gateway;

determine the impact satisfies one or more criteria; and

after the determining the impact satisfies the one or more criteria, facilitate performance of enhanced filtering by the API gateway by providing feedback to the API gateway, wherein the feedback comprises inclusion of content from a payload associated with the external API call on a deny list, wherein the deny list contains content from one or more payloads that when received as part of subsequent external API calls are to be blocked by the API gateway.

18 . The non-transitory machine readable medium of claim 17 , wherein the API gateway comprises an ingress controller associated with the container orchestration platform.

19 . The non-transitory machine readable medium of claim 17 , wherein the API gateway is associated with a cloud provider in which the container orchestration platform is running.

20 . The non-transitory machine readable medium of claim 19 , wherein the API gateway includes one or more of a web application firewall (WAF) deployment and an intrusion prevention system (IPS) deployment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2023
From: BENAMEUR, AZZEDINE; SHEN, YUN
To: NETAPP, INC.
Reel/Frame 063421/0157 →
Continuity (2)
Provisional Application 63477105 · Dec 23, 2022
Related Publication 20240214348A1 · Jun 27, 2024
References Cited (20)
US 20200162503A1 · Shurtleff · 2020 [cited by examiner]
US 20200220875A1 · Harguindeguy · 2020 [cited by examiner]
US 20220210172A1 · Tan · 2022 [cited by examiner]
US 20220382593A1 · Tootaghaj · 2022 [cited by examiner]
US 20230034344A1 · Jain · 2023 [cited by examiner]
US 20230337019A1 · Mehta · 2023 [cited by examiner]
US 20240015092A1 · Griffin · 2024 [cited by examiner]
US 20240126916A1 · Nguyen · 2024 [cited by examiner]
US 20240129317A1 · Addaguduru · 2024 [cited by examiner]
US 20240193467A1 · Vohra · 2024 [cited by examiner]
Amazon., “Amazon ECS,” Run highly secure, reliable, and scalable containers. Retrieved from Internet URL: https://aws.amazon.com/ecs/. [cited by applicant]
AWS., “Serverless API Security, Authentication, and Authorization on AWS,” Retrieved from Internet URL: https://aws.amazon.com/graphql/api-security-auth/. [cited by applicant]
Axway., “4 types of APIs and what makes each one unique,” Axway Blog, 2022. Retrieved from Internet URL: https://blog.axway.com/learning-center/apis/basics/different-types-apis#:˜:text=Internal%20service%20APls%20expose… [cited by applicant]
Bender J., “What Is Statistical Analysis?,” Business News Daily, 2023. Retrieved from Internet URL: https://www.businessnewsdaily.com/6000-statistical-analysis.html. [cited by applicant]
Cloud Flare., “What is a WAF? | Web Application Firewall Explained,” Cloud Flare. Retrieved from Internet URL: https://www.cloudflare.com/learning/ddos/glossary/web-application-firewall-waf/. [cited by applicant]
Comiskey C., “Track Your Cloud Activities Using IBM Cloud Activity Tracker with LogDNA,” IBM Cloud, 2019, pp. 1-9. Retrieved from Internet URL: https://www.ibm.com/cloud/blog/track-your-cloud-activities-using-ibm-cloud-… [cited by applicant]
Elastic., “Modernize SecOps with Elastic Security,” Elastic Security. Retrieved from Internet URL: https://www.elastic.co/security. [cited by applicant]
NetApp., “What is cloud analytics?,” Cloud Services. Retrieved from Internet URL: https://www.netapp.com/cloud-services/what-is-cloud-analytics/#:˜:text=Cloud%20analytics%20involves%20deployment%20of,in%20all%20sorts%20… [cited by applicant]
Trend Micro Cloud One., “Configure Google Cloud Audit Logs to Track All Activities,” Retrieved from Internet URL: https://www.trendmicro.com/cloudoneconformity/knowledge-base/gcp/CloudIAM/record-all-activities.html. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2023/085035, mailed on Apr. 3, 2024, 11 pages. [cited by applicant]