IP Library Patent Application 18419593
Patent Application
App. No. 18/419,593

GENERALIZED BEHAVIOR ANALYTICS FRAMEWORK FOR DETECTING AND PREVENTING DIFFERENT TYPES OF API SECURITY VULNERABILITIES

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/419,593
Abstract

A behavior analytics method for detecting and preventing different types of API based threats and attacks is disclosed. The method includes collecting request and response data of API calls from plurality of user sessions and storing it in a data lake. The method further includes extracting and combining features of the collected request and response data. The features may be associated with login behavior, API request content and behavior, API object accessing content and behavior, and API response content and behavior. The method also includes encoding the combined features via a neural network model to create a behavior fingerprint of each of the user sessions. Also, the method includes clustering the created behavior fingerprint to detect normal or abnormal user behavior. Thereafter, the method includes reporting the detected abnormal user behavior.

Claims (35)

1 . A behavior analytics system for different types of Application Programming Interface (API) vulnerabilities and attacks, the behavior analytics system comprises:

a collection engine to collect requests and responses of one or more API calls associated to an application in a protected environment made during one or more login sessions;

an API sequence engine to:

combine one or more features extracted from the collected requests and responses, wherein the one or more features are associated with login behavior, API request content and behavior, API object accessing content and behavior, and API response content and behavior; and

encode the combined one or more features via a neural network based embedding model to create a behavior fingerprint of each of the one or more login sessions;

a clustering engine to detect at least one of: a normal and an abnormal user behavior based on the created behavior fingerprint of each of the one or more login sessions; and

a report and response engine to report the detected abnormal user behavior.

2 . The behavior analytics system as claimed in claim 1 , wherein the user is facilitated to validate the provided user behavior.

3 . The behavior analytics system as claimed in claim 2 , wherein the report and response engine take a necessary action to mitigate the effects of the abnormal user behavior based on the validation of the user.

4 . The behavior analytics system as claimed in claim 1 , wherein the report and response engine automatically take a necessary action to mitigate the effects of the abnormal user behavior if magnitude of associated threat is more than a pre-defined threshold.

5 . The behavior analytics system as claimed in claim 1 , wherein the collection engine stores the collected requests and responses in a data lake for detailed analysis at any point of time.

6 . The behavior analytics system as claimed in claim 1 , wherein the requests and responses correspond to one or more API calls made by at least one of: one or more users and services.

7 . The behavior analytics system as claimed in claim 6 , wherein the one or more API calls includes at least one of: initial authentication, authorization, and one or more Hyper Text Transfer Protocol (HTTP) requests and responses in the login session.

8 . The behavior analytics system as claimed in claim 1 , wherein the login behavior includes at least one of: Internet Protocol (IP) address, geolocation, organization, and Autonomous System Number (ASN) of the origin where a user comes from.

9 . The behavior analytics system as claimed in claim 1 , wherein the API request content and behavior includes at least one of: API endpoints and a time-series pattern a user accesses different APIs during a particular login session.

10 . The behavior analytics system as claimed in claim 1 , wherein the API object accessing content and behavior includes all object types and object values that a user accesses during a particular login session.

11 . The behavior analytics system as claimed in claim 1 , wherein the API response content and behavior includes at least one of: a response status code and a body content that a user receives during a particular login session.

12 . A behavior analytics method for different types of Application Programming Interface (API) vulnerabilities and attacks, the behavior analytics method comprises:

collecting requests and responses of one or more API calls associated to an application in a protected environment made during one or more login sessions;

combining one or more features extracted from the collected requests and responses, wherein the one or more features are associated with login behavior, API request content and behavior, API object accessing content and behavior, and API response content and behavior;

encoding the combined one or more features via a neural network based embedding model to create a behavior fingerprint of each of the one or more login sessions;

detecting at least one of: a normal and an abnormal user behavior based on the created behavior fingerprint of each of the one or more login sessions; and

reporting the detected abnormal user behavior.

13 . The behavior analytics method as claimed in claim 12 , further comprises:

facilitating a user to validate the provided user behavior; and

taking a necessary action to mitigate the effects of the abnormal user behavior based on the validation of the user.

14 . The behavior analytics method as claimed in claim 12 , further comprises taking a necessary action to mitigate the effects of the abnormal user behavior if magnitude of associated threat is more than a pre-defined threshold.

15 . The behavior analytics method as claimed in claim 12 , further comprises storing the collected requests and responses in a data lake for detailed analysis at any point of time.

16 . The behavior analytics method as claimed in claim 12 ,

wherein the requests and responses correspond to one or more API calls made by at least one of: one or more users and services, and

wherein the one or more API calls include at least one of: initial authentication, authorization, and one or more Hyper Text Transfer Protocol (HTTP) requests and responses in the login session.

17 . The behavior analytics method as claimed in claim 12 , wherein the login behavior includes at least one of: Internet Protocol (IP) address, geolocation, organization, and Autonomous System Number (ASN) of the origin where a user comes from.

18 . The behavior analytics method as claimed in claim 12 , wherein the API request content and behavior includes at least one of: API endpoints and a time-series pattern a user accesses different API during a particular login session.

19 . The behavior analytics method as claimed in claim 12 , wherein the API object accessing content and behavior includes all object types and object values that a user accesses during a particular login session.

20 . The behavior analytics method as claimed in claim 12 , wherein the API response content and behavior includes at least one of: a response status code and a body content that a user receives during a particular login session.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Aug 18, 2026
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK & TRUST COMPANY
To: HARNESS INC.; HARNESS INTERNATIONAL, INC.
Reel/Frame 075689/0062 →
RELEASE OF SECURITY INTEREST Recorded Aug 18, 2026
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK & TRUST COMPANY, AS AGENT
To: HARNESS INC.; HARNESS INTERNATIONAL, INC.
Reel/Frame 075689/0281 →
SECURITY INTEREST Recorded Mar 31, 2026
From: HARNESS INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 074240/0665 →
SECURITY INTEREST Recorded Mar 31, 2026
From: HARNESS INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY, AS AGENT
Reel/Frame 074240/0707 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2025
From: TRACEABLE INC.
To: HARNESS INC.
Reel/Frame 071911/0025 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2024
From: WANG, JISHENG, MR; NAGARAJ, SANJAY, MR
To: TRACEABLE INC
Reel/Frame 066236/0586 →