IP Library Granted Patent US 12,739,280
Granted Patent B2
US 12,739,280 · App. 18/655,070 · Granted Sep 15, 2026

Accelerated policy assessment for requests

Inventors: Sai Sree Laya Chukkapalli (Catonsville, MD); Julian James Stephen (Yorktown Heights, NY); Arjun Natarajan (Old Tappan, NJ)
Assignee: International Business Machines Corporation
H04L63/20H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,739,280
App. No.
18/655,070
Granted
Sep 15, 2026
Kind
B2
Abstract

A computer-implemented method, according to one approach, is performed in response to intercepting an application request. The computer-implemented method includes forwarding a first copy of the application request to a policy agent, and forwarding a second copy of the application request to a sketch algorithm. The sketch algorithm extracts metadata from the second copy of the application request. Moreover, the policy agent applies a security policy to the first copy of the application request and the metadata extracted by the sketch algorithm. Furthermore, the application request is dispositioned based at least in part on whether the first copy of the application request and/or the metadata extracted by the sketch algorithm satisfy the security policy.

Claims (68)

1 . A computer-implemented method (CIM), comprising:

in response to intercepting an application request:

causing a first copy of the application request to be forwarded to a policy agent,

causing a second copy of the application request to be forwarded to a sketch algorithm, wherein the first copy and second copy of the application request are forwarded to the policy agent and the sketch algorithm simultaneously; and

causing the sketch algorithm to extract metadata from the second copy of the application request includes:

accessing Layer 7 metadata in the second copy of the application request; and

applying a width while summarizing the streaming traffic of the Layer 7 and wherein the width is determined while training the sketch algorithm, by:

causing the policy agent to forward network traffic to the sketch algorithm; and

in response to detecting diverse active network traffic, causing the sketch algorithm to dynamically increase the width;

in response to detecting lean active network traffic, causing the sketch algorithm to dynamically decrease the width;

causing the policy agent to apply a security policy to the first copy of the application request and the metadata extracted by the sketch algorithm; and

dispositioning the application request based at least in part on whether the first copy of the application request and/or the metadata extracted by the sketch algorithm satisfy the security policy, wherein the application request is intercepted by a proxy.

2 . The CIM of claim 1 , wherein the width is determined while training the sketch algorithm, by:

causing the policy agent to forward all network traffic to the sketch algorithm;

causing the sketch algorithm to observe the network traffic for a predetermined amount of time; and

identifying a width that most effectively summarizes the network traffic.

3 . The CIM of claim 1 , wherein the width is dynamically updated over time, by:

observing active network traffic for a predetermined amount of time; in

response to detecting diverse active network traffic, increasing the width; and in

response to detecting lean active network traffic, decreasing the width.

4 . The CIM of claim 1 , wherein the Layer 7 metadata is selected from the group consisting of: service names, authentication tokens, Uniform Resource Locator (URL) paths, session tokens, cookies, and HTTP response codes.

5 . The CIM of claim 1 , wherein the dispositioning of the application request, includes:

in response to determining the first copy of the application request and/or the metadata extracted by the sketch algorithm satisfy the security policy, causing the application request to be forwarded to a target application for implementation.

6 . The CIM of claim 5 , wherein the dispositioning of the application request, includes:

in response to determining the first copy of the application request and/or the metadata extracted by the sketch algorithm do not satisfy the security policy, causing the application request to be rejected.

7 . A computer program product (CPP), comprising:

a set of one or more computer-readable storage media; and

program instructions, collectively stored in the set of one or more storage media, for causing a processor set to perform the following computer operations:

in response to intercepting an application request:

cause a first copy of the application request to be forwarded to a policy agent, and

cause a second copy of the application request to be forwarded to a sketch algorithm

cause the sketch algorithm to:

extract metadata from the second copy of the application request includes:

accessing Layer 7 metadata in the second copy of the application request;

and applying a width while summarizing the Streaming traffic of the Layer 7; and

store the metadata extracted by the sketch algorithm in a designated portion of memory allocated to the sketch algorithm, the designated portion of memory having a width determined while training the sketch algorithm;

cause the policy agent to apply a security policy to the first copy of the application request and the metadata extracted by the sketch algorithm; and

disposition the application request based at least in part on whether the first copy of the application request and/or the metadata extracted by the sketch algorithm satisfy the security policy wherein the width is dynamically updated over time, by:

observing active network traffic for a predetermined amount of time; in response to detecting diverse active network traffic, increasing the width of the designated portion of memory allocated to the sketch algorithm; and

in response to detecting lean active network traffic, decreasing the width of the designated portion of memory allocated to the sketch algorithm.

8 . The CPP of claim 7 , wherein the first and second copies of the application request are forwarded to the policy agent and the sketch algorithm simultaneously.

9 . The CPP of claim 7 , wherein the application request is intercepted by a proxy.

10 . The CPP of claim 7 , wherein the width is determined while training the sketch algorithm, by:

causing the policy agent to forward all network traffic to the sketch algorithm;

causing the sketch algorithm to observe the network traffic for a predetermined amount of time;

determining an amount of the memory that most effectively summarizes the network traffic for the predetermined amount of time; and

presetting the width as the determined amount of the memory.

11 . The CPP of claim 7 , wherein the Layer 7 metadata is selected from the group consisting of: service names, authentication tokens, Uniform Resource Locator (URL) paths, session tokens, cookies, and HTTP response codes.

12 . The CPP of claim 7 , wherein the dispositioning of the application request, includes:

in response to determining the first copy of the application request and/or the metadata extracted by the sketch algorithm satisfy the security policy, causing the application request to be forwarded to a target application for implementation.

13 . The CPP of claim 12 , wherein the dispositioning of the application request, includes:

in response to determining the first copy of the application request and/or the metadata extracted by the sketch algorithm do not satisfy the security policy, causing the application request to be rejected.

14 . A computer system (CS), comprising:

a processor set;

a set of one or more computer-readable storage media;

program instructions, collectively stored in the set of one or more storage media, for causing the processor set to perform the following computer operations:

in response to intercepting an application request:

cause a first copy of the application request to be forwarded to a policy agent, and

cause a second copy of the application request to be forwarded to a sketch algorithm

cause the sketch algorithm to:

extract metadata from the second copy of the application request includes:

accessing Layer 7 metadata in the second copy of the application request;

and applying the width while summarizing the Streaming traffic of the Layer 7; and

store the metadata extracted by the sketch algorithm in a designated portion of memory allocated to the sketch algorithm, the designated portion of memory having a width determined while training the sketch algorithm;

cause the policy agent to apply a security policy to the first copy of the application request and the metadata extracted by the sketch algorithm; and

disposition the application request based at least in part on whether the first copy of the application request and/or the metadata extracted by the sketch algorithm satisfy the security policy wherein the width is dynamically updated over time, by:

observing active network traffic for a predetermined amount of time; in response to detecting diverse active network traffic, increasing the width of the designated portion of memory allocated to the sketch algorithm; and

in response to detecting lean active network traffic, decreasing the width of the designated portion of memory allocated to the sketch algorithm.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2024
From: CHUKKAPALLI, SAI SREE LAYA; JAMES STEPHEN, JULIAN; NATARAJAN, ARJUN
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 067321/0187 →
Continuity (1)
Related Publication 20250343821A1 · Nov 6, 2025
References Cited (31)
US 10230571B2 · Rangasamy et al. · 2019 [cited by applicant]
US 10242073B2 · Koerner et al. · 2019 [cited by applicant]
US 10389602B2 · Chang et al. · 2019 [cited by applicant]
US 10411973B2 · Brown et al. · 2019 [cited by applicant]
US 10425386B2 · Wardell et al. · 2019 [cited by applicant]
US 10769274B2 · Hassan · 2020 [cited by applicant]
US 11057393B2 · Coffing · 2021 [cited by applicant]
US 11233826B2 · Nakagoe et al. · 2022 [cited by applicant]
US 11271969B2 · Pitre et al. · 2022 [cited by applicant]
US 11411974B2 · Vittal · 2022 [cited by applicant]
US 11824836B2 · Jiang et al. · 2023 [cited by applicant]
US 11943260B2 · Narayanaswamy et al. · 2024 [cited by applicant]
US 20210036991A1 · Owens · 2021 [cited by examiner]
US 20210067543A1 · Levy Nahum · 2021 [cited by examiner]
US 20230146667A1 · Jiang et al. · 2023 [cited by applicant]
US 20230208817A1 · Veereshwara et al. · 2023 [cited by applicant]
CN 109309666A · 2019 [cited by applicant]
CN 110971575A · 2020 [cited by applicant]
International Searching Authority, “Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, or Declaration,” Patent Cooperation Treaty Jun. 4, 202… [cited by applicant]
Minna et al., “SoK: Run-time security for cloud microservices. Are we there yet?” Computers & Security, vol. 127, 2023, pp. 1-14. [cited by applicant]
Li et al., “Automatic Policy Generation for Inter-Service Access Control of Microservices,” 30th USENIX Security Symposium, Aug. 2021, pp. 3971-3988. [cited by applicant]
Li et al. “MicroSketch: Lightweight and Adaptive Sketch Based Performance Issue Detection and Localization in Microservice Systems,” International Conference on Service-Oriented Computing (ICSOC), 2022, pp. 219-236. [cited by applicant]
Zaheer et al., “eZTrust: Network-Independent Zero-Trust Perimeterization for Microservices,” Proceedings of the ACM Symposium on SDN Research, 2019, 13 pages. [cited by applicant]
Li et al., “Towards Automated Inter-Service Authorization for Microservice Applications,” Proceedings of the ACM SIGCOMM Posters and Demos, 2019, 4 pages. [cited by applicant]
Chakraborty et al., “CausIL: Causal Graph for Instance Level Microservice Data,” WWW23, Apr./May 2023, pp. 2905-2915. [cited by applicant]
Jacob et al., “Detecting Cyber Security Attacks against a Microservices Application using Distributed Tracing,” Proceedings of the 7th International Conference on Information Systems Security and Privacy (ICISSP), 2021,… [cited by applicant]
Meadows et al., “Sidecar-based Path-aware Security for Microservices,” Proceedings of the 28th ACM Symposium on Access Control Models and Technologies, 2023, pp. 157-162. [cited by applicant]
Parker et al., “Visualizing Anti-Patterns in Microservices at Runtime: A Systematic Mapping Study,” IEEE Access, vol. 11, Jan. 2023, pp. 4434-4442. [cited by applicant]
Yang et al., “Elastic Sketch: Adaptive and Fast Network-wide Measurements,” SIGGCOMM, Aug. 2018, 15 pages, retrieved from https://conferences.sigcomm.org/events/apnet2018/papers/elastic_sketch.pdf. [cited by applicant]
Cormode et al., “An Improved Data Stream Summary: The Count-Min Sketch and its Applications,” Journal of Algorithms, vol. 55, 2005, 11 pages, retrieved from https://github.com/florian/reading-notes/blob/master/papers/01… [cited by applicant]
Jiang et al., U.S. Appl. No. 17/453,887, filed Nov. 8, 2021. [cited by applicant]