IP Library › Granted Patent US 12,537,849
Granted Patent B1
US 12,537,849 · App. 19/092,750 · Granted Jan 27, 2026

Techniques for API endpoint mitigation

Inventors: Or Tzabary (Petah Tikva, IL); Ido Yariv (New York, NY); Cfir Cohen (Seattle, WA)
Assignee: Wiz, Inc.
H04L63/1441G06F9/547H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,537,849
App. No.
19/092,750
Granted
Jan 27, 2026
Kind
B1
Abstract

A system and method for initiating a mitigation action for an exposed Application Programming Interface (API) endpoint in a cloud computing environment is presented. The method includes detecting an API endpoint of a plurality of API endpoints in a cloud computing environment; executing a network access instruction on the API endpoint, wherein the network access instruction is provided over at least an external network; determining that the API endpoint is an exposed API endpoint in response to receiving a predetermined result of executing the network access instruction; initiating a mitigation action in response to the detection of the exposed API endpoint.

Claims (60)

1 . A method for initiating a mitigation action for an exposed Application Programming Interface (API) endpoint in a cloud computing environment, comprising:

detecting an API endpoint of a plurality of API endpoints in a cloud computing environment, wherein verifying the API endpoint includes generating a list of detected API endpoints based on runtime data and static analysis results of an application;

executing a network access instruction on the API endpoint, wherein the network access instruction is provided over at least an external network;

determining that the API endpoint is an exposed API endpoint in response to receiving a predetermined result of executing the network access instruction; and

initiating a mitigation action in response to the detection of the exposed API endpoint.

2 . The method of claim 1 , further comprising:

initiating the mitigation action in any of a plurality of platforms of the cloud computing environment.

3 . The method of claim 2 , wherein the plurality of platforms includes any one of: an infrastructure as a service (IaaS), a platform as a service (PaaS), a software as a service (Saas), and any combination thereof.

4 . The method of claim 1 , wherein initiating a mitigation action further comprises:

initiating any one of: an input validation, an authentication protocol, an API gateway, an API input rate limit, and any combination thereof.

5 . The method of claim 1 , further comprising:

determining that the API endpoint is an unexposed API endpoint in response to receiving a result of executing the network access instruction which is different than the predetermined result.

6 . The method of claim 1 , wherein detecting an API endpoint further comprises:

receiving runtime data from a plurality of sensors, each sensor deployed on a workload in the cloud computing environment;

extracting a plurality of API calls from the received runtime data; and

detecting an API path from an extracted API call of the plurality of API calls.

7 . The method of claim 6 , further comprising:

initiating inspection of a workload associated with the API path; and

detecting an API endpoint of the plurality of API endpoints based on a result of the inspection and the detected API path.

8 . The method of claim 7 , further comprising:

inspecting the workload for a cybersecurity object, wherein the cybersecurity object indicates an application associated with the API path.

9 . The method of claim 8 , wherein initiating inspection of a workload further comprises:

initiating static analysis on a workload on which a sensor is deployed for a detection of an application related to the API call.

10 . The method of claim 1 , wherein verifying the API endpoint further comprises:

generating the network access instruction based on data extracted from an API call.

11 . A non-transitory computer-readable medium storing a set of instructions for initiating a mitigation action for an exposed Application Programming Interface (API) endpoint in a cloud computing environment, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

detect an API endpoint of a plurality of API endpoints in a cloud computing environment, wherein verifying the API endpoint includes generating a list of detected API endpoints based on runtime data and static analysis results of an application;

execute a network access instruction on the API endpoint, wherein the network access instruction is provided over at least an external network;

determine that the API endpoint is an exposed API endpoint in response to receiving a predetermined result of executing the network access instruction; and

initiate a mitigation action in response to the detection of the exposed API endpoint.

12 . A system for initiating a mitigation action for an exposed Application Programming Interface (API) endpoint in a cloud computing environment comprising:

a processing circuitry;

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

detect an API endpoint of a plurality of API endpoints in a cloud computing environment by generating a list of detected API endpoints based on runtime data and static analysis results of an application;

execute a network access instruction on the API endpoint, wherein the network access instruction is provided over at least an external network;

determine that the API endpoint is an exposed API endpoint in response to receiving a predetermined result of executing the network access instruction; and

initiate a mitigation action in response to the detection of the exposed API endpoint.

13 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

initiate the mitigation action in any of a plurality of platforms of the cloud computing environment.

14 . The system of claim 13 , wherein the plurality of platforms includes any one of:

an infrastructure as a service (IaaS), a platform as a service (PaaS), a software as a service (Saas), and any combination thereof.

15 . The system of claim 12 , wherein the memory contains further instructions that, when executed by the processing circuitry for initiating a mitigation action, further configure the system to:

initiate any one of:

an input validation, an authentication protocol, an API gateway, an API input rate limit, and any combination thereof.

16 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

determine that the API endpoint is an unexposed API endpoint in response to receiving a result of executing the network access instruction which is different than the predetermined result.

17 . The system of claim 12 , wherein the memory contains further instructions that, when executed by the processing circuitry for detecting an API endpoint, further configure the system to:

receive runtime data from a plurality of sensors, each sensor deployed on a workload in the cloud computing environment;

extract a plurality of API calls from the received runtime data; and

detect an API path from an extracted API call of the plurality of API calls.

18 . The system of claim 17 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

initiate inspection of a workload associated with the API path; and

detect an API endpoint of the plurality of API endpoints based on a result of the inspection and the detected API path.

19 . The system of claim 18 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

inspect the workload for a cybersecurity object, wherein the cybersecurity object indicates an application associated with the API path.

20 . The system of claim 19 , wherein the memory contains further instructions that, when executed by the processing circuitry for initiating inspection of a workload, further configure the system to:

initiate static analysis on a workload on which a sensor is deployed for a detection of an application related to the API call.

21 . The system of claim 12 , wherein the memory contains further instructions that, when executed by the processing circuitry for verifying the API endpoint, further configure the system to:

generate the network access instruction based on data extracted from an API call.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2025
From: TZABARY, OR; YARIV, IDO; COHEN, CFIR
To: WIZ, INC.
Reel/Frame 071373/0404 →
References Cited (14)
US 10063570B2 · Muddu et al. · 2018 [cited by applicant]
US 10917439B2 · Purathepparambil et al. · 2021 [cited by applicant]
US 11388186B2 · Srivastava · 2022 [cited by applicant]
US 11477219B2 · Jenkinson et al. · 2022 [cited by applicant]
US 11863573B2 · Tineo · 2024 [cited by applicant]
US 20180255089A1 · Wilton · 2018 [cited by examiner]
US 20210352136A1 · Dojka · 2021 [cited by examiner]
US 20210382986A1 · Lebin · 2021 [cited by examiner]
US 20230019180A1 · de Nijs et al. · 2023 [cited by applicant]
US 20240176892A1 · Mehta · 2024 [cited by examiner]
US 20240275808A1 · Lejin · 2024 [cited by examiner]
US 20240403437A1 · Szigeti · 2024 [cited by examiner]
US 20240403444A1 · Jeevagunta · 2024 [cited by examiner]
US 20240406201A1 · Khayat · 2024 [cited by examiner]