IP Library › Granted Patent US 11,132,278
Granted Patent B2
US 11,132,278 · App. 16/531,393 · Granted Sep 28, 2021

Application programming interface security validation for system integration testing

Inventors: Scott E. Joyce (Foxboro, MA); Norman M. Miles (Bedford, MA); Munish T. Desai (Shrewsbury, MA); Yingying Wang Martin (Southborough, MA); Dan Yuan (Hopkinton, MA)
Assignee: EMC IP Holding Company LLC
G06F11/3604G06F9/54G06F21/54G06F21/577G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,132,278
App. No.
16/531,393
Granted
Sep 28, 2021
Kind
B2
Abstract

Techniques are provided to implement application programming interface (API) security validation testing for system integration testing (SIT) in a continuous integration environment. For example, a SIT tool detects a change in master code associated with an application comprising a plurality of microservices and an API gateway to route client API requests to the microservices of the application. The SIT tool obtains a listing of API endpoints exposed by the microservices of the application. The SIT tool performs an automated API security test validation process to determine whether an API security test file has been created for each API endpoint in the listing of API endpoints. The SIT tool fails the API security test validation process in response to determining that an API security test file has not be created for one or more API endpoints in the listing of API endpoints.

Claims (62)

1. A method, comprising:

detecting, by a system integration testing (SIT) tool, a change in master code associated with an application comprising a plurality of microservices and an application programming interface (API) gateway to route client API requests to the microservices of the application;

obtaining, by the SIT tool, a listing of API endpoints exposed by the microservices of the application; and

performing, by the SIT tool, an automated API security test validation process which comprises:

determining whether each API endpoint in the listing of API endpoints has an associated API security test file which has been created to test a security of the API endpoint;

generating a test failure indication in response to determining that an associated API security test file has not been created for one or more API endpoints in the listing of API endpoints;

in response to determining that each API endpoint in the listing of API endpoints has an associated API security test file, determining whether the associated API security test file of a given API endpoint in the listing of API endpoints comprises a test for validating at least one element of the given API endpoint; and

generating a test failure indication in response to determining that the associated API security test file of the given API endpoint does not comprise a test for validating at least one element of the given API endpoint.

2. The method of claim 1 , wherein obtaining the listing of API endpoints comprises the SIT tool issuing an API request to the API gateway to obtain the listing of API endpoints.

3. The method of claim 2 , wherein the listing of API endpoints comprises a whitelist of permitted API endpoints of registered microservices of the application, which is generated by the API gateway.

4. The method of claim 1 , wherein:

determining whether the associated API security test file of the given API endpoint in the listing of API endpoints comprises a test for validating at least one element of the given API endpoint comprises determining whether the associated API security test file for the given API endpoint specifies a validation test for each parameter of the given API endpoint; and

generating a test failure indication in response to determining that the associated API security test file of the given API endpoint does not comprise a test for validating at least one element of the given API endpoint comprises generating a test failure indication in response to determining that the associated API security test file for the given API endpoint does not specify a validation test for at least one parameter of the given API endpoint.

5. The method of claim 1 , wherein:

determining whether the associated API security test file of the given API endpoint in the listing of API endpoints comprises a test for validating at least one element of the given API endpoint comprises determining whether the associated API security test file for the given API endpoint specifies a validation test for each method of the given API endpoint; and

generating a test failure indication in response to determining that the associated API security test file of the given API endpoint does not comprise a test for validating at least one element of the given API endpoint comprises generating a test failure indication in response to determining that the associated API security test file for the given API endpoint does not specify a validation test for at least one method of the given API endpoint.

6. The method of claim 1 , comprising:

in response to determining that each API endpoint in the listing of API endpoints has an associated API security test file, the SIT tool continuing the automated API security test validation process by:

performing a test procedure on the given API endpoint to determine whether the given API is behaving properly, wherein the test procedure comprises (i) generating an invalid API request for the given API endpoint, and (ii) passing the invalid API request to the given API endpoint to determine whether the given API endpoint accepts or rejects the invalid API request; and

generating a test failure indication in response to determining that the given API endpoint accepts the invalid API request.

7. The method of claim 6 , wherein generating the invalid API request for the given API endpoint comprises generating an API request with at least one of an invalid parameter and an invalid parameter value.

8. The method of claim 6 , wherein generating the invalid API request for the given API endpoint comprises generating an API request with an invalid method that is not supported by the given API endpoint.

9. The method of claim 6 , wherein generating the invalid API request for the given API endpoint comprises generating an API request with a size that exceeds a predefined threshold.

10. An article of manufacture comprising a non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code is executable by one or more processors to implement a method comprising:

detecting, by a system integration testing (SIT) tool, a change in master code associated with an application comprising a plurality of microservices and an application programming interface (API) gateway to route client API requests to the microservices of the application;

obtaining, by the SIT tool, a listing of API endpoints exposed by the microservices of the application; and

performing, by the SIT tool, an automated API security test validation process which comprises:

determining whether each API endpoint in the listing of API endpoints has an associated API security test file which has been created to test a security of the API endpoint;

generating a test failure indication in response to determining that an associated API security test file has not been created for one or more API endpoints in the listing of API endpoints;

in response to determining that each API endpoint in the listing of API endpoints has an associated API security test file, determining whether the associated API security test file of a given API endpoint in the listing of API endpoints comprises a test for validating at least one element of the given API endpoint; and

generating a test failure indication in response to determining that the associated API security test file of the given API endpoint does not comprise a test for validating at least one element of the given API endpoint.

11. The article of manufacture of claim 10 , wherein obtaining the listing of API endpoints comprises the SIT tool issuing an API request to the API gateway to obtain the listing of API endpoints.

12. The article of manufacture of claim 11 , wherein the listing of API endpoints comprises a whitelist of permitted API endpoints of registered microservices of the application, which is generated by the API gateway.

13. The article of manufacture of claim 10 , wherein:

the program code for determining whether the associated API security test file of the given API endpoint in the listing of API endpoints comprises a test for validating at least one element of the given API endpoint comprises program code for determining whether the associated API security test file for the given API endpoint specifies a validation test for each parameter of the given API endpoint; and

the program code for generating a test failure indication in response to determining that the associated API security test file of the given API endpoint does not comprise a test for validating at least one element of the given API endpoint comprises program code for generating a test failure indication in response to determining that the associated API security test file for the given API endpoint does not specify a validation test for at least one parameter of the given API endpoint.

14. The article of manufacture of claim 10 , wherein:

the program code for determining whether the associated API security test file of the given API endpoint in the listing of API endpoints comprises a test for validating at least one element of the given API endpoint comprises program code for determining whether the associated API security test file for the given API endpoint specifies a validation test for each method of the given API endpoint; and

the program code for generating a test failure indication in response to determining that the associated API security test file of the given API endpoint does not comprise a test for validating at least one element of the given API endpoint comprises program code for generating a test failure indication in response to determining that the associated API security test file for the given API endpoint does not specify a validation test for at least one method of the given API endpoint.

15. The article of manufacture of claim 10 , wherein the program code is executable by the one or more processors to implement a method comprising:

in response to determining that each API endpoint in the listing of API endpoints has an associated API security test file, the SIT tool continuing the automated API security test validation process by:

performing a test procedure on the given API endpoint to determine whether the given API is behaving properly, wherein the test procedure comprises (i) generating an invalid API request for the given API endpoint, and (ii) passing the invalid API request to the given API endpoint to determine whether the given API endpoint accepts or rejects the invalid API request; and

generating a test failure indication in response to determining that the given API endpoint accepts the invalid API request.

16. The article of manufacture of claim 15 , wherein generating the invalid API request for the given API endpoint comprises generating an API request with at least one of an invalid parameter and an invalid parameter value.

17. The article of manufacture of claim 15 , wherein generating the invalid API request for the given API endpoint comprises generating an API request with an invalid method that is not supported by the given API endpoint.

18. The article of manufacture of claim 15 , wherein generating the invalid API request for the given API endpoint comprises generating an API request with a size that exceeds a predefined threshold.

19. A server node, comprising:

at least one processor; and

system memory configured to store program code, wherein the program code is executable by the at least one processor to instantiate systems integration testing (SIT) tool, wherein the SIT tool is configured to:

detect a change in master code associated with an application comprising a plurality of microservices and an application programming interface (API) gateway to route client API requests to the microservices of the application;

obtain a listing of API endpoints exposed by the microservices of the application; and

perform an automated API security test validation process, wherein in performing the automated API security test validation process, the SIT is configured to:

determine whether each API endpoint in the listing of API endpoints has an associated API security test file which has been created to test a security of the API endpoint;

generate a test failure indication response to determining that an associated API security test file has not been created for one or more API endpoints in the listing of API endpoints;

in response to determining that each API endpoint in the listing of API endpoints has an associated API security test file, determine whether the associated API security test file of a given API endpoint in the listing of API endpoints comprises a test for validating at least one element of the given API endpoint; and

generate a test failure indication in response to determining that the associated API security test file of the given API endpoint does not comprise a test for validating at least one element of the given API endpoint.

20. The server node of claim 19 , wherein:

in determining whether the associated API security test file of a given API endpoint in the listing of API endpoints comprises a test for validating at least one element of the given API endpoint the SIT tool is configured to:

determine whether the associated API security test file for the given API endpoint specifies a validation test for each parameter of the given API endpoint, and generate a test failure indication in response to determining that the associated API security test file for the given API endpoint does not specify a validation test for at least one parameter of the given API endpoint; and

determine whether the associated API security test file for the given API endpoint specifies a validation test for each method of the given API endpoint, and generate a test failure indication in response to determining that the associated API security test file for the given API endpoint does not specify a validation test for at least one method of the given API endpoint; and

the SIT tool is further configured to perform a test procedure on the given API endpoint to determine whether the given API is behaving properly, wherein the test procedure comprises (i) generating an invalid API request for the given API endpoint, and (ii) passing the invalid API request to the given API endpoint to determine whether the given API endpoint accepts or rejects the invalid API request; and

generate a test failure indication in response to determining that the given API endpoint accepts the invalid API request.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (051302/0528) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.); SECUREWORKS CORP.
Reel/Frame 060438/0593 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST AT REEL 051449 FRAME 0728 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.; EMC CORPORATION
Reel/Frame 058002/0010 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Dec 31, 2019
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.; EMC CORPORATION
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 051449/0728 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Dec 16, 2019
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 051302/0528 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 6, 2019
From: JOYCE, SCOTT E.; MILES, NORMAN M.; DESAI, MUNISH T.; MARTIN, YINGYING WANG; YUAN, DAN
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 049966/0361 →
Continuity (1)
Related Publication 20210042207A1 · Feb 11, 2021
Cited By (2)
US 12,664,005 US 12,705,366