IP Library › Granted Patent US 11,503,038
Granted Patent B1
US 11,503,038 · App. 17/559,993 · Granted Nov 15, 2022

Policy enforcement and visibility for IaaS and SaaS open APIs

Inventors: Krishna Narayanaswamy (Saratoga, CA); Venkataswamy Pathapati (Koduru Mandal, IN); Muhammed Shafeek (Bangalore, IN)
Assignee: Netskope, Inc.
H04L63/105G06F11/3089H04L43/028H04L63/029H04L63/0281H04L63/0853H04L63/1433H04L67/01H04L67/133G06F9/542
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,503,038
App. No.
17/559,993
Granted
Nov 15, 2022
Kind
B1
Abstract

The disclosed technology teaches keeping up with the deployment of APIs, so that Secure Access Service Edge (SASE) protection is afforded, parsing an OpenAPI specification for an API family, for identifying overall attributes of the API family. The method includes identifying resources with respective URIs within the API family and extracting usable attributes of the API resources, useful for building a connector, extracting per-activity attributes that correspond to core activities that trigger protective actions. The disclosed technology also includes applying a connector creator that performs actions including accessing a template for creating connector rules that recognize intercepted API calls and activities requested by the API calls, and that trigger the protective actions, using the template and the extracted attributes from the API resources, producing the connector rules, and storing the connector rules for use in processing intercepted APIs. Further taught is using the connector rules for the SASE protection.

Claims (44)

1. A method of keeping up with deployment of application programming interfaces (abbreviated APIs), so that Secure Access Service Edge (abbreviated SASE) protection is afforded, including:

parsing an OpenAPI specification for an API family, including:

identifying overall attributes of the API family;

identifying API resources with respective URIs within the API family; and

extracting usable attributes of the API resources, which are useful for building a connector, including extracting per-activity attributes that correspond to core activities that trigger protective actions;

applying a connector creator that performs actions including:

accessing a template for creating connector rules that recognize intercepted API calls and activities requested by the API calls, and that trigger the protective actions;

producing the connector rules using the template and the extracted attributes from the API resources; and

storing the connector rules for use in processing intercepted APIs; and

whereby the parsing and the applying the connector creator automates the generation of connectors.

2. The method of claim 1 , further including deploying the connector rules in deep packet inspection (DPI) proxies for processing the intercepted APIs.

3. The method of claim 1 , further including determining to use the connector rules based on a domain name in a uniform resource identifier (abbreviated URI) used to access the API.

4. The method of claim 1 , further including an operation identifier key usable to identify activities requested by the API calls.

5. The method of claim 4 , further including combining uniform resource locator (URL) endpoint information and at least part of a uniform resource identifier (abbreviated URI) for an API call to create an alternate operation identifier usable to identify activities requested by the API call.

6. The method of claim 1 , wherein the API family includes one of Amazon Web Services (abbreviated AWS), Google Cloud Platform (abbreviated GCP), Microsoft Azure, Alibaba Open Platform, IBM Cloud Platform and Cloud Oracle Platform.

7. The method of claim 1 , wherein the extracted usable attributes include a protocol field value, server domain and a base URI path of connector resources.

8. A tangible non-transitory computer readable storage medium, including program instructions loaded into memory that, when executed on processors, cause the processors to implement a method of keeping up with deployment of application programming interfaces (abbreviated APIs), so that Secure Access Service Edge (abbreviated SASE) protection is afforded, including:

parsing an OpenAPI specification for an API family, including:

identifying overall attributes of the API family;

identifying API resources with respective URIs within the API family; and

extracting usable attributes of the API resources, which are useful for building a connector, including extracting per-activity attributes that correspond to core activities that trigger protective actions;

applying a connector creator that performs actions including:

accessing a template for creating connector rules that recognize intercepted API calls and activities requested by the API calls, and that trigger the protective actions;

producing the connector rules using the template and the extracted attributes from the API resources; and

storing the connector rules for use in processing intercepted APIs; and

whereby the parsing and the applying the connector creator automates the generation of connectors.

9. The tangible non-transitory computer readable storage medium of claim 8 , further including deploying the connector rules in deep packet inspection (DPI) proxies for processing the intercepted APIs.

10. The tangible non-transitory computer readable storage medium of claim 8 , further including determining to use the connector rules based on a domain name in a uniform resource identifier (abbreviated URI) used to access the API.

11. The tangible non-transitory computer readable storage medium of claim 8 , further including an operation identifier key usable to identify activities requested by the API calls.

12. The tangible non-transitory computer readable storage medium of claim 11 , further including combining uniform resource locator (URL) endpoint information and at least part of a URI for an API call to create an alternate operation identifier usable to identify activities requested by the API calls.

13. The tangible non-transitory computer readable storage medium of claim 8 , wherein the extracted usable attributes include a protocol field value, server domain and a base URI path of connector resources.

14. A device for keeping up with deployment of application programming interfaces (abbreviated APIs), so that Secure Access Service Edge (abbreviated SASE) protection is afforded, the device including a processor, memory coupled to the processor, and computer instructions loaded into the memory that, when executed, cause the processor to implement a process that includes:

a parser that maps an OpenAPI specification for an API family, identifies overall attributes of the API family, identifies API resources with respective URIs within the API family, and extracts usable attributes of API resources, which are useful for building a connector, including per-activity attributes that correspond to core activities that trigger protective actions; and

a connector creator that

accesses a template for creating connector rules that recognize intercepted API calls and activities requested by the API calls, and that trigger the protective actions;

applies the template to the extracted attributes from the API resources to produce the connector rules; and

stores the connector rules for use in processing intercepted APIs; and

whereby the parsing and the applying the connector creator automates the generation of connectors.

15. The device of claim 14 , further including deploying the connector rules as at least one deep packet inspection (DPI) proxy for processing the intercepted APIs.

16. The device of claim 14 , further including determining to use the connector rules based on a domain name in a uniform resource identifier (abbreviated URI) used to access the API.

17. The device of claim 14 , further including an operation identifier key usable to identify activities requested by the API calls.

18. The device of claim 17 , further including combining uniform resource locator (URL) endpoint information and at least part of a URI for an API call to create an alternate operation identifier usable to identify activities requested by the API calls.

19. The device of claim 14 , wherein the API family includes one of Amazon Web Services (abbreviated AWS), Google Cloud Platform (abbreviated GCP), Microsoft Azure, Alibaba Open Platform, IBM Cloud Platform and Cloud Oracle Platform.

20. The device of claim 14 , wherein the extracted usable attributes include a protocol field value, server domain and a base URI path of connector resources.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 27, 2021
From: NARAYANASWAMY, KRISHNA; PATHAPATI, VENKATASWAMY; SHAFEEK, MUHAMMED
To: NETSKOPE, INC
Reel/Frame 058481/0067 →
Priority Claims (1)
IN 202141049114 · Oct 27, 2021 · national
Cited By (1)
US 12,609,934