Invention Grant
US09258274B2 Using individualized APIs to block automated attacks on native apps and/or purposely exposed APIs
有权
使用个性化的API来阻止对本机应用程序和/或有意暴露的API的自动攻击
- Patent Title: Using individualized APIs to block automated attacks on native apps and/or purposely exposed APIs
- Patent Title (中): 使用个性化的API来阻止对本机应用程序和/或有意暴露的API的自动攻击
-
Application No.: US14327461Application Date: 2014-07-09
-
Publication No.: US09258274B2Publication Date: 2016-02-09
- Inventor: Marc Hansen
- Applicant: Shape Security, Inc.
- Applicant Address: US CA Palo Alto
- Assignee: SHAPE SECURITY, INC.
- Current Assignee: SHAPE SECURITY, INC.
- Current Assignee Address: US CA Palo Alto
- Agency: Davis Wright Tremaine LLP
- Agent Philip H. Albert
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
An API call filtering system filters responses to API call requests received, via a network, from user devices. The API call filtering system is configured to require personalized API call requests wherein each API call (except for some minor exceptions) includes a unique endpoint identifier (“UEID”) of the user device making the request. Using the UEID, the web service or other service protected by the API call filtering system can be secured against excessive request iterations from a set of rogue user devices while allowing for ordinary volumes of requests of requests the user devices, wherein one or more boundaries between what is deemed to be an ordinary volume of requests and what is deemed to be excessive request iterations are determined by predetermined criteria.
Public/Granted literature
- US20160014076A1 USING INDIVIDUALIZED APIS TO BLOCK AUTOMATED ATTACKS ON NATIVE APPS AND/OR PURPOSELY EXPOSED APIS Public/Granted day:2016-01-14
Information query