EP3471007B1

Methods and apparatus for analyzing sequences of application programming interface traffic to identify potential malicious actions

Abstract

This record has no abstract on file.

EP3471007B1, drawing sheet 1
Sheet 1 of 6

Term

12 yearsleft in the term

Expires 12 October 2038.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

14 claims: 2 independent, 12 dependent

  1. 1
    A non-transitory processor-readable medium storing code representing instructions to be executed by a processor (122), the code comprising code to cause the processor to:receive, from a client device (110), a set of application programming interface, API, calls (140) having a sequence;provide an indication associated with at least one API call from the set of API calls (140) as an input to a machine learning model to identify a predicted sequence of API calls associated with the at least one API call;calculate a plurality of consistency scores for each pair of API calls from the set of API calls (140) by comparing (1) a proximity within the sequence of a first API call in that pair of API calls to a second API call in that pair of API calls and (2) a proximity within the predicted sequence of the first API call in that pair of API calls to the second API call in that pair of API calls, each consistency score from the plurality of consistency scores for each pair of API calls being associated with a predetermined context;generate a combined consistency score for each pair of API calls by combining each consistency score from the plurality of consistency scores for that pair of API calls with remaining consistency scores from the plurality of consistency scores for that pair of API calls;identify, based on comparing the combined consistency scores for a plurality of pairs of API calls from the set of API calls to a predetermined threshold, that the client device (110) is operating in a malicious manner;and restrict API calls received from the client device (110) based on identifying that the client device (110) is operating in the malicious manner.
  2. 10
    An apparatus (120), comprising:a memory (124);and a processor (122) operatively coupled to the memory (124), the processor (122) configured to receive a first set of application programming interface, API, calls (140) before a first time, the processor (122) configured to train, using the first set of API calls (140), a machine learning model to predict sequences of API calls, the processor (122) configured to receive a second set of API calls at a second time after the first time, the second set of API calls having a sequence, the processor (122) configured to provide an indication associated with at least one API call from the second set of API calls as an input to the machine learning model to identify a predicted sequence of API calls associated with the at least one API call, the processor (122) configured to calculate a plurality of consistency scores for each pair of API calls from the second set of API calls by comparing (1) a proximity within the sequence of a first API call in that pair of API calls to a second API call in that pair of API calls and (2) a proximity within the predicted sequence of the first API call in that pair of API calls to the second API call in that pair of API calls, each consistency score from the plurality of consistency scores for each pair of API calls being associated with a predetermined context, the processor (122) configured to generate a combined consistency score for each pair of API calls by combining each consistency score from the plurality of consistency scores for that pair of API calls with remaining consistency scores from the plurality of consistency scores for that pair of API calls, the processor (122) configured to identify, based on comparing the combined consistency scores for a plurality of pairs of API calls from the second set of API calls to a predetermined threshold, that the second set of API calls is indicative of maliciousness, and the processor (122) configured to send a signal to implement a remedial action based on the second set of API calls being indicative of maliciousness.