首页> 外国专利> DYNAMIC, RUNTIME APPLICATION PROGRAMMING INTERFACE PARAMETER LABELING, FLOW PARAMETER TRACKING AND SECURITY POLICY ENFORCEMENT

DYNAMIC, RUNTIME APPLICATION PROGRAMMING INTERFACE PARAMETER LABELING, FLOW PARAMETER TRACKING AND SECURITY POLICY ENFORCEMENT

机译:动态,运行时应用程序编程接口参数标签,流程参数跟踪和安全策略执行

摘要

A dynamic API security policy is enforced at runtime. This can be done without having access to the API specification or code. A flow of execution initiated by the API is tracked at runtime, and a data object used by the API is identified. Specific data labels are assigned to specific fields of the data object used by the API. The specific data labels consistently identify data fields of specific types. The API security policy that is enforced prohibits specific actions concerning data fields of specific types, which are also consistently identified in the security policy. Actions in the tracked flow of execution that violate the API security policy are detected at runtime, and security actions are taken in response. In some implementations, these dynamic API security techniques are supplemented with static API security analysis of an API specification and a set of rules concerning API risk assessment.
机译:在运行时强制执行动态API安全策略。 这可以在不访问API规范或代码的情况下完成。 在运行时跟踪由API发起的执行流程,并识别API使用的数据对象。 将特定的数据标签分配给API使用的数据对象的特定字段。 特定数据标签一致地识别特定类型的数据字段。 强制执行的API安全策略禁止有关特定类型的数据字段的特定操作,这些类型也在安全策略中一致地识别。 在运行时检测到违反API安全策略的跟踪执行流程中的操作,并响应安全操作。 在一些实现中,这些动态API安全技术补充了API规范的静态API安全性分析以及关于API风险评估的一组规则。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号