The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Apr. 12, 2022

Filed:

Dec. 26, 2018
Applicant:

International Business Machines Corporation, Armonk, NY (US);

Inventors:

Xuejie Yu, Kassel, DE;

Matthias Bartelt, Kassel, DE;

Manuel Hauptmann, Kassel, DE;

Ronald Williams, Austin, TX (US);

Lidiya Mekbib Tilahun, Kassel, DE;

Archana Kumari, Kassel, DE;

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
G06F 9/54 (2006.01); G06N 3/08 (2006.01); H04L 29/06 (2006.01);
U.S. Cl.
CPC ...
H04L 63/1425 (2013.01); G06F 9/54 (2013.01); G06N 3/08 (2013.01); H04L 63/20 (2013.01);
Abstract

Unauthenticated client access to an application (e.g., a SaaS-based web application) that employs unauthenticated API endpoints is monitored and protected by an access control system and method that leverages a neural network. The neural network is trained to recognize user behaviors that should be deemed to be 'inappropriate' according to a policy. Using the neural network, the system provides effective discrimination with respect to unauthenticated user behavior, and it enables access controls to be more effectively enforced with respect to users that are not using the application according to an enterprise security policy. By training the neural network to recognize pattern(s) behind regular user behavior, the approach enables robust access control with respect to users that are unauthenticated. More generally, the approach facilitates access control based in whole or in part on API interactions with an application where the identity of the individuals making that access are unknown or necessarily ascertainable.


Find Patent Forward Citations

Loading…