Patents by Inventor Abraham Jeevagunta
Abraham Jeevagunta has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Publication number: 20260203419Abstract: Various embodiments facilitate Application Programming Interface (APIs) testing. In some examples, an apparatus detects security vulnerabilities in an API. The apparatus comprises one or more computer-readable storage media, a processing system operatively coupled with the one or more computer-readable storage media, and program instructions stored on the one or more computer-readable storage media. When executed by the processing system, the program instructions direct the processing system to perform operations. The apparatus monitors API traffic and responsively generates contextual information that characterizes the operations of the API. The apparatus generates an API test based on the contextual information to detect the security vulnerabilities in the API. The apparatus executes the API test on the API. The apparatus generates test results that indicate detected security vulnerabilities in the API. The processing system exports the test results.Type: ApplicationFiled: March 13, 2026Publication date: July 16, 2026Inventors: Shreyans Mehta, Abraham Jeevagunta
-
Patent number: 12596810Abstract: Various embodiments facilitate Application Programming Interface (APIs) testing. In some examples, an apparatus detects security vulnerabilities in an API. The apparatus comprises one or more computer-readable storage media, a processing system operatively coupled with the one or more computer-readable storage media, and program instructions stored on the one or more computer-readable storage media. When executed by the processing system, the program instructions direct the processing system to perform operations. The apparatus monitors API traffic and responsively generates contextual information that characterizes the operations of the API. The apparatus generates an API test based on the contextual information to detect the security vulnerabilities in the API. The apparatus executes the API test on the API. The apparatus generates test results that indicate detected security vulnerabilities in the API. The processing system exports the test results.Type: GrantFiled: November 28, 2023Date of Patent: April 7, 2026Assignee: Cequence Security, Inc.Inventors: Shreyans Mehta, Abraham Jeevagunta
-
Publication number: 20260052168Abstract: Various embodiments facilitate uncovering an Application Programming Interface (API) attack surface for an organization. In some examples, an apparatus comprises storage media, a processing system, and program instructions stored on the storage media. The apparatus processes Domain Name System (DNS) data to determine a set of possible API servers. The apparatus determines a set of possible Uniform Resource Identifier (URI) paths that may lead to one or more actual API endpoints. The apparatus joins the set of possible API servers with the set of possible URI paths to generate a set of possible API Uniform Resource Locators (URLs). The apparatus performs an API-specific crawl of the set of possible API URLs by submitting API requests to the set of possible API URLs and analyzing responses to determine the one or more actual API endpoints and one or more actual API servers of the set of possible API servers.Type: ApplicationFiled: October 23, 2025Publication date: February 19, 2026Inventors: Abraham Jeevagunta, Shreyans Mehta
-
Publication number: 20250373656Abstract: Various embodiments include a system. The system comprises processing circuitry. The processing circuitry obtains an Application Programming Interface (API) call that is associated with a Large Language Model (LLM). The processing circuitry generates a feature vector that numerically represents data included in the API call associated with the LLM. The processing circuitry provides the feature vector to a security LLM trained to detect security threats to the LLM. The processing circuitry obtains an output from the security LLM that indicates a security threat to the LLM. The processing circuitry determines a security policy based on the security threat. The processing circuitry provides the security policy to a security proxy that screens the API call.Type: ApplicationFiled: May 28, 2025Publication date: December 4, 2025Inventors: Abraham Jeevagunta, Rohit Unnikrishnan, Khyati Ganatra, Shreyans Mehta
-
Patent number: 12476995Abstract: Various embodiments facilitate uncovering an Application Programming Interface (API) attack surface for an organization. In some examples, an apparatus comprises storage media, a processing system, and program instructions stored on the storage media. The apparatus processes Domain Name System (DNS) data to determine a set of possible API servers. The apparatus determines a set of possible Uniform Resource Identifier (URI) paths that may lead to one or more actual API endpoints. The apparatus joins the set of possible API servers with the set of possible URI paths to generate a set of possible API Uniform Resource Locators (URLs). The apparatus performs an API-specific crawl of the set of possible API URLs by submitting API requests to the set of possible API URLs and analyzing responses to determine the one or more actual API endpoints and one or more actual API servers of the set of possible API servers.Type: GrantFiled: September 13, 2023Date of Patent: November 18, 2025Assignee: Cequence Security, Inc.Inventors: Abraham Jeevagunta, Shreyans Mehta
-
Publication number: 20240403444Abstract: Various embodiments include a system that discovers hidden Application Programming Interfaces (APIs) and detects security vulnerabilities in the hidden APIs. The system accesses Cloud Security Posture Management (CSPM) logs and discovers APIs based on the logs. The system identifies additional APIs that are not present in the CSPM logs. The system initiates API calls using modified addresses for the discovered APIs to discover hidden APIs. The system tests the discovered APIs to determine attack surfaces in the discovered APIs. The system generates a report that identifies the discovered APIs and that indicates the attack surfaces.Type: ApplicationFiled: June 5, 2024Publication date: December 5, 2024Inventors: Abraham Jeevagunta, Shreyans Mehta, Subramanian Iyer, Ravindran Harigopan Nair
-
Publication number: 20240388601Abstract: Techniques to facilitate prevention of malicious attacks on a web service are disclosed herein. In at least one implementation, web resources associated with the web service are crawled to obtain information about internal and external web assets associated with the web service. Responses from the internal and external web assets are intercepted and content security policy headers are dynamically injected into the responses to determine internal and external dependency data associated with the internal and external web assets. The internal and external dependency data is processed with script reputation and domain reputation data to generate enriched dependency graph data. The enriched dependency graph data is analyzed to dynamically generate content security policies for the web service, and the dynamically generated content security policies are deployed to protect the web service.Type: ApplicationFiled: July 25, 2024Publication date: November 21, 2024Inventors: Abraham Jeevagunta, Shreyans Mehta
-
Patent number: 12074903Abstract: Techniques to facilitate prevention of malicious attacks on a web service are disclosed herein. In at least one implementation, web resources associated with the web service are crawled to obtain information about internal and external web assets associated with the web service. Responses from the internal and external web assets are intercepted and content security policy headers are dynamically injected into the responses to determine internal and external dependency data associated with the internal and external web assets. The internal and external dependency data is processed with script reputation and domain reputation data to generate enriched dependency graph data. The enriched dependency graph data is analyzed to dynamically generate content security policies for the web service, and the dynamically generated content security policies are deployed to protect the web service.Type: GrantFiled: July 28, 2021Date of Patent: August 27, 2024Assignee: CEQUENCE SECURITY, INCInventors: Abraham Jeevagunta, Shreyans Mehta
-
Publication number: 20240176892Abstract: Various embodiments facilitate Application Programming Interface (APIs) testing. In some examples, an apparatus detects security vulnerabilities in an API. The apparatus comprises one or more computer-readable storage media, a processing system operatively coupled with the one or more computer-readable storage media, and program instructions stored on the one or more computer-readable storage media. When executed by the processing system, the program instructions direct the processing system to perform operations. The apparatus monitors API traffic and responsively generates contextual information that characterizes the operations of the API. The apparatus generates an API test based on the contextual information to detect the security vulnerabilities in the API. The apparatus executes the API test on the API. The apparatus generates test results that indicate detected security vulnerabilities in the API. The processing system exports the test results.Type: ApplicationFiled: November 28, 2023Publication date: May 30, 2024Inventors: Shreyans Mehta, Abraham Jeevagunta
-
Publication number: 20240106852Abstract: Various embodiments facilitate uncovering an Application Programming Interface (API) attack surface for an organization. In some examples, an apparatus comprises storage media, a processing system, and program instructions stored on the storage media. The apparatus processes Domain Name System (DNS) data to determine a set of possible API servers. The apparatus determines a set of possible Uniform Resource Identifier (URI) paths that may lead to one or more actual API endpoints. The apparatus joins the set of possible API servers with the set of possible URI paths to generate a set of possible API Uniform Resource Locators (URLs). The apparatus performs an API-specific crawl of the set of possible API URLs by submitting API requests to the set of possible API URLs and analyzing responses to determine the one or more actual API endpoints and one or more actual API servers of the set of possible API servers.Type: ApplicationFiled: September 13, 2023Publication date: March 28, 2024Inventors: Abraham Jeevagunta, Shreyans Mehta
-
Publication number: 20220038468Abstract: Techniques to facilitate prevention of malicious attacks on a web service are disclosed herein. In at least one implementation, web resources associated with the web service are crawled to obtain information about internal and external web assets associated with the web service. Responses from the internal and external web assets are intercepted and content security policy headers are dynamically injected into the responses to determine internal and external dependency data associated with the internal and external web assets. The internal and external dependency data is processed with script reputation and domain reputation data to generate enriched dependency graph data. The enriched dependency graph data is analyzed to dynamically generate content security policies for the web service, and the dynamically generated content security policies are deployed to protect the web service.Type: ApplicationFiled: July 28, 2021Publication date: February 3, 2022Inventors: Abraham Jeevagunta, Shreyans Mehta