| CPC G06F 21/606 (2013.01) [G06F 9/54 (2013.01); G06F 40/211 (2020.01); G06F 40/30 (2020.01)] | 20 Claims |

|
1. A method comprising:
during runtime of an application, intercepting a first application programming interface (API) call directed to a first software component and from a second software component, wherein the application includes the first and second software components in an application layer;
comparing the first API call to a stored set of policies, wherein the set of policies sets out either or both of allowed API call content and disallowed API call content;
determining that the first API call is allowed based on the set of policies; and
allowing a first requested action of the first API call to be performed.
|