Services for data provisioning can be extremely valuable. Organizations wrestle with deciding whether to “expose or not to expose” their data through Web APIs and, depending on the nature of their business, mull over potential benefits and drawbacks. This is because data can be exploited and misused in unanticipated ways. Rate restriction techniques are frequently used to manage data access and protect back-end computing resources. The best choice for the maximum rate at which information can be “safely” provided to clients will determine its effectiveness. An important situation involves formal service-level agreements that govern the quality of services provided by public governments and private businesses. These firms might need to decide on a rate cap for their Web APIs that prevents unauthorized clients from accurately calculating service levels while still enabling the development of valuable value-added services. In this paper, we propose a statistical model for this problem and a technique, based on sampling tools, following brute-force, binary search, and heuristic search methods, to select an appropriate rate limit, and demonstrate its validity through a case study involving a large Italian bus company.
An Adaptive Toolbox for Computing Throttling Rate Limits in Web APIs / Arman, A., Monticelli, M., Firmani, D., Leotta, F., Mecella, M.. - In: IEEE TRANSACTIONS ON SERVICES COMPUTING. - ISSN 1939-1374. - 19:1(2026), pp. 141-152. [10.1109/tsc.2025.3633389]
An Adaptive Toolbox for Computing Throttling Rate Limits in Web APIs
Arman, Ala;Firmani, Donatella
;Leotta, Francesco
;Mecella, Massimo
2026
Abstract
Services for data provisioning can be extremely valuable. Organizations wrestle with deciding whether to “expose or not to expose” their data through Web APIs and, depending on the nature of their business, mull over potential benefits and drawbacks. This is because data can be exploited and misused in unanticipated ways. Rate restriction techniques are frequently used to manage data access and protect back-end computing resources. The best choice for the maximum rate at which information can be “safely” provided to clients will determine its effectiveness. An important situation involves formal service-level agreements that govern the quality of services provided by public governments and private businesses. These firms might need to decide on a rate cap for their Web APIs that prevents unauthorized clients from accurately calculating service levels while still enabling the development of valuable value-added services. In this paper, we propose a statistical model for this problem and a technique, based on sampling tools, following brute-force, binary search, and heuristic search methods, to select an appropriate rate limit, and demonstrate its validity through a case study involving a large Italian bus company.I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.


