RSS Amplifier

API Security Newsletter · May 16, 2022

The API Security Newsletter - Issue #6

0
Sign in to vote or save

Filip Verloy · API Security Newsletter

APIs (application programming interfaces) are no longer just a technical detail of interest to computer scientists. Banks, for example, are launching API platforms, and we hear the term “API first” thrown around in discussions of business strategy. We’ve used APIs for decades so we decided to take a look at why they are seemingly more important now than ever. We’ll have more to say on APIs in coming months.

APIs (application programming interfaces) are no longer just a technical detail of interest to computer scientists. Banks, for example, are launching API platforms, and we hear the term “API first” thrown around in discussions of business strategy. We’ve used APIs for decades so we decided to take a look at why they are seemingly more important now than ever.

X avatar for @sdxcentral

SDxCentral News@sdxcentral

Check out: API Security Starts With Discovery, Not Gateways The challenge with discovering APIs is that there isn't typically one place to look for them, Gartner VP Mark O'Neill said. https://t.co/GetUwx5KLC

10:17 PM · Jan 18, 2023

There are three strategic steps to securing APIs, but the process cannot start with implementing an API gateway or other API security products. First, enterprises need to know exactly what they’re trying to secure, VP Analyst Mark O’Neill said during Gartner’s Application Innovation and Business Solutions Summit.

APIs bring tremendous value to businesses in every sector. However, the security model for APIs is problematic. What are the issues?

The security model for APIs is problematic. What are the issues facing CISOs trying to secure their APIs? In this article, you will learn about the current issues and how to tackle them.

Active Testing is now available on Noname's API Security Platform. The solution allows you to simulate more than 100 prebuilt attacks on APIs. Active

The solution supports API security during the development process. An important factor, because most API vulnerabilities originate from vulnerable configurations. The best precautions are taken during the development phase, not afterwards.

To build secure software, engineers need to consider the road not taken and incorporate greater security into our applications.

I’ve found that when you work with others, an engineering organization can significantly contribute to API security. But how we think about software makes it difficult to get started. There is an alternative perspective—a road not taken—that must be considered when it comes to securing endpoints from threat actors. 

The principle of least privilege has been around for some time. Here's how the new world of APIs can adopt a least privilege approach.

The idea of Least Privilege takes on a new level of importance when it comes to APIs because there are more sources of data and more developers in play. While tools like the OpenAPI Specification are helpful for standardization, they don’t really help when it comes to assigning appropriate permissions and privileges.

While GraphQL APIs are one of the hottest trends in API development, they are no magic bullet. You still have to write a lot of resolver-code, adjust your API to changing schemas, figure out database performance and handle security properly.

For our Q2 TechTalk, Noname Security experts joined the API Academy team for what was a most interesting discussion. Our team talked about API Security – not only from an API management perspective (i.e. locked down gateways, best practices, secured mobile apps) but also enterprise-wide API security tactics, as well as emerging threat vectors.

Industry advisors have repeatedly asked us to teach this class, because every modern business needs a web presence and there are far too few workers qualified to protect them from hackers. There are many jobs available for students who learn how to protect our healthcare, financial, and other confidential data from criminals, spies, and pranksters.

The Cloud Security Podcast from Google is a weekly news and interview show with insights from the cloud security community.

Why is API security hot now? What happened that made it a priority for many?  Is API security different from application security? Doesn't the first "A" in API stand for application?  What are the real threats to exposed APIs? APIs are designed for automated use, so how do you tell automated use from automated abuse / attack? What are the biggest challenges that companies are having with API security? What are the components of API security? Is there a “secure by default API”? API threat detection? Just like cloud in general, API misconfigurations seem to be leading to security problems, are APIs hard to configure securely for most organizations?

GraphQL threat framework used by security professionals to research security gaps in GraphQL implementations - GitHub - nicholasaleks/graphql-threat-matrix: GraphQL threat framework used by security professionals to research security gaps in GraphQL implementations

We kicked off a series on API authentication and authorization. Let's look more depth at how to shape your security strategy with some guiding questions.

Every approach to auth comes with tradeoffs, and considering all the possible pros and cons can be overwhelming. The best auth strategy is going to depend on many factors and will require in-depth conversations across your organization. 

In the video below Jeffrey Snover reminisces about going to lunch with his then CEO at Tivoli where he got the question "Do you want to be relevant?" It referred to working on products, and being really really good at it, that weren't moving the company forward in a meaningful way. The whole session is full of great lessons (although be aware of survivorship bias ofc) you should check it out.

Disclaimer: The author of this newsletter is employed by Noname Security, but this is not an official Nonane Security publication, the newsletter is meant to provide independent API Security News. I encourage you to reach out with comments and/or suggestions for the newsletter via https://twitter.com/filipv (DM’s are open).

No posts

Read the original on apisec.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.