APIs (application programming interfaces) are no longer just a technical detail of interest to computer scientists. Banks, for example, are launching API platforms, and we hear the term “API first” thrown around in discussions of business strategy. We’ve used APIs for decades so we decided to take a look at why they are seemingly more important now than ever.
SDxCentral News@sdxcentral
Check out: API Security Starts With Discovery, Not Gateways The challenge with discovering APIs is that there isn't typically one place to look for them, Gartner VP Mark O'Neill said. https://t.co/GetUwx5KLC
10:17 PM · Jan 18, 2023
There are three strategic steps to securing APIs, but the process cannot start with implementing an API gateway or other API security products. First, enterprises need to know exactly what they’re trying to secure, VP Analyst Mark O’Neill said during Gartner’s Application Innovation and Business Solutions Summit.
The security model for APIs is problematic. What are the issues facing CISOs trying to secure their APIs? In this article, you will learn about the current issues and how to tackle them.
The solution supports API security during the development process. An important factor, because most API vulnerabilities originate from vulnerable configurations. The best precautions are taken during the development phase, not afterwards.
I’ve found that when you work with others, an engineering organization can significantly contribute to API security. But how we think about software makes it difficult to get started. There is an alternative perspective—a road not taken—that must be considered when it comes to securing endpoints from threat actors.
The idea of Least Privilege takes on a new level of importance when it comes to APIs because there are more sources of data and more developers in play. While tools like the OpenAPI Specification are helpful for standardization, they don’t really help when it comes to assigning appropriate permissions and privileges.
While GraphQL APIs are one of the hottest trends in API development, they are no magic bullet. You still have to write a lot of resolver-code, adjust your API to changing schemas, figure out database performance and handle security properly.
For our Q2 TechTalk, Noname Security experts joined the API Academy team for what was a most interesting discussion. Our team talked about API Security – not only from an API management perspective (i.e. locked down gateways, best practices, secured mobile apps) but also enterprise-wide API security tactics, as well as emerging threat vectors.
Why is API security hot now? What happened that made it a priority for many? Is API security different from application security? Doesn't the first "A" in API stand for application? What are the real threats to exposed APIs? APIs are designed for automated use, so how do you tell automated use from automated abuse / attack? What are the biggest challenges that companies are having with API security? What are the components of API security? Is there a “secure by default API”? API threat detection? Just like cloud in general, API misconfigurations seem to be leading to security problems, are APIs hard to configure securely for most organizations?
Every approach to auth comes with tradeoffs, and considering all the possible pros and cons can be overwhelming. The best auth strategy is going to depend on many factors and will require in-depth conversations across your organization.
In the video below Jeffrey Snover reminisces about going to lunch with his then CEO at Tivoli where he got the question "Do you want to be relevant?" It referred to working on products, and being really really good at it, that weren't moving the company forward in a meaningful way. The whole session is full of great lessons (although be aware of survivorship bias ofc) you should check it out.
Disclaimer: The author of this newsletter is employed by Noname Security, but this is not an official Nonane Security publication, the newsletter is meant to provide independent API Security News. I encourage you to reach out with comments and/or suggestions for the newsletter via https://twitter.com/filipv (DM’s are open).
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.