SlideShare a Scribd company logo
1 of 13
Download to read offline
I Know What
You(r APIs) Did
Last Summer
Shannon Wilkinson
CEO, Tego Cyber Inc
โ€ข DDoS
โ€ข Injection Attacks
โ€ข Authentication Attacks
โ€ข Cross-Site Scripting (XSS)
โ€ข Parameter Tampering
โ€ข Man in the Middle (MiTM)
โ€ข Credential Stuffing
โ€ข Application Abuse
โ€ข Server-Side Request Forgery (SSRF)
Top 10 2023RC
โ€ข Broken Level Authorization
โ€ข Broken Authentication
โ€ข Broken Object Property Level Authorization
โ€ข Unrestricted Resource Consumption
โ€ข Broken Function Level Authorization
โ€ข Server Side Request Forgery
โ€ข Security Misconfiguration
โ€ข Lack of Protection from Automated Threats
โ€ข Improper Asset Management
โ€ข Unsafe Consumption of APIs
Top 10 2019
โ€ข Broken Level Authorization
โ€ข Broken User Authentication
โ€ข Excessive Data Exposure
โ€ข Lack of Resource & Rate Limiting
โ€ข Broken Function Level Authorization
โ€ข Mass Assignment
โ€ข Security Misconfiguration
โ€ข Injection
โ€ข Improper Asset Management
โ€ข Insufficient Logging & Monitoring
Where Do API
Threats Come
From?
โ€ข Bad Coding โ€“ QA, we donโ€™t need
no stinking QA!
โ€ข Poor Validation โ€“ Do you validate
your SSL certs to protect
traffic/data?
โ€ข Poor Authentication โ€“ Do you
require authentication?
โ€ข Automated Threats
โ€ข BOTSSSSSSSSSSSSSSSSSS!
โ€ข API Utilization โ€“ How much data
should be going out?
Where Are Your
APIs?
โ€ข How can you protect what you
donโ€™t know?
โ€ข You need to or you need
someone to perform a thorough
analysis of what APIs you have in
your environment.
โ€ข Itโ€™s not a One-And-Done
assessment, you need
continuous validation/testing
โ€ข Data Flow
โ€ข What is the normal flow of data?
โ€ข User Behavior
โ€ข Who/where/when/how?
โ€ข Expected Level of Errors
โ€ข KYAPIs โ€“ Know Your APIs
โ€ข What data is exposed?
โ€ข Are the endpoints secured?
โ€ข Do we have SSL and no HTTP redirects?
Thatโ€™s Not Normal -
Anomaly Detection
โ€ข Unusual Traffic
โ€ข Increased Traffic
โ€ข Unexpected API Calls
โ€ข Vulnerability Scanning
โ€ข 404/500 Errors
โ€ข Unusual User Behavior
โ€ข Extraordinary Traveler
โ€ข Repeated Failed Attempts
API Specific Rules
โ€ข Excessive API Calls
โ€ข Exceed Rate Limits
โ€ข You Do Rate Limit, Right?
Right?
โ€ข Unusual User/Data Behavior
โ€ข Schema Validation
โ€ข Add to Cart & Buy in Less
than X Timeframe (Bots!)
โ€ข Configuration Changes
โ€ข Suspicious Payloads/File
Transfer
โ€ข Scan with AV/EDR
โ€ข Developers
โ€ข Code Reviews
โ€ข Code Repository Reviews
โ€ข Code Vulnerability Scanning
โ€ข Documentation of API Endpoints
โ€ข SBOM (Software Bill of
Materials)
โ€ข Unmanaged APIs
โ€ข Vulnerable APIs (Log4j anyone?)
โ€ข What do 3rd Party APIs have access to?
โ€ข Protecting
Credentials/Authentication
โ€ข Public vs Private APIs
โ€ข Security Team / Audit & Compliance
โ€ข Policies & Procedures
โ€ข Assessments
โ€ข Attack Surface Management Tools
โ€ข AV/EDR on Endpoints/Servers
โ€ข WAFs
โ€ข Security Operations Center (SOC)
โ€ข Ingestion of API Security Logs
โ€ข Monitoring of API Activity through
SIEM/Data Lake
Nope, Not On My Watch!
โ€ข Monitoring
โ€ข OWASP Top API 10 โ€“ Insufficient Logging & Monitoring
โ€ข 200+ Days to Detect
โ€ข Detection by 3rd Party (Ouch, Embarrassing!)
โ€ข SIEM/Data Lake Platforms
โ€ข Comprehensive View โ€“ Attack Surface, WAFs, Endpoints
โ€ข Threat Intelligence / Correlation Tools
โ€ฆIf You
Enjoyed the
Presentation
Shannon Wilkinson โ€“ CEO โ€“ Tego Cyber Inc
https://tegocyber.com
shannon.wilkinson@tegocyber.com

More Related Content

Similar to APIsecure 2023 - Understanding and Identifying Threats Against APIs, Shannon Wilkinson

Wakanda and the top 5 security risks - JS.everyrwhere(2012) Europe
Wakanda and the top 5 security risks - JS.everyrwhere(2012) EuropeWakanda and the top 5 security risks - JS.everyrwhere(2012) Europe
Wakanda and the top 5 security risks - JS.everyrwhere(2012) Europe
Alexandre Morgaut
ย 
Security audit
Security auditSecurity audit
Security audit
Nicholas Davis
ย 
Security Audit
Security AuditSecurity Audit
Security Audit
Nicholas Davis
ย 
Octogence Profile
Octogence ProfileOctogence Profile
Octogence Profile
Octogence
ย 
Security testing presentation
Security testing presentationSecurity testing presentation
Security testing presentation
Confiz
ย 
Web application security & Testing
Web application security  & TestingWeb application security  & Testing
Web application security & Testing
Deepu S Nath
ย 

Similar to APIsecure 2023 - Understanding and Identifying Threats Against APIs, Shannon Wilkinson (20)

Data encryption for Ruby web applications - Dmytro Shapovalov (RUS) | Ruby Me...
Data encryption for Ruby web applications - Dmytro Shapovalov (RUS) | Ruby Me...Data encryption for Ruby web applications - Dmytro Shapovalov (RUS) | Ruby Me...
Data encryption for Ruby web applications - Dmytro Shapovalov (RUS) | Ruby Me...
ย 
Injecting simplicity not SQL RSA Europe 2010
Injecting simplicity not SQL RSA Europe 2010Injecting simplicity not SQL RSA Europe 2010
Injecting simplicity not SQL RSA Europe 2010
ย 
Wakanda and the top 5 security risks - JS.everyrwhere(2012) Europe
Wakanda and the top 5 security risks - JS.everyrwhere(2012) EuropeWakanda and the top 5 security risks - JS.everyrwhere(2012) Europe
Wakanda and the top 5 security risks - JS.everyrwhere(2012) Europe
ย 
Checkmarx meetup API Security - Solving security at scale - Ante Gulam
Checkmarx meetup API Security -  Solving security at scale - Ante GulamCheckmarx meetup API Security -  Solving security at scale - Ante Gulam
Checkmarx meetup API Security - Solving security at scale - Ante Gulam
ย 
The API Primer (OWASP AppSec Europe, May 2015)
The API Primer (OWASP AppSec Europe, May 2015)The API Primer (OWASP AppSec Europe, May 2015)
The API Primer (OWASP AppSec Europe, May 2015)
ย 
How to Test for The OWASP Top Ten
 How to Test for The OWASP Top Ten How to Test for The OWASP Top Ten
How to Test for The OWASP Top Ten
ย 
How to Harden the Security of Your .NET Website
How to Harden the Security of Your .NET WebsiteHow to Harden the Security of Your .NET Website
How to Harden the Security of Your .NET Website
ย 
Security audit
Security auditSecurity audit
Security audit
ย 
Security Audit
Security AuditSecurity Audit
Security Audit
ย 
The OWASP Zed Attack Proxy
The OWASP Zed Attack ProxyThe OWASP Zed Attack Proxy
The OWASP Zed Attack Proxy
ย 
Octogence Profile
Octogence ProfileOctogence Profile
Octogence Profile
ย 
Web security and OWASP
Web security and OWASPWeb security and OWASP
Web security and OWASP
ย 
Spa Secure Coding Guide
Spa Secure Coding GuideSpa Secure Coding Guide
Spa Secure Coding Guide
ย 
Enhancing your Security APIs
Enhancing your Security APIsEnhancing your Security APIs
Enhancing your Security APIs
ย 
Security testing presentation
Security testing presentationSecurity testing presentation
Security testing presentation
ย 
Geek Sync | Taking Control of Your Organizationโ€™s SQL Server Sprawl
Geek Sync | Taking Control of Your Organizationโ€™s SQL Server SprawlGeek Sync | Taking Control of Your Organizationโ€™s SQL Server Sprawl
Geek Sync | Taking Control of Your Organizationโ€™s SQL Server Sprawl
ย 
Hacker vs AI
Hacker vs AI Hacker vs AI
Hacker vs AI
ย 
API IN(SECURITY)
API IN(SECURITY)API IN(SECURITY)
API IN(SECURITY)
ย 
Web application security & Testing
Web application security  & TestingWeb application security  & Testing
Web application security & Testing
ย 
Make your Azure PaaS Deployment More Safe
Make your Azure PaaS Deployment More SafeMake your Azure PaaS Deployment More Safe
Make your Azure PaaS Deployment More Safe
ย 

More from apidays

More from apidays (20)

Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
ย 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
ย 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
ย 
Apidays New York 2024 - The secrets to Graph success, by Leah Hurwich Adler, ...
Apidays New York 2024 - The secrets to Graph success, by Leah Hurwich Adler, ...Apidays New York 2024 - The secrets to Graph success, by Leah Hurwich Adler, ...
Apidays New York 2024 - The secrets to Graph success, by Leah Hurwich Adler, ...
ย 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
ย 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
ย 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
ย 
Apidays New York 2024 - API Discovery - From Crawl to Run by Rob Dickinson, G...
Apidays New York 2024 - API Discovery - From Crawl to Run by Rob Dickinson, G...Apidays New York 2024 - API Discovery - From Crawl to Run by Rob Dickinson, G...
Apidays New York 2024 - API Discovery - From Crawl to Run by Rob Dickinson, G...
ย 
Apidays Singapore 2024 - Building with the Planet in Mind by Sandeep Joshi, M...
Apidays Singapore 2024 - Building with the Planet in Mind by Sandeep Joshi, M...Apidays Singapore 2024 - Building with the Planet in Mind by Sandeep Joshi, M...
Apidays Singapore 2024 - Building with the Planet in Mind by Sandeep Joshi, M...
ย 
Apidays Singapore 2024 - Connecting Cross Border Commerce with Payments by Gu...
Apidays Singapore 2024 - Connecting Cross Border Commerce with Payments by Gu...Apidays Singapore 2024 - Connecting Cross Border Commerce with Payments by Gu...
Apidays Singapore 2024 - Connecting Cross Border Commerce with Payments by Gu...
ย 
Apidays Singapore 2024 - Privacy Enhancing Technologies for AI by Mark Choo, ...
Apidays Singapore 2024 - Privacy Enhancing Technologies for AI by Mark Choo, ...Apidays Singapore 2024 - Privacy Enhancing Technologies for AI by Mark Choo, ...
Apidays Singapore 2024 - Privacy Enhancing Technologies for AI by Mark Choo, ...
ย 
Apidays Singapore 2024 - Blending AI and IoT for Smarter Health by Matthew Ch...
Apidays Singapore 2024 - Blending AI and IoT for Smarter Health by Matthew Ch...Apidays Singapore 2024 - Blending AI and IoT for Smarter Health by Matthew Ch...
Apidays Singapore 2024 - Blending AI and IoT for Smarter Health by Matthew Ch...
ย 
Apidays Singapore 2024 - OpenTelemetry for API Monitoring by Danielle Kayumbi...
Apidays Singapore 2024 - OpenTelemetry for API Monitoring by Danielle Kayumbi...Apidays Singapore 2024 - OpenTelemetry for API Monitoring by Danielle Kayumbi...
Apidays Singapore 2024 - OpenTelemetry for API Monitoring by Danielle Kayumbi...
ย 
Apidays Singapore 2024 - Connecting Product and Engineering Teams with Testin...
Apidays Singapore 2024 - Connecting Product and Engineering Teams with Testin...Apidays Singapore 2024 - Connecting Product and Engineering Teams with Testin...
Apidays Singapore 2024 - Connecting Product and Engineering Teams with Testin...
ย 
Apidays Singapore 2024 - The Growing Carbon Footprint of Digitalization and H...
Apidays Singapore 2024 - The Growing Carbon Footprint of Digitalization and H...Apidays Singapore 2024 - The Growing Carbon Footprint of Digitalization and H...
Apidays Singapore 2024 - The Growing Carbon Footprint of Digitalization and H...
ย 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
ย 
Apidays Singapore 2024 - API Monitoring x SRE by Ryan Ashneil and Eugene Wong...
Apidays Singapore 2024 - API Monitoring x SRE by Ryan Ashneil and Eugene Wong...Apidays Singapore 2024 - API Monitoring x SRE by Ryan Ashneil and Eugene Wong...
Apidays Singapore 2024 - API Monitoring x SRE by Ryan Ashneil and Eugene Wong...
ย 
Apidays Singapore 2024 - A nuanced approach on AI costs and benefits for the ...
Apidays Singapore 2024 - A nuanced approach on AI costs and benefits for the ...Apidays Singapore 2024 - A nuanced approach on AI costs and benefits for the ...
Apidays Singapore 2024 - A nuanced approach on AI costs and benefits for the ...
ย 
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu SubbuApidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
ย 
Apidays Singapore 2024 - How APIs drive business at BNP Paribas by Quy-Doan D...
Apidays Singapore 2024 - How APIs drive business at BNP Paribas by Quy-Doan D...Apidays Singapore 2024 - How APIs drive business at BNP Paribas by Quy-Doan D...
Apidays Singapore 2024 - How APIs drive business at BNP Paribas by Quy-Doan D...
ย 

Recently uploaded

Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
SUHANI PANDEY
ย 
Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...
Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...
Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...
SUHANI PANDEY
ย 
Call Girls in Prashant Vihar, Delhi ๐Ÿ’ฏ Call Us ๐Ÿ”9953056974 ๐Ÿ” Escort Service
Call Girls in Prashant Vihar, Delhi ๐Ÿ’ฏ Call Us ๐Ÿ”9953056974 ๐Ÿ” Escort ServiceCall Girls in Prashant Vihar, Delhi ๐Ÿ’ฏ Call Us ๐Ÿ”9953056974 ๐Ÿ” Escort Service
Call Girls in Prashant Vihar, Delhi ๐Ÿ’ฏ Call Us ๐Ÿ”9953056974 ๐Ÿ” Escort Service
9953056974 Low Rate Call Girls In Saket, Delhi NCR
ย 
Russian Call Girls Pune (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
Russian Call Girls Pune  (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...Russian Call Girls Pune  (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
Russian Call Girls Pune (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
SUHANI PANDEY
ย 
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
@Chandigarh #call #Girls 9053900678 @Call #Girls in @Punjab 9053900678
ย 

Recently uploaded (20)

Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
ย 
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
ย 
Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...
Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...
Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...
ย 
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
ย 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
ย 
Katraj ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
Katraj ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...Katraj ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...
Katraj ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
ย 
Real Escorts in Al Nahda +971524965298 Dubai Escorts Service
Real Escorts in Al Nahda +971524965298 Dubai Escorts ServiceReal Escorts in Al Nahda +971524965298 Dubai Escorts Service
Real Escorts in Al Nahda +971524965298 Dubai Escorts Service
ย 
APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53
ย 
Call Girls in Prashant Vihar, Delhi ๐Ÿ’ฏ Call Us ๐Ÿ”9953056974 ๐Ÿ” Escort Service
Call Girls in Prashant Vihar, Delhi ๐Ÿ’ฏ Call Us ๐Ÿ”9953056974 ๐Ÿ” Escort ServiceCall Girls in Prashant Vihar, Delhi ๐Ÿ’ฏ Call Us ๐Ÿ”9953056974 ๐Ÿ” Escort Service
Call Girls in Prashant Vihar, Delhi ๐Ÿ’ฏ Call Us ๐Ÿ”9953056974 ๐Ÿ” Escort Service
ย 
Enjoy NightโšกCall Girls Dlf City Phase 3 Gurgaon >เผ’8448380779 Escort Service
Enjoy NightโšกCall Girls Dlf City Phase 3 Gurgaon >เผ’8448380779 Escort ServiceEnjoy NightโšกCall Girls Dlf City Phase 3 Gurgaon >เผ’8448380779 Escort Service
Enjoy NightโšกCall Girls Dlf City Phase 3 Gurgaon >เผ’8448380779 Escort Service
ย 
Russian Call Girls Pune (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
Russian Call Girls Pune  (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...Russian Call Girls Pune  (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
Russian Call Girls Pune (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
ย 
(+971568250507 ))# Young Call Girls in Ajman By Pakistani Call Girls in ...
(+971568250507  ))#  Young Call Girls  in Ajman  By Pakistani Call Girls  in ...(+971568250507  ))#  Young Call Girls  in Ajman  By Pakistani Call Girls  in ...
(+971568250507 ))# Young Call Girls in Ajman By Pakistani Call Girls in ...
ย 
๐“€คCall On 7877925207 ๐“€ค Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
๐“€คCall On 7877925207 ๐“€ค Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...๐“€คCall On 7877925207 ๐“€ค Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
๐“€คCall On 7877925207 ๐“€ค Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
ย 
VVVIP Call Girls In Connaught Place โžก๏ธ Delhi โžก๏ธ 9999965857 ๐Ÿš€ No Advance 24HRS...
VVVIP Call Girls In Connaught Place โžก๏ธ Delhi โžก๏ธ 9999965857 ๐Ÿš€ No Advance 24HRS...VVVIP Call Girls In Connaught Place โžก๏ธ Delhi โžก๏ธ 9999965857 ๐Ÿš€ No Advance 24HRS...
VVVIP Call Girls In Connaught Place โžก๏ธ Delhi โžก๏ธ 9999965857 ๐Ÿš€ No Advance 24HRS...
ย 
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
ย 
Russian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl ServiceRussian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl Service
ย 
Busty DesiโšกCall Girls in Vasundhara Ghaziabad >เผ’8448380779 Escort Service
Busty DesiโšกCall Girls in Vasundhara Ghaziabad >เผ’8448380779 Escort ServiceBusty DesiโšกCall Girls in Vasundhara Ghaziabad >เผ’8448380779 Escort Service
Busty DesiโšกCall Girls in Vasundhara Ghaziabad >เผ’8448380779 Escort Service
ย 
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
ย 
All Time Service Available Call Girls Mg Road ๐Ÿ‘Œ โญ๏ธ 6378878445
All Time Service Available Call Girls Mg Road ๐Ÿ‘Œ โญ๏ธ 6378878445All Time Service Available Call Girls Mg Road ๐Ÿ‘Œ โญ๏ธ 6378878445
All Time Service Available Call Girls Mg Road ๐Ÿ‘Œ โญ๏ธ 6378878445
ย 
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
ย 

APIsecure 2023 - Understanding and Identifying Threats Against APIs, Shannon Wilkinson

  • 1. I Know What You(r APIs) Did Last Summer Shannon Wilkinson CEO, Tego Cyber Inc
  • 2.
  • 3. โ€ข DDoS โ€ข Injection Attacks โ€ข Authentication Attacks โ€ข Cross-Site Scripting (XSS) โ€ข Parameter Tampering โ€ข Man in the Middle (MiTM) โ€ข Credential Stuffing โ€ข Application Abuse โ€ข Server-Side Request Forgery (SSRF)
  • 4. Top 10 2023RC โ€ข Broken Level Authorization โ€ข Broken Authentication โ€ข Broken Object Property Level Authorization โ€ข Unrestricted Resource Consumption โ€ข Broken Function Level Authorization โ€ข Server Side Request Forgery โ€ข Security Misconfiguration โ€ข Lack of Protection from Automated Threats โ€ข Improper Asset Management โ€ข Unsafe Consumption of APIs Top 10 2019 โ€ข Broken Level Authorization โ€ข Broken User Authentication โ€ข Excessive Data Exposure โ€ข Lack of Resource & Rate Limiting โ€ข Broken Function Level Authorization โ€ข Mass Assignment โ€ข Security Misconfiguration โ€ข Injection โ€ข Improper Asset Management โ€ข Insufficient Logging & Monitoring
  • 5. Where Do API Threats Come From? โ€ข Bad Coding โ€“ QA, we donโ€™t need no stinking QA! โ€ข Poor Validation โ€“ Do you validate your SSL certs to protect traffic/data? โ€ข Poor Authentication โ€“ Do you require authentication? โ€ข Automated Threats โ€ข BOTSSSSSSSSSSSSSSSSSS! โ€ข API Utilization โ€“ How much data should be going out?
  • 6. Where Are Your APIs? โ€ข How can you protect what you donโ€™t know? โ€ข You need to or you need someone to perform a thorough analysis of what APIs you have in your environment. โ€ข Itโ€™s not a One-And-Done assessment, you need continuous validation/testing
  • 7. โ€ข Data Flow โ€ข What is the normal flow of data? โ€ข User Behavior โ€ข Who/where/when/how? โ€ข Expected Level of Errors โ€ข KYAPIs โ€“ Know Your APIs โ€ข What data is exposed? โ€ข Are the endpoints secured? โ€ข Do we have SSL and no HTTP redirects?
  • 8. Thatโ€™s Not Normal - Anomaly Detection โ€ข Unusual Traffic โ€ข Increased Traffic โ€ข Unexpected API Calls โ€ข Vulnerability Scanning โ€ข 404/500 Errors โ€ข Unusual User Behavior โ€ข Extraordinary Traveler โ€ข Repeated Failed Attempts
  • 9. API Specific Rules โ€ข Excessive API Calls โ€ข Exceed Rate Limits โ€ข You Do Rate Limit, Right? Right? โ€ข Unusual User/Data Behavior โ€ข Schema Validation โ€ข Add to Cart & Buy in Less than X Timeframe (Bots!) โ€ข Configuration Changes โ€ข Suspicious Payloads/File Transfer โ€ข Scan with AV/EDR
  • 10. โ€ข Developers โ€ข Code Reviews โ€ข Code Repository Reviews โ€ข Code Vulnerability Scanning โ€ข Documentation of API Endpoints โ€ข SBOM (Software Bill of Materials) โ€ข Unmanaged APIs โ€ข Vulnerable APIs (Log4j anyone?) โ€ข What do 3rd Party APIs have access to? โ€ข Protecting Credentials/Authentication โ€ข Public vs Private APIs
  • 11. โ€ข Security Team / Audit & Compliance โ€ข Policies & Procedures โ€ข Assessments โ€ข Attack Surface Management Tools โ€ข AV/EDR on Endpoints/Servers โ€ข WAFs โ€ข Security Operations Center (SOC) โ€ข Ingestion of API Security Logs โ€ข Monitoring of API Activity through SIEM/Data Lake
  • 12. Nope, Not On My Watch! โ€ข Monitoring โ€ข OWASP Top API 10 โ€“ Insufficient Logging & Monitoring โ€ข 200+ Days to Detect โ€ข Detection by 3rd Party (Ouch, Embarrassing!) โ€ข SIEM/Data Lake Platforms โ€ข Comprehensive View โ€“ Attack Surface, WAFs, Endpoints โ€ข Threat Intelligence / Correlation Tools
  • 13. โ€ฆIf You Enjoyed the Presentation Shannon Wilkinson โ€“ CEO โ€“ Tego Cyber Inc https://tegocyber.com shannon.wilkinson@tegocyber.com