Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

2/2/2018
10:40 AM
Connect Directly
Twitter
RSS
E-Mail
100%
0%

APIs Pose 'Mushrooming' Security Risk

As APIs grow in prominence, top security concerns include bots and authentication.

The application economy has now become the API economy. And as the importance of application programming interfaces (APIs) grows within the enterprise, organizations must keep their security top-of-mind, lest they put the entire software stack at risk.

Software is powering digital disruption today and the secret sauce to this success is not just the features of the software itself, but how well it integrates with other software. Integrations between internal applications across business groups, with external platforms and applications held by partners, and with other consumer-based applications on customer devices is what fuels business success today. APIs are the glue that holds all these integrations together.

But APIs deployed without security measures expose organizations to yet another class of attack vectors.

"APIs represent a mushrooming security risk because they expose multiple avenues for hackers to try to access a company's data," explains Terry Ray, CTO of Imperva. "To close the door on security risks and protect their customers, companies need to treat APIs with the same level of protection that they provide for their business-critical web applications.”

Nevertheless, APIs remain greatly important for business and IT strategy.

"The greatest revenue potential (APIs) provide is removing barriers to growing revenue by integrating platforms and apps so organizations can quickly launch new business models and scale fast," explains Louis Columbus, an enterprise software strategist and principal at IQMS, a manufacturing ERP vendor, in a Forbes piece last year.

What's more, APIs are also fueling new methods of developing and deploying software. As organizations seek means to deliver and tweak software faster, they're increasingly breaking up large monolithic code bases into smaller chunks of independent code called microservices. Advanced organizations develop applications using segmented microservices that fit together like bricks into a larger software structure, making it easier to execute quick changes to parts of the software without accidentally breaking something else in the code base. But these microservices must interface with one another, and it takes APIs to accomplish that.

According to a study out this week from Imperva, these trends in software strategy have translated to the kind of proliferation where the typical organization is managing an average of 363 APIs within their application ecosystem. So, the obvious question for cybersecurity is where do the risks lie? 

According to the survey, more than two-thirds of organizations expose APIs to the public in order to enable partners and external developers to hook into the power of their software. This kind of exposure may open up a world of business opportunity, but it also brings risk to the table. Among the 250 IT and security practitioners questioned, the biggest proportion - 39% - were most concerned about the risks that bots and DDoS attacks posed to APIs.

Nearly a quarter of respondents also expressed concerns about authentication enforcement, a tricky topic when it comes to allowing access to only some data within an application without exposing other sensitive data. A bank, for example, might want its application to easily interface with other consumer applications, but wouldn't want its credentials shared with those applications on sign-on. And that's just the start of the threat exposure.

Some 76% of organizations report that they currently treat API security differently than Web security. Only about 63% of organizations use a Web application firewall to secure their APIs. Approximately 63% also report using an API gateway, though that number does bump up to 80% for public-facing APIs. Meanwhile, fewer than half of organizations use runtime application self-protection (RASP) to prevent attackers from tampering with or reversing API code for future attacks.

"In their approach to API security, organizations exposing Web APIs must balance ease of access - to ensure adoption of APIs - with control - to prevent abuse or attacks," Gartner analysts Mark O'Neill, Dionisio Zumerle, and Jeremy D'Hoinne said in a recent report on API security strategy. "Like the bank robber attacking banks because 'that's where the money is,' the use of APIs to provide access to applications and to business-critical data has naturally led to API security incidents."

Related Content:

 

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
aumickmanuela
50%
50%
aumickmanuela,
User Rank: Strategist
2/7/2018 | 10:00:10 AM
Interesting post
Post is really interesting) I have never heard such interesting terms, thanks a lot )
Mobile Banking Malware Up 50% in First Half of 2019
Kelly Sheridan, Staff Editor, Dark Reading,  1/17/2020
Exploits Released for As-Yet Unpatched Critical Citrix Flaw
Jai Vijayan, Contributing Writer,  1/13/2020
Microsoft to Officially End Support for Windows 7, Server 2008
Kelly Sheridan, Staff Editor, Dark Reading,  1/13/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-7227
PUBLISHED: 2020-01-18
Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the source code of different functions of the web application via requests that lack certain mandatory parameters. This affects ifaces-diag.asp, system.asp, ...
CVE-2019-15625
PUBLISHED: 2020-01-18
A memory usage vulnerability exists in Trend Micro Password Manager 3.8 that could allow an attacker with access and permissions to the victim's memory processes to extract sensitive information.
CVE-2019-19696
PUBLISHED: 2020-01-18
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishi...
CVE-2019-19697
PUBLISHED: 2020-01-18
An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an attacker to gain elevated privileges and tamper with protected services by disabling or otherwise preventing them to start. An attacker must already have administr...
CVE-2019-20357
PUBLISHED: 2020-01-18
A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain persistence on a vulnerable system.