In today’s digital world, application programming interfaces (APIs) are at the heart of personal and professional Internet use. These enable a wide range of services, from mobile applications to Internet of Things (IoT) and banking.
APIs account for 70% of all web traffic observed by content delivery network provider Cloudflare. Akamai estimates this number to be 83% of all traffic they observe.
Additionally, API usage continues to grow: Salt Labs API Security State Report Q1 2023According to a study published in March 2023, the average number of APIs per customer increased by 82% from July 2021 to July 2022.
This makes APIs one of the main attack vectors, Contxt CEO Mayur Upadhyaya said in a presentation at Infosecurity Europe.
“First, vulnerable APIs can be exposed to the public internet, which can lead to countless identities and other known misconfigurations that make the OWASP APIs in the top 10. Next In addition, insufficient authorization of API endpoints can lead to various security issues.Finally, it can lead to developers sharing more data than necessary or reusing APIs for multiple purposes. , a permissive API poses a significant risk to the enterprise.”
However, Upadhyaya said API security solutions have not yet been widely adopted. “Because there is no explicit owner of his API within the company, there is usually no single stakeholder responsible for securing the API, and API security is often overlooked,” he said. Added.
As a result, API security solutions must comply with regulations such as the EU’s revised Payment Services Directive (PSD2) and standards such as the Payment Card Industry Data Security Standard (PCI DSS), primarily for financial services, It has only been adopted in highly regulated industries. ).
Thankfully, things are starting to change for the better these days, Upadhyaya continued.
For example, IoT security regulations such as the UK Product Security and Telecommunications Infrastructure (PSTI) Bill and the EU Cyber Resilience Act have recently been adopted. This means IoT manufacturers will have to comply with stricter security standards, including API protection provisions.
“Also, the OpenID Foundation’s Financial-Grade API (FAPI) project is starting to drive adoption, and we are trying to get pharmaceutical companies and medical institutions to adopt this project,” he said. Information security.
Recent concerns about cyber risks posed by supply chain attacks and generative AI also highlight just how important API security is.
“But if you want effective API security practices, you need to integrate it into a consistent API governance system within your organization. We have launched a free API maturity model that you can use to assess whether you are ready or not,” said Upadhyaya.
Contxt has been named one of the 14 finalists for the UK’s Most Innovative Cyber SMEs for 2023. Winners will be announced at Infosecurity Europe on June 21, 2023.