SlideShare uma empresa Scribd logo
1 de 13
Baixar para ler offline
THE IMPORTANCE OF REAL-TIME
PROTECTION IN API SECURITY
Jeremy Ventura
Field CISO
AGENDA
Copyrights 2
The key challenges and risk
associated with API Security
Case Studies from ThreatX
The importance of real-time
blocking
APIS REPRESENT A TARGET RICH ENVIRONMENT
• Thousands of APIs and
endpoints with limited visibility
• API vulnerabilities easily
exposed and discoverable
• Attackers continually leverage
advanced techniques against
APIs
• Multi-mode attacks becoming
the norm
3
Increased Usage = Increased Risk
APIS IN THE NEWS
• Entity had access from November to
January to an API
• Data attained via API was done
“without authorization”
• Name, Address, Email, Phone,
DoB, Account #
• 37 million end users affected
• More info to come but:
• Lack of visibility?
• Misconfiguration/Misuse?
• Broken business logic?
• Stolen Credentials?
4
Incidents & Breaches on the Rise
COMPLEXITY & AUTOMATION OF ATTACKS IS EVER INCREASING
5
• Hacking is easier than ever
• Industrialized hacking tools
• Rent-a-bot/Solver Services
• Attack-as-a-Service
• Residential proxies, anonymizers
• Advanced attacks are far more
coordinated
• Security tools do not keep up
Multi-mode attacks require a fundamental shift in protection strategies
Traditional
OWASP Top 10
Sophisticated,
multi-mode
attacks
THE THREAT OF MULTI-VECTOR ATTACKS
6
• Orchestrated attacks that span
varied phases & techniques
• Distributed IPs
• Massive volumes
• Diversionary tactics
• Embedded, multi-step
automation
Disguise true attack through diversion, distraction & evasion
A WORD ABOUT BOTS
7
• Bot management critical, but must
evolve with attacks
• Current approaches best suited for high
volume, binary attacks
• Heavy reliance on static threat intel
feeds
• APIs present new challenges
• No browser injections
• No Captcha or IP challenges
• Attacker profiling & behavioral context
critical for protection against multi-
mode attacks
Bots present a new challenge to protecting APIs
TALES FROM THE THREATX SOC
8
• Large online retailer taking fire from
multiple directions
• Periodic mid-grade DDoS attacks
• Increased login failure rates on web
• High rate of rebate fraud
• Goal: trigger BGP routing to bypass
fraud protection for mobile APIs while
the security team is distracted
• Multiple best-of-breed technologies
fail to identify & block attacks
Attackers deploy multiple techniques to distract security & target APIs
TALES FROM THE THREATX SOC
9
• Gaming company launching new
product
• Attacker engaged foreign botnet to
discover potentially vulnerable API
endpoints
• Later during product launch, attacker
deployed large ATO attack while
quietly attempting vulnerability
exploits
• Although rotating IPs and user agents,
TLS signatures & IP fingerprints
detected same attacker profile to
block all suspicious behavior
Tracking & correlating attacker behavior – to enable real-time protection
PROTECTING APIS STARTS WITH FOCUS ON THE ATTACKER
10
• Understanding attacker risk profile
• Digital fingerprints to each unique
attacker
• Cumulative across multiple attack
vectors
• Continually evaluate risk &
response
• Behavioral fingerprints of an attack
reveal patterns, techniques &
targets
Context of attack over time is key to protecting APIs
INSIGHT & CONTEXT THROUGH CROSS PLATFORM VISIBILITY
11
• Identify unique attacker
executing campaigns across
multiple methods and vectors
• Correlate data over time to see
through deception
• Understanding behaviors and
intentions
• Biggest challenge = enabling
effective response
Correlating attack patterns to identify and mitigate API risk
BLOCKING API ATTACKS IN REAL TIME
12
• Observing attack data offline will not
enable real-time protection of APIs
• Often too late by the time an attack is
discovered
• Complexity required to identify attacks
typically can’t be replicated in 3rd party
firewall
• Blocking single IP at a time
• Responses must occur as the attack
is underway – and based on insights
gathered over time
Real-time API protection key to defense
API PROTECTION: KEY CAPABILITIES
13
Real-time Analysis
& Response
• AI/ML/Context Engine
• IP Interrogation &
Fingerprinting
• Active Deception
• Tarpit/Rate Limiting
• Attacker/User Behavior
Analysis
• Data Flow Analysis &
Enforcement
• Real-time Blocking
13
API Discovery &
Analysis
• API Discovery
• API Specification Mgt
• Endpoint Usage Analysis
• Endpoint Attack Metrics
• Endpoint Risk Scoring
Fully Integrated
Attack Prevention
• API Protection
• Web App Protection
• DDoS Protection
• Bot Mgt & Mitigation
• Fraud Protection
Flexible
Deployment
Options
• Inline / Agentless
• Inline / Agent-based
• Out-of-Band / Agentless
• Hosted, Cloud, On-Premise
Managed Services
• Managed Cloud Platform
• Managed Threat Analysis
• Managed Policy Enforcement
• Managed Attack Response
• APIs are under siege – by mixed-mode, high volume attacks, including bots and DDoS
• API observability does not = real-time protection
• API protection must deliver active, real-time attack blocking
• API protection should have ability to extend to broader application portfolio
Can’t block?
Then you’re not protecting APIs.

Mais conteúdo relacionado

Semelhante a APIsecure 2023 - The Importance of Real-Time Protection in API Security, Jeremy Ventura (ThreatX)

API Security - Everything You Need to Know To Protect Your APIs
API Security - Everything You Need to Know To Protect Your APIsAPI Security - Everything You Need to Know To Protect Your APIs
API Security - Everything You Need to Know To Protect Your APIs
AaronLieberman5
 
F5 XC Distributed cloud Security and Application Delievery
F5 XC Distributed cloud Security and Application DelieveryF5 XC Distributed cloud Security and Application Delievery
F5 XC Distributed cloud Security and Application Delievery
stkannan1
 
Layered API Security: What Hackers Don't Want You To Know
Layered API Security: What Hackers Don't Want You To KnowLayered API Security: What Hackers Don't Want You To Know
Layered API Security: What Hackers Don't Want You To Know
AaronLieberman5
 

Semelhante a APIsecure 2023 - The Importance of Real-Time Protection in API Security, Jeremy Ventura (ThreatX) (20)

2022 APIsecure_API Security & Fraud Detection - Are you ready?
2022 APIsecure_API Security & Fraud Detection - Are you ready?2022 APIsecure_API Security & Fraud Detection - Are you ready?
2022 APIsecure_API Security & Fraud Detection - Are you ready?
 
Defending Your IBM i Against Malware
Defending Your IBM i Against MalwareDefending Your IBM i Against Malware
Defending Your IBM i Against Malware
 
Why Network and Endpoint Security Isn’t Enough
Why Network and Endpoint Security Isn’t EnoughWhy Network and Endpoint Security Isn’t Enough
Why Network and Endpoint Security Isn’t Enough
 
Catalyst 2015: Patrick Harding
Catalyst 2015: Patrick HardingCatalyst 2015: Patrick Harding
Catalyst 2015: Patrick Harding
 
apidays LIVE Singapore 2021 - Novel approaches in API security by Dr Tal Stei...
apidays LIVE Singapore 2021 - Novel approaches in API security by Dr Tal Stei...apidays LIVE Singapore 2021 - Novel approaches in API security by Dr Tal Stei...
apidays LIVE Singapore 2021 - Novel approaches in API security by Dr Tal Stei...
 
apidays LIVE Paris 2021 - Addressing OWASP API Security Top 10 by Isabelle Ma...
apidays LIVE Paris 2021 - Addressing OWASP API Security Top 10 by Isabelle Ma...apidays LIVE Paris 2021 - Addressing OWASP API Security Top 10 by Isabelle Ma...
apidays LIVE Paris 2021 - Addressing OWASP API Security Top 10 by Isabelle Ma...
 
Multi-Factor Authentication - "Moving Towards the Enterprise"
Multi-Factor Authentication - "Moving Towards the Enterprise" Multi-Factor Authentication - "Moving Towards the Enterprise"
Multi-Factor Authentication - "Moving Towards the Enterprise"
 
Breaking Secure Mobile Applications - Hack In The Box 2014 KL
Breaking Secure Mobile Applications - Hack In The Box 2014 KLBreaking Secure Mobile Applications - Hack In The Box 2014 KL
Breaking Secure Mobile Applications - Hack In The Box 2014 KL
 
5 step plan to securing your APIs
5 step plan to securing your APIs5 step plan to securing your APIs
5 step plan to securing your APIs
 
API Security - Everything You Need to Know To Protect Your APIs
API Security - Everything You Need to Know To Protect Your APIsAPI Security - Everything You Need to Know To Protect Your APIs
API Security - Everything You Need to Know To Protect Your APIs
 
F5 XC Distributed cloud Security and Application Delievery
F5 XC Distributed cloud Security and Application DelieveryF5 XC Distributed cloud Security and Application Delievery
F5 XC Distributed cloud Security and Application Delievery
 
2022 APIsecure_Hackers with Valid Credentials
2022 APIsecure_Hackers with Valid Credentials2022 APIsecure_Hackers with Valid Credentials
2022 APIsecure_Hackers with Valid Credentials
 
API Security Best Practices and Guidelines
API Security Best Practices and GuidelinesAPI Security Best Practices and Guidelines
API Security Best Practices and Guidelines
 
F5 Web Application Security
F5 Web Application SecurityF5 Web Application Security
F5 Web Application Security
 
Layered API Security: What Hackers Don't Want You To Know
Layered API Security: What Hackers Don't Want You To KnowLayered API Security: What Hackers Don't Want You To Know
Layered API Security: What Hackers Don't Want You To Know
 
Application security meetup k8_s security with zero trust_29072021
Application security meetup k8_s security with zero trust_29072021Application security meetup k8_s security with zero trust_29072021
Application security meetup k8_s security with zero trust_29072021
 
APIdays Paris 2019 - RASP for APIs and Microservices by Jean-Baptiste Aviat, ...
APIdays Paris 2019 - RASP for APIs and Microservices by Jean-Baptiste Aviat, ...APIdays Paris 2019 - RASP for APIs and Microservices by Jean-Baptiste Aviat, ...
APIdays Paris 2019 - RASP for APIs and Microservices by Jean-Baptiste Aviat, ...
 
Cybersecurity update 12
Cybersecurity update 12Cybersecurity update 12
Cybersecurity update 12
 
Cyber security series Application Security
Cyber security series   Application SecurityCyber security series   Application Security
Cyber security series Application Security
 
Information Risk and Protection
Information Risk and ProtectionInformation Risk and Protection
Information Risk and Protection
 

Mais de apidays

Mais de apidays (20)

Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Apidays New York 2024 - The secrets to Graph success, by Leah Hurwich Adler, ...
Apidays New York 2024 - The secrets to Graph success, by Leah Hurwich Adler, ...Apidays New York 2024 - The secrets to Graph success, by Leah Hurwich Adler, ...
Apidays New York 2024 - The secrets to Graph success, by Leah Hurwich Adler, ...
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
Apidays New York 2024 - API Discovery - From Crawl to Run by Rob Dickinson, G...
Apidays New York 2024 - API Discovery - From Crawl to Run by Rob Dickinson, G...Apidays New York 2024 - API Discovery - From Crawl to Run by Rob Dickinson, G...
Apidays New York 2024 - API Discovery - From Crawl to Run by Rob Dickinson, G...
 
Apidays Singapore 2024 - Building with the Planet in Mind by Sandeep Joshi, M...
Apidays Singapore 2024 - Building with the Planet in Mind by Sandeep Joshi, M...Apidays Singapore 2024 - Building with the Planet in Mind by Sandeep Joshi, M...
Apidays Singapore 2024 - Building with the Planet in Mind by Sandeep Joshi, M...
 
Apidays Singapore 2024 - Connecting Cross Border Commerce with Payments by Gu...
Apidays Singapore 2024 - Connecting Cross Border Commerce with Payments by Gu...Apidays Singapore 2024 - Connecting Cross Border Commerce with Payments by Gu...
Apidays Singapore 2024 - Connecting Cross Border Commerce with Payments by Gu...
 
Apidays Singapore 2024 - Privacy Enhancing Technologies for AI by Mark Choo, ...
Apidays Singapore 2024 - Privacy Enhancing Technologies for AI by Mark Choo, ...Apidays Singapore 2024 - Privacy Enhancing Technologies for AI by Mark Choo, ...
Apidays Singapore 2024 - Privacy Enhancing Technologies for AI by Mark Choo, ...
 
Apidays Singapore 2024 - Blending AI and IoT for Smarter Health by Matthew Ch...
Apidays Singapore 2024 - Blending AI and IoT for Smarter Health by Matthew Ch...Apidays Singapore 2024 - Blending AI and IoT for Smarter Health by Matthew Ch...
Apidays Singapore 2024 - Blending AI and IoT for Smarter Health by Matthew Ch...
 
Apidays Singapore 2024 - OpenTelemetry for API Monitoring by Danielle Kayumbi...
Apidays Singapore 2024 - OpenTelemetry for API Monitoring by Danielle Kayumbi...Apidays Singapore 2024 - OpenTelemetry for API Monitoring by Danielle Kayumbi...
Apidays Singapore 2024 - OpenTelemetry for API Monitoring by Danielle Kayumbi...
 
Apidays Singapore 2024 - Connecting Product and Engineering Teams with Testin...
Apidays Singapore 2024 - Connecting Product and Engineering Teams with Testin...Apidays Singapore 2024 - Connecting Product and Engineering Teams with Testin...
Apidays Singapore 2024 - Connecting Product and Engineering Teams with Testin...
 
Apidays Singapore 2024 - The Growing Carbon Footprint of Digitalization and H...
Apidays Singapore 2024 - The Growing Carbon Footprint of Digitalization and H...Apidays Singapore 2024 - The Growing Carbon Footprint of Digitalization and H...
Apidays Singapore 2024 - The Growing Carbon Footprint of Digitalization and H...
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Apidays Singapore 2024 - API Monitoring x SRE by Ryan Ashneil and Eugene Wong...
Apidays Singapore 2024 - API Monitoring x SRE by Ryan Ashneil and Eugene Wong...Apidays Singapore 2024 - API Monitoring x SRE by Ryan Ashneil and Eugene Wong...
Apidays Singapore 2024 - API Monitoring x SRE by Ryan Ashneil and Eugene Wong...
 
Apidays Singapore 2024 - A nuanced approach on AI costs and benefits for the ...
Apidays Singapore 2024 - A nuanced approach on AI costs and benefits for the ...Apidays Singapore 2024 - A nuanced approach on AI costs and benefits for the ...
Apidays Singapore 2024 - A nuanced approach on AI costs and benefits for the ...
 
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu SubbuApidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
 
Apidays Singapore 2024 - How APIs drive business at BNP Paribas by Quy-Doan D...
Apidays Singapore 2024 - How APIs drive business at BNP Paribas by Quy-Doan D...Apidays Singapore 2024 - How APIs drive business at BNP Paribas by Quy-Doan D...
Apidays Singapore 2024 - How APIs drive business at BNP Paribas by Quy-Doan D...
 

Último

( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
nilamkumrai
 
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
Call Girls In Delhi Whatsup 9873940964 Enjoy Unlimited Pleasure
 
💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
nirzagarg
 
VIP Call Girls Pollachi 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Pollachi 7001035870 Whatsapp Number, 24/07 BookingVIP Call Girls Pollachi 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Pollachi 7001035870 Whatsapp Number, 24/07 Booking
dharasingh5698
 
📱Dehradun Call Girls Service 📱☎️ +91'905,3900,678 ☎️📱 Call Girls In Dehradun 📱
📱Dehradun Call Girls Service 📱☎️ +91'905,3900,678 ☎️📱 Call Girls In Dehradun 📱📱Dehradun Call Girls Service 📱☎️ +91'905,3900,678 ☎️📱 Call Girls In Dehradun 📱
📱Dehradun Call Girls Service 📱☎️ +91'905,3900,678 ☎️📱 Call Girls In Dehradun 📱
@Chandigarh #call #Girls 9053900678 @Call #Girls in @Punjab 9053900678
 
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
@Chandigarh #call #Girls 9053900678 @Call #Girls in @Punjab 9053900678
 
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort ServiceCall Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
9953056974 Low Rate Call Girls In Saket, Delhi NCR
 

Último (20)

( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
 
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
 
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort ServiceBusty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
 
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
 
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
 
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
 
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
 
💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
 
VIP Call Girls Pollachi 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Pollachi 7001035870 Whatsapp Number, 24/07 BookingVIP Call Girls Pollachi 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Pollachi 7001035870 Whatsapp Number, 24/07 Booking
 
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
 
📱Dehradun Call Girls Service 📱☎️ +91'905,3900,678 ☎️📱 Call Girls In Dehradun 📱
📱Dehradun Call Girls Service 📱☎️ +91'905,3900,678 ☎️📱 Call Girls In Dehradun 📱📱Dehradun Call Girls Service 📱☎️ +91'905,3900,678 ☎️📱 Call Girls In Dehradun 📱
📱Dehradun Call Girls Service 📱☎️ +91'905,3900,678 ☎️📱 Call Girls In Dehradun 📱
 
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
 
"Boost Your Digital Presence: Partner with a Leading SEO Agency"
"Boost Your Digital Presence: Partner with a Leading SEO Agency""Boost Your Digital Presence: Partner with a Leading SEO Agency"
"Boost Your Digital Presence: Partner with a Leading SEO Agency"
 
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
 
Wadgaon Sheri $ Call Girls Pune 10k @ I'm VIP Independent Escorts Girls 80057...
Wadgaon Sheri $ Call Girls Pune 10k @ I'm VIP Independent Escorts Girls 80057...Wadgaon Sheri $ Call Girls Pune 10k @ I'm VIP Independent Escorts Girls 80057...
Wadgaon Sheri $ Call Girls Pune 10k @ I'm VIP Independent Escorts Girls 80057...
 
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort ServiceCall Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
 
20240508 QFM014 Elixir Reading List April 2024.pdf
20240508 QFM014 Elixir Reading List April 2024.pdf20240508 QFM014 Elixir Reading List April 2024.pdf
20240508 QFM014 Elixir Reading List April 2024.pdf
 
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
 
Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...
Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...
Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...
 

APIsecure 2023 - The Importance of Real-Time Protection in API Security, Jeremy Ventura (ThreatX)

  • 1. THE IMPORTANCE OF REAL-TIME PROTECTION IN API SECURITY Jeremy Ventura Field CISO
  • 2. AGENDA Copyrights 2 The key challenges and risk associated with API Security Case Studies from ThreatX The importance of real-time blocking
  • 3. APIS REPRESENT A TARGET RICH ENVIRONMENT • Thousands of APIs and endpoints with limited visibility • API vulnerabilities easily exposed and discoverable • Attackers continually leverage advanced techniques against APIs • Multi-mode attacks becoming the norm 3 Increased Usage = Increased Risk
  • 4. APIS IN THE NEWS • Entity had access from November to January to an API • Data attained via API was done “without authorization” • Name, Address, Email, Phone, DoB, Account # • 37 million end users affected • More info to come but: • Lack of visibility? • Misconfiguration/Misuse? • Broken business logic? • Stolen Credentials? 4 Incidents & Breaches on the Rise
  • 5. COMPLEXITY & AUTOMATION OF ATTACKS IS EVER INCREASING 5 • Hacking is easier than ever • Industrialized hacking tools • Rent-a-bot/Solver Services • Attack-as-a-Service • Residential proxies, anonymizers • Advanced attacks are far more coordinated • Security tools do not keep up Multi-mode attacks require a fundamental shift in protection strategies Traditional OWASP Top 10 Sophisticated, multi-mode attacks
  • 6. THE THREAT OF MULTI-VECTOR ATTACKS 6 • Orchestrated attacks that span varied phases & techniques • Distributed IPs • Massive volumes • Diversionary tactics • Embedded, multi-step automation Disguise true attack through diversion, distraction & evasion
  • 7. A WORD ABOUT BOTS 7 • Bot management critical, but must evolve with attacks • Current approaches best suited for high volume, binary attacks • Heavy reliance on static threat intel feeds • APIs present new challenges • No browser injections • No Captcha or IP challenges • Attacker profiling & behavioral context critical for protection against multi- mode attacks Bots present a new challenge to protecting APIs
  • 8. TALES FROM THE THREATX SOC 8 • Large online retailer taking fire from multiple directions • Periodic mid-grade DDoS attacks • Increased login failure rates on web • High rate of rebate fraud • Goal: trigger BGP routing to bypass fraud protection for mobile APIs while the security team is distracted • Multiple best-of-breed technologies fail to identify & block attacks Attackers deploy multiple techniques to distract security & target APIs
  • 9. TALES FROM THE THREATX SOC 9 • Gaming company launching new product • Attacker engaged foreign botnet to discover potentially vulnerable API endpoints • Later during product launch, attacker deployed large ATO attack while quietly attempting vulnerability exploits • Although rotating IPs and user agents, TLS signatures & IP fingerprints detected same attacker profile to block all suspicious behavior Tracking & correlating attacker behavior – to enable real-time protection
  • 10. PROTECTING APIS STARTS WITH FOCUS ON THE ATTACKER 10 • Understanding attacker risk profile • Digital fingerprints to each unique attacker • Cumulative across multiple attack vectors • Continually evaluate risk & response • Behavioral fingerprints of an attack reveal patterns, techniques & targets Context of attack over time is key to protecting APIs
  • 11. INSIGHT & CONTEXT THROUGH CROSS PLATFORM VISIBILITY 11 • Identify unique attacker executing campaigns across multiple methods and vectors • Correlate data over time to see through deception • Understanding behaviors and intentions • Biggest challenge = enabling effective response Correlating attack patterns to identify and mitigate API risk
  • 12. BLOCKING API ATTACKS IN REAL TIME 12 • Observing attack data offline will not enable real-time protection of APIs • Often too late by the time an attack is discovered • Complexity required to identify attacks typically can’t be replicated in 3rd party firewall • Blocking single IP at a time • Responses must occur as the attack is underway – and based on insights gathered over time Real-time API protection key to defense
  • 13. API PROTECTION: KEY CAPABILITIES 13 Real-time Analysis & Response • AI/ML/Context Engine • IP Interrogation & Fingerprinting • Active Deception • Tarpit/Rate Limiting • Attacker/User Behavior Analysis • Data Flow Analysis & Enforcement • Real-time Blocking 13 API Discovery & Analysis • API Discovery • API Specification Mgt • Endpoint Usage Analysis • Endpoint Attack Metrics • Endpoint Risk Scoring Fully Integrated Attack Prevention • API Protection • Web App Protection • DDoS Protection • Bot Mgt & Mitigation • Fraud Protection Flexible Deployment Options • Inline / Agentless • Inline / Agent-based • Out-of-Band / Agentless • Hosted, Cloud, On-Premise Managed Services • Managed Cloud Platform • Managed Threat Analysis • Managed Policy Enforcement • Managed Attack Response • APIs are under siege – by mixed-mode, high volume attacks, including bots and DDoS • API observability does not = real-time protection • API protection must deliver active, real-time attack blocking • API protection should have ability to extend to broader application portfolio Can’t block? Then you’re not protecting APIs.