SlideShare a Scribd company logo
AN HOLISTIC APPROACH TO API SECURITY
ISABELLE MAUNY - CTO
The API Security Platform
for the Enterprise
API SECURITY NEEDS TO
2
EVOLVE
TITLE TEXT
Complex deployments
3
FROM ESTABLISHED PERIMETER…
4
TO BLURRY PERIMETER…
TITLE TEXT
5
App icon made by https://www.flaticon.com/authors/pixel-buddha
Internal
Partner Public
VIRTUAL APPLICATION NETWORKS
TITLE TEXTFAST APP DELIVERY
6
APPLICATION

DEVELOPMENT
APPLICATION

SECURITY
7
SECURITY IS NEEDED. ALWAYS.
1
8
EXPOSING ENTERPRISE DATA
AND PROCESSES.
WHAT ARE APIS FOR ?
9
Internal
External
80
55
57
69
Now
Expect in the next
18 months
Source: @The State of Cybersecurity and Digital Trust 2016” Accenture
and HIS Research - Sample: 208 Enterprise Security Professionals
Have you experienced the theft
or corruption of internal
corporate or user/consumer
information by Internal or
External threat actors?
10
“I think that a lot of people think that because there is no GUI on an
API that no one can find it and it is invisible. But we can find
them in about five seconds with a proxy…
…Almost every threat that applies to a web app, can
happen to an API, but a lot of people for some reason are not
protecting them as much as their web applications.”
Tanya Janca
Application Security Evangelist - AppSec Podcast
11
“
12
YOU NEED AN HOLISTIC APPROACH 

TO API SECURITY2
13
Authentication
Integrity
(transport &
message)
Audit
Confidentiality
(transport &
message)
Availability
(Rate Limiting)
Authorization
Non
Repudiation
Data Validity
(attacks
protection)
14
YES. You need to
consider all of this…
… AND you need to
configure all aspects
in the right way
15
EASY TO GET
THOSE WRONG!
16
AND you need the
right infrastructure…
17
NOT ALL APIS ARE EQUAL
3
“Security is a risk control measure…In
the security sphere, one size does not fit
all. We have to take ‘appropriate
measures’.
Nat SakimuraFixing OAuth, Nat Sakimura, July 20, 2016, https://nat.sakimura.org/2016/07/20/fixing-oauth/
18
“
19
Financial APIS Security Auth Grant Types
OpenID Connect Flows
TLS Settings
Message Confidentiality
Non-Repudiation
Message Integrity
Financial APIs Working Group: http://openid.net/wg/fapi/
20
DEVOPS, BUT WITH SECURITY ON
4
LET’S SHIFT LEFT!
21
DeploymentTestingDevelopmentDesign
TITLE TEXTSEC-DEV-OPS IN ACTION
22
Develop
Assess
Secure
TestDocument
Deploy
Continuous API
testing, including
security testing
Deploy to API Security
Platform
Configure and apply
security policy from
assessed risk
Assess API description
and evaluate risk level
Document and annotate
API with OpenAPI/Swagger
23
COLLABORATION IS CRUCIAL
5
24
RELIES ON STRONG COLLABORATION
ACROSS OPERATIONS, DEVELOPMENT,
SECURITY AND BUSINESS TEAMS
PROPER SECURITY
CONTACT: INFO@42CRUNCH.COM
WWW.42CRUNCH.COM
The API Security Platform for the Enterprise

More Related Content

PPTX
API Security Survey
Imperva
 
PDF
(SACON) Wayne Tufek - chapter three - sabsa
Priyanka Aash
 
PPTX
Data-driven API Security
Apigee | Google Cloud
 
PDF
(SACON) Wayne Tufek - chapter four - industry reports
Priyanka Aash
 
PDF
5 must-have security testing tools for your pentesting tasks
Pentest-Tools.com
 
PDF
COVID-19 free penetration tests by Pentest-Tools.com
Pentest-Tools.com
 
PPTX
Security as an Enabler for the Digital World - CISO Perspective
Apigee | Google Cloud
 
PDF
API Security and OAuth for the Enterprise
CA API Management
 
API Security Survey
Imperva
 
(SACON) Wayne Tufek - chapter three - sabsa
Priyanka Aash
 
Data-driven API Security
Apigee | Google Cloud
 
(SACON) Wayne Tufek - chapter four - industry reports
Priyanka Aash
 
5 must-have security testing tools for your pentesting tasks
Pentest-Tools.com
 
COVID-19 free penetration tests by Pentest-Tools.com
Pentest-Tools.com
 
Security as an Enabler for the Digital World - CISO Perspective
Apigee | Google Cloud
 
API Security and OAuth for the Enterprise
CA API Management
 

What's hot (20)

PPTX
Threat Check for Struts Released, Equifax Breach Dominates News
Black Duck by Synopsys
 
PPTX
Balancing Mobile UX & Security: An API Management Perspective Presentation fr...
CA API Management
 
PPTX
apidays LIVE India - 10 steps to secure your API by Pabitra Kumar Sahoo, Qual...
apidays
 
PDF
Mobile App Hacking In A Nutshell
Prathan Phongthiproek
 
PPTX
Building better security for your API platform using Azure API Management
Eldert Grootenboer
 
PPTX
Open Source Insight: CVE–2017-9805, Equifax Breach & Wacky Open Source Licenses
Black Duck by Synopsys
 
PDF
Jump-Start The MASVS
Prathan Phongthiproek
 
PPTX
Open Source Insight: Equifax, Apache Struts, & CVE-2017-5638 Vulnerability
Black Duck by Synopsys
 
PPTX
8 must dos for a perfect privileged account management strategy
ManageEngine
 
PPTX
Protecting APIs from Mobile Threats- Beyond Oauth
Apigee | Google Cloud
 
PDF
API Security with Postman and Qualys
Postman
 
PDF
(SACON) Suhas Desai - The Power of APIs – API Economy Trends & Market Drivers...
Priyanka Aash
 
PDF
GitStack 0day . Remote code execution - Adam Nurudini
Adam Nurudini
 
PDF
Preparing for the inevitable: The mobile incident response playbook
NowSecure
 
PPTX
Managing Identities in the World of APIs
Apigee | Google Cloud
 
PDF
Applying API Security at Scale
Nordic APIs
 
PDF
API Security Needs AI Now More Than Ever
Ping Identity
 
PDF
Protecting Against Vulnerabilities in SharePoint Add-ons
Imperva
 
PDF
Optimize Your Zero Trust Infrastructure
Ping Identity
 
PDF
CIS13: APIs, Identity, and Securing the Enterprise
CloudIDSummit
 
Threat Check for Struts Released, Equifax Breach Dominates News
Black Duck by Synopsys
 
Balancing Mobile UX & Security: An API Management Perspective Presentation fr...
CA API Management
 
apidays LIVE India - 10 steps to secure your API by Pabitra Kumar Sahoo, Qual...
apidays
 
Mobile App Hacking In A Nutshell
Prathan Phongthiproek
 
Building better security for your API platform using Azure API Management
Eldert Grootenboer
 
Open Source Insight: CVE–2017-9805, Equifax Breach & Wacky Open Source Licenses
Black Duck by Synopsys
 
Jump-Start The MASVS
Prathan Phongthiproek
 
Open Source Insight: Equifax, Apache Struts, & CVE-2017-5638 Vulnerability
Black Duck by Synopsys
 
8 must dos for a perfect privileged account management strategy
ManageEngine
 
Protecting APIs from Mobile Threats- Beyond Oauth
Apigee | Google Cloud
 
API Security with Postman and Qualys
Postman
 
(SACON) Suhas Desai - The Power of APIs – API Economy Trends & Market Drivers...
Priyanka Aash
 
GitStack 0day . Remote code execution - Adam Nurudini
Adam Nurudini
 
Preparing for the inevitable: The mobile incident response playbook
NowSecure
 
Managing Identities in the World of APIs
Apigee | Google Cloud
 
Applying API Security at Scale
Nordic APIs
 
API Security Needs AI Now More Than Ever
Ping Identity
 
Protecting Against Vulnerabilities in SharePoint Add-ons
Imperva
 
Optimize Your Zero Trust Infrastructure
Ping Identity
 
CIS13: APIs, Identity, and Securing the Enterprise
CloudIDSummit
 
Ad

Similar to LF_APIStrat17_Beyond OAuth: A Holistic Approach to Securing Your APIs and Your Infrastructure (20)

PDF
Five Principles to API Security
Isabelle Mauny
 
PDF
API Security Guidelines: Beyond SSL and OAuth.
Isabelle Mauny
 
PDF
apidays LIVE LONDON - API Abuse - Comprehension and Prevention by David Stewart
apidays
 
PPTX
apidays LIVE New York 2021 - Playing with FHIR without getting burned by Dav...
apidays
 
PDF
apidays LIVE Singapore 2021 - Why verifying user identity Is not enough In 20...
apidays
 
PDF
Traceable.ai Debuts Platform for Building API Knowledge that Detects And Thwa...
Dana Gardner
 
PPTX
Open Source Insight: Happy Birthday Open Source and Application Security for ...
Black Duck by Synopsys
 
PDF
ITCamp 2018 - Tobiasz Koprowski - SECDEV(OPS). How to Brace Your IT Security.
ITCamp
 
PDF
When it Comes to API Security, Expect the Whole World to Be Testing Your Mett...
Dana Gardner
 
PDF
FireTail at API Days Australia 2024 - The Double-edge sword of AI for API Sec...
JeremySnyder8
 
PDF
42crunch-API-security-workshop
42Crunch
 
PDF
OWASP API Security TOP 10 - 2019
Miguel Angel Falcón Muñoz
 
PPTX
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
apidays
 
PPTX
Cyber Risk Management in 2017 - Challenges & Recommendations
Ulf Mattsson
 
PDF
API SECURITY by krishna murari and vikas maurya
Krishna Murari
 
PPTX
Security in the age of open source - Myths and misperceptions
Tim Mackey
 
PDF
apidays LIVE Paris 2021 - API Attack Simulator - Find your API vulnerabilitie...
apidays
 
PPTX
Automating Your Tools: How to Free Up Your Security Professionals for Actual ...
Kevin Fealey
 
PDF
How to minimise API risks during development - Bahaa Al Zubaidi.pdf
Bahaa Al Zubaidi
 
PPTX
Open Source Insight: 2017 Top 10 IT Security Stories, Breaches, and Predictio...
Black Duck by Synopsys
 
Five Principles to API Security
Isabelle Mauny
 
API Security Guidelines: Beyond SSL and OAuth.
Isabelle Mauny
 
apidays LIVE LONDON - API Abuse - Comprehension and Prevention by David Stewart
apidays
 
apidays LIVE New York 2021 - Playing with FHIR without getting burned by Dav...
apidays
 
apidays LIVE Singapore 2021 - Why verifying user identity Is not enough In 20...
apidays
 
Traceable.ai Debuts Platform for Building API Knowledge that Detects And Thwa...
Dana Gardner
 
Open Source Insight: Happy Birthday Open Source and Application Security for ...
Black Duck by Synopsys
 
ITCamp 2018 - Tobiasz Koprowski - SECDEV(OPS). How to Brace Your IT Security.
ITCamp
 
When it Comes to API Security, Expect the Whole World to Be Testing Your Mett...
Dana Gardner
 
FireTail at API Days Australia 2024 - The Double-edge sword of AI for API Sec...
JeremySnyder8
 
42crunch-API-security-workshop
42Crunch
 
OWASP API Security TOP 10 - 2019
Miguel Angel Falcón Muñoz
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
apidays
 
Cyber Risk Management in 2017 - Challenges & Recommendations
Ulf Mattsson
 
API SECURITY by krishna murari and vikas maurya
Krishna Murari
 
Security in the age of open source - Myths and misperceptions
Tim Mackey
 
apidays LIVE Paris 2021 - API Attack Simulator - Find your API vulnerabilitie...
apidays
 
Automating Your Tools: How to Free Up Your Security Professionals for Actual ...
Kevin Fealey
 
How to minimise API risks during development - Bahaa Al Zubaidi.pdf
Bahaa Al Zubaidi
 
Open Source Insight: 2017 Top 10 IT Security Stories, Breaches, and Predictio...
Black Duck by Synopsys
 
Ad

More from LF_APIStrat (20)

PDF
LF_APIStrat17_OWASP’s Latest Category: API Underprotection
LF_APIStrat
 
PDF
LF_APIStrat17_Creating Communication Applications using the Asterisk RESTFul ...
LF_APIStrat
 
PDF
LF_APIStrat17_Super-Powered REST API Testing
LF_APIStrat
 
PDF
LF_APIStrat17_How Mature are You? A Developer Experience Maturity Model
LF_APIStrat
 
PDF
LF_APIStrat17_Connect Your RESTful API to Hundreds of Others in Minutes (Zapi...
LF_APIStrat
 
PDF
LF_APIStrat17_Things I Wish People Told Me About Writing Docs
LF_APIStrat
 
PDF
LF_APIStrat17_Lifting Legacy to the Cloud on API Boosters
LF_APIStrat
 
PDF
LF_APIStrat17_Contract-first API Development: A Case Study in Parallel API Pu...
LF_APIStrat
 
PDF
LF_APIStrat17_Don't Repeat Yourself - Your API is Your Documentation
LF_APIStrat
 
PDF
LF_APIStrat17_How We Doubled the Velocity of Our Developer Experience Team
LF_APIStrat
 
PDF
LF_APIStrat17_API Marketing: First Comes Usability, then Discoverability
LF_APIStrat
 
PDF
LF_APIStrat17_Standing Taller with Technology: APIs, IoT, and the Digital Wor...
LF_APIStrat
 
PDF
LF_APIStrat17_REST API Microversions
LF_APIStrat
 
PDF
LF_APIStrat17_I Believe You But My Enterprise Don't: Adopting Open Standards ...
LF_APIStrat
 
PDF
LF_APIStrat17_Case Study: Cold Decision Trees
LF_APIStrat
 
PDF
LF_APIStrat17_Getting Your API House In Order
LF_APIStrat
 
PDF
LF_APIStrat17_Diving Deep into the API Ocean with Open Source Deep Learning T...
LF_APIStrat
 
PDF
LF_APIStrat17_Supporting SDKs in 7 Different Programming Languages While Main...
LF_APIStrat
 
PDF
LF_APIStrat17_Open Data vs. the World
LF_APIStrat
 
PDF
LF_APIStrat17_Practical DevSecOps for APIs
LF_APIStrat
 
LF_APIStrat17_OWASP’s Latest Category: API Underprotection
LF_APIStrat
 
LF_APIStrat17_Creating Communication Applications using the Asterisk RESTFul ...
LF_APIStrat
 
LF_APIStrat17_Super-Powered REST API Testing
LF_APIStrat
 
LF_APIStrat17_How Mature are You? A Developer Experience Maturity Model
LF_APIStrat
 
LF_APIStrat17_Connect Your RESTful API to Hundreds of Others in Minutes (Zapi...
LF_APIStrat
 
LF_APIStrat17_Things I Wish People Told Me About Writing Docs
LF_APIStrat
 
LF_APIStrat17_Lifting Legacy to the Cloud on API Boosters
LF_APIStrat
 
LF_APIStrat17_Contract-first API Development: A Case Study in Parallel API Pu...
LF_APIStrat
 
LF_APIStrat17_Don't Repeat Yourself - Your API is Your Documentation
LF_APIStrat
 
LF_APIStrat17_How We Doubled the Velocity of Our Developer Experience Team
LF_APIStrat
 
LF_APIStrat17_API Marketing: First Comes Usability, then Discoverability
LF_APIStrat
 
LF_APIStrat17_Standing Taller with Technology: APIs, IoT, and the Digital Wor...
LF_APIStrat
 
LF_APIStrat17_REST API Microversions
LF_APIStrat
 
LF_APIStrat17_I Believe You But My Enterprise Don't: Adopting Open Standards ...
LF_APIStrat
 
LF_APIStrat17_Case Study: Cold Decision Trees
LF_APIStrat
 
LF_APIStrat17_Getting Your API House In Order
LF_APIStrat
 
LF_APIStrat17_Diving Deep into the API Ocean with Open Source Deep Learning T...
LF_APIStrat
 
LF_APIStrat17_Supporting SDKs in 7 Different Programming Languages While Main...
LF_APIStrat
 
LF_APIStrat17_Open Data vs. the World
LF_APIStrat
 
LF_APIStrat17_Practical DevSecOps for APIs
LF_APIStrat
 

Recently uploaded (20)

PPTX
The-Ethical-Hackers-Imperative-Safeguarding-the-Digital-Frontier.pptx
sujalchauhan1305
 
PDF
How Open Source Changed My Career by abdelrahman ismail
a0m0rajab1
 
PDF
NewMind AI Weekly Chronicles - July'25 - Week IV
NewMind AI
 
PDF
Software Development Methodologies in 2025
KodekX
 
PDF
The Future of Artificial Intelligence (AI)
Mukul
 
PDF
GDG Cloud Munich - Intro - Luiz Carneiro - #BuildWithAI - July - Abdel.pdf
Luiz Carneiro
 
PDF
Doc9.....................................
SofiaCollazos
 
PDF
Presentation about Hardware and Software in Computer
snehamodhawadiya
 
PDF
CIFDAQ's Market Wrap : Bears Back in Control?
CIFDAQ
 
PDF
Make GenAI investments go further with the Dell AI Factory
Principled Technologies
 
PDF
Tea4chat - another LLM Project by Kerem Atam
a0m0rajab1
 
PPTX
The Future of AI & Machine Learning.pptx
pritsen4700
 
PDF
A Strategic Analysis of the MVNO Wave in Emerging Markets.pdf
IPLOOK Networks
 
PPTX
Agile Chennai 18-19 July 2025 | Emerging patterns in Agentic AI by Bharani Su...
AgileNetwork
 
PDF
Data_Analytics_vs_Data_Science_vs_BI_by_CA_Suvidha_Chaplot.pdf
CA Suvidha Chaplot
 
PPTX
Agile Chennai 18-19 July 2025 Ideathon | AI Powered Microfinance Literacy Gui...
AgileNetwork
 
PDF
Accelerating Oracle Database 23ai Troubleshooting with Oracle AHF Fleet Insig...
Sandesh Rao
 
PPTX
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
 
PDF
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
 
PPTX
Introduction to Flutter by Ayush Desai.pptx
ayushdesai204
 
The-Ethical-Hackers-Imperative-Safeguarding-the-Digital-Frontier.pptx
sujalchauhan1305
 
How Open Source Changed My Career by abdelrahman ismail
a0m0rajab1
 
NewMind AI Weekly Chronicles - July'25 - Week IV
NewMind AI
 
Software Development Methodologies in 2025
KodekX
 
The Future of Artificial Intelligence (AI)
Mukul
 
GDG Cloud Munich - Intro - Luiz Carneiro - #BuildWithAI - July - Abdel.pdf
Luiz Carneiro
 
Doc9.....................................
SofiaCollazos
 
Presentation about Hardware and Software in Computer
snehamodhawadiya
 
CIFDAQ's Market Wrap : Bears Back in Control?
CIFDAQ
 
Make GenAI investments go further with the Dell AI Factory
Principled Technologies
 
Tea4chat - another LLM Project by Kerem Atam
a0m0rajab1
 
The Future of AI & Machine Learning.pptx
pritsen4700
 
A Strategic Analysis of the MVNO Wave in Emerging Markets.pdf
IPLOOK Networks
 
Agile Chennai 18-19 July 2025 | Emerging patterns in Agentic AI by Bharani Su...
AgileNetwork
 
Data_Analytics_vs_Data_Science_vs_BI_by_CA_Suvidha_Chaplot.pdf
CA Suvidha Chaplot
 
Agile Chennai 18-19 July 2025 Ideathon | AI Powered Microfinance Literacy Gui...
AgileNetwork
 
Accelerating Oracle Database 23ai Troubleshooting with Oracle AHF Fleet Insig...
Sandesh Rao
 
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
 
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
 
Introduction to Flutter by Ayush Desai.pptx
ayushdesai204
 

LF_APIStrat17_Beyond OAuth: A Holistic Approach to Securing Your APIs and Your Infrastructure