API Security
The practices and controls that protect application programming interfaces from abuse, covering authentication, authorisation, input validation, rate limiting, inventory and monitoring of the APIs that connect applications, devices and services.
APIs expose application logic and data directly to clients, partners and machines, often without the constraints a user interface imposes. The 2023 edition of the OWASP API Security Top 10 highlights the main risks, led by broken object level authorisation, in which changing an identifier in a request returns another user's data. Other listed risks include broken authentication, broken object property level authorisation, unrestricted resource consumption, broken function level authorisation, server-side request forgery and improper inventory management.
APIs underpin mobile apps, single-page web applications, microservices, partner integrations and IoT and industrial platforms, so weaknesses in them can expose large volumes of data or allow unauthorised actions. Unknown or forgotten APIs, sometimes called shadow or zombie APIs, are a particular risk because they escape testing and monitoring.
Core controls include strong authentication using standards such as OAuth 2.0, object-level and function-level authorisation checks on every request, schema-based input validation, rate limiting and quotas, minimal response data, TLS for all traffic, an up-to-date inventory based on OpenAPI definitions, and logging of API activity. API gateways enforce many of these controls consistently, and testing should combine automated scanning with manual tests of business logic.
Key points
- Broken object level authorisation tops the 2023 OWASP API Security Top 10.
- Every request needs authentication and object-level authorisation checks.
- Rate limiting protects against abuse and resource exhaustion.
- A complete API inventory prevents shadow and zombie APIs.
Where AiVibe comes in
AiVedha.ai's automated website audit includes API security checks, and AiVibe's penetration testing services include API testing.
Related terms
- OWASP Top 10Cybersecurity & Compliance
- OAuth 2.0Cybersecurity & Compliance
- Broken Access ControlCybersecurity & Compliance
- Server-Side Request Forgery (SSRF)Cybersecurity & Compliance
- Web Application Firewall (WAF)Cybersecurity & Compliance
- Penetration TestingCybersecurity & Compliance
Terms that refer to API Security
- Cross-Origin Resource Sharing (CORS)Cybersecurity & Compliance
- Distributed Denial of Service (DDoS)Cybersecurity & Compliance
- Dynamic Application Security Testing (DAST)Cybersecurity & Compliance
- Threat ModellingCybersecurity & Compliance
- Vulnerability Assessment and Penetration Testing (VAPT)Cybersecurity & Compliance