API security: whose job is it anyway?

Network Security - Tập 2018 - Trang 6-9 - 2018
Jason Macy1
1Forum Systems

Tóm tắt

It's probably safe to assume that nearly everyone is out to get your data. Nowadays it's data, not gold or oil, that is the world's most valuable and sought-after asset and it seems as if every month some company or other is hacked, exposing thousands of their users' information to unauthorised third parties. APIs are the glue that holds the digital world together. But's that's also the fundamental challenge with APIs – that they are everywhere. You use them every day and most of the time you are not even aware of it. And the sheer scale at which APIs are used means the potential impact of an API-related attack is significant. But as with other cyberthreats, the effects of a breach depend on the specific scenario and the data that is being shared through the API. Jason Macy of Forum Systems looks at how APIs can be vulnerable – and how they can be employed responsibly.

Tài liệu tham khảo

‘Top 10-2017 Top 10’. OWASP; www.owasp.org/index.php/Top_10-2017_Top_10 accessed August 2018 2016, ‘API Security: A Disjointed Affair’ Nichols Shaun, 2018, The Register ‘Meltdown and Spectre’. Home page; https://meltdownattack.com/ accessed August 2018