By Nick Rago, Field CTO at Salt Security
It’s the time of year for ghastly Zombies, Shadows, Ghosts, and all things terrifying to come knocking at your door. Although Halloween is known best for the appearance of unwanted spooky guests, it doesn’t mean these atrocities vanish as soon as the calendar hits November 1st. Many organizations find themselves haunted year round but not in the way you might think. The monstrosities that plague organizations aren’t hiding in closets or lurking in basements, but rather, hiding as APIs in your infrastructure, patiently waiting for just the right time to wreak havoc on your business.
APIs sit at the core of today’s modern applications, connecting both consumer apps and enterprises to vital data and services. As organizations continue to shift their operations towards an API-driven economy, a new and terrifying challenge they are faced dealing with is API sprawl. API sprawl is just what it sounds like – the accelerating proliferation of APIs at organizations around the world and the resulting challenge of managing and securing them. As more APIs and underlying microservices and endpoints are created, it becomes increasingly difficult to keep track of them and how they’re being used.
With the attack surface growing ever so rapidly, unwanted and ghoulish API entities such as Zombies, Shadows, and Ghosts creep and crawl into existence, and become threats when organizations do not have proper security in place.
The Walking Dead: Zombie API Edition
Zombie APIs might not eat your brains, but they could eat into your most critical assets, as well as your organization’s ability to maintain operations, by giving cybercriminals easy access to your data and network infrastructure
Zombie APIs are endpoints that are no longer maintained or that have become outdated or replaced. These forgotten APIs no longer serve a purpose to an organization, yet they still live on in perpetuity, providing a point of access to data, application functions, or key infrastructure management.
Zombie APIs are not receiving any ongoing patching or maintenance or updates in any functional or security capacity, and therefore can become a critical security risk to an organization. In fact, Salt Labs’ State of API Security report research shows how Zombie APIs have accelerated to the top of the list of API concerns with 54% of respondents saying outdated or “zombie” APIs are a high concern, up from 42% from last quarter.
What is creeping in your API Shadows?
Shadow APIs are third-party APIs or API endpoints whose creation and deployment was done “under the radar.” These ominous APIs come to existence outside of an organization’s official API governance, visibility, and security controls.
Because these types of APIs are unregulated and sit outside of a company’s API governance processes, they can pose a wide variety of security risks. For example, the API may not adhere to corporate standards and not have proper authentication and access gates in place, or may be exposing sensitive data improperly. In addition, the API may not be adhering to best practices from a security standpoint, making it vulnerable to many of the OWASP API Security Top 10 attack threats.
All in all, Shadow APIs can be bad news and can create serious vulnerabilities when allowed to freely inhabit the organization’s software environment.
Ghosts, Goblins and Ghouls, Oh My!
Third-party APIs are often referred to as Ghost or “ghostwritten” APIs, because they provide important functionality and potentially access to sensitive data, but are written by outside entities. In these cases, organizations have no authority over how the APIs are developed and must trust that outside developers followed API security best practices. Additionally, Ghost APIs are often not properly inventoried, governed, tested, monitored, and maintained because they are published outside the typical devops cycle that an internally developed API flushes through. This, in itself, creates security risks to both an application and its infrastructure.
Ghost APIs can find their way into corporate infrastructure from a variety of sources and extend the potential attack surface in different ways. These frightening souls can be exposed anywhere: commercial packaged and open-source applications, SaaS-based services, no-code/low-code solutions, 3rd party on-premise and cloud based infrastructure components, and more.
Keeping Safe from Spooky API Sprawl
It would be ghoulish not to protect yourself from the horrors and havoc of API sprawl.
As a first step to tackle the challenges of Zombie, Shadow and Ghost APIs, organizations must get visibility and security coverage into all APIs already running within their infrastructure. An easy way to do this is through the adoption of continuous API discovery. After all APIs are discovered and their initial security posture is assessed, it is important for organizations to implement proper API runtime protection. By monitoring APIs in runtime, organizations can gain a better understanding about normal API usage versus abnormal API usage behaviors in their environment, allowing them to quickly spot potential paranormal abuse and misuse patterns that typically evade traditional security defenses
Finally, organizations must adopt an API governance strategy that enforces controls over how and when and in what manner an API gets deployed regardless of who developed it and why.
Zombie, Shadow, and Ghost APIs can wreak havoc in an organization’s infrastructure and become prey for cyber mischief, if not properly secured. Organizations can put those ghoulish nightmares back where they belong (in the graveyard) by having the proper API visibility, governance and lifecycle strategies in place.
##
ABOUT THE AUTHOR
Nick Rago, Field CTO at Salt Security
Nick is a startup veteran and Internet technology expert with over 25 years of application development, testing, and cybersecurity experience. He is recognized as an industry expert in the realms of API development, API management, and API security. In the world of APIs, Nick has helped architect and implement some of the largest API Management and monolith to microservice digital transformation projects in North America. Nick has had the honor of speaking at prestigious conferences including Blackhat, RSA, AWS re:inforce, SecureWorld, APIWorld, and his expert opinions are regularly featured in prominent publications such as Darkreading, Infosecurity Magazine, Computer Weekly, SC Magazine, Security Boulevard, Security Week, and many others.
As Field CTO and Product Strategist at Salt Security, Nick helps guide and positively influence how organizations can foster API-driven success, while protecting themselves from today’s emerging API security threats. Prior to joining Salt, Nick was an early contributor to the success of Kong, the world’s most widely used API management platform.






