Opens in a new tab
vmblog logo 2024 wht (updated)

Imperva 2023 Predictions: API Security Starts and Ends with Bridging the Gap Between Security and DevOps

Share: 

David Marshall | Published: January 11, 2023

vmblog-predictions-2023 

Industry executives and experts share their predictions for 2023.  Read them in this 15th annual VMblog.com series exclusive.

API Security Starts and Ends with Bridging the Gap Between Security and DevOps

By Lebin Cheng, Vice President of API Security, Imperva

An application programming interface (API) is foundational to every organization’s innovation strategy. But at the same time, an API is a pathway to data and represents a risk to the business, unless it’s protected. This cannot be done effectively with an endpoint security solution. If organizations limit their focus to only protecting the API endpoint, they are overlooking critical attack vectors that can be exploited by cybercriminals.

API security requires a holistic strategy that protects applications from a range of API-related attacks. Bringing this comprehensive approach to life requires equal collaboration from the organization’s security and development teams. These two groups have traditionally been an odd couple. The DevOps team is responsible for building the company’s innovations quickly while the security operations team is tasked with keeping everything protected. Sometimes, that means the security team is telling a developer “no” or halting a project until a security review is completed. In 2023, expect the dynamic of this relationship to evolve as organizations use technology to unlock the hurdle that prevents many organizations from implementing effective API security.

To Protect APIs Effectively, Collaboration Between Security and DevOps Must Evolve

APIs are the backbone to digital transformation, working as communication intermediaries between applications, containers, microservices, and data stores. They enable data to be exchanged between disparate systems quickly and efficiently, unlocking greater convenience for consumers. Think of APIs as the connective tissue within an application environment.

APIs are also critical to development as they deliver unprecedented flexibility and speed at a lower cost. In fact, research from Google found that 58% of IT decision makers believe APIs are increasing the speed of new application development. The volume of APIs used by businesses is also increasing. Nearly half of all businesses have between 50 – 500 deployed, either internally or publicly, while some have over a thousand active APIs, finds a study conducted by the Marsh McLennan Cyber Risk Analytics Center.

The increased volume of APIs creates more security risks and vulnerabilities for organizations to manage. Cybercriminals can abuse APIs as a direct pathway to access sensitive data, internal objects, and internal database structures. What makes APIs so important to digital transformation can also render them dangerous. 

Data exfiltration through a vulnerable API is a security risk that every business should be concerned about in 2023. Successful incidents are often the result of a sophisticated operation where the attacker discovers and exploits the unknown vulnerability in the API implementation. This kind of attack cannot be easily recognized through predictable attack patterns and can be nearly impossible to block altogether. The only effective countermeasure is to employ continuous API monitoring that enables the security team to detect anomalies in API behavior. This intelligence is then fed back to the DevOps team so developers can fix the API implementation before it’s exploited. This is the type of feedback loop that is needed to mitigate the long-term risks associated with API security.

Addressing API-related security challenges requires equal input and participation from both the security and development teams. The security team cannot monitor all development processes to ensure every line of code is written with best practices in mind, while DevOps teams cannot afford to slow development.

In the New Year, organizations must adopt and integrate AI and machine learning solutions that grant security teams around-the-clock visibility into API activity, while monitoring for suspicious behavior. Through automation, security teams will be provided API discovery and data classification, which will enable for rapid remediation. At the same time, this process of monitoring API behavior will allow developers to continue their important work with limited interruption or friction.  

Selecting the Right Solution is a Team Effort

When selecting tools, both security and development teams should be involved in the evaluation. A solution should offer the following capabilities:

  • Complete visibility into API activity, as well as an up-to-date inventory of APIs and data exchange patterns. This ensures runtime protection is enabled based on a near real-time baseline of behavior.
  • Protection that operates on automated, self-regulatory anomaly detection.
  • Automated API behavior anomaly detection that integrates with the organization’s software development lifecycle (SDLC). This allows for testing and an improved API security posture.
  • A constant feedback loop to ensure developers can address vulnerabilities quickly and efficiently through enhanced API design and security testing.

With the New Year Comes Opportunity for Collaboration

As organizations expand their API ecosystems, creating a feedback loop between security and DevOps teams will be critical for mitigating the risk associated with APIs, without disrupting product development.

By adopting new AI and machine learning technologies, companies can evolve the relationship between these teams and enable more efficient and secure API development. With improved collaboration, developers can also leverage the findings from runtime security to improve their API implementations as a preventive measure. Taken together, the feedback loop can bolster an organization’s overall security posture and enable it to combat sophisticated business logic and object level attacks, mitigating long-term security and compliance risks. 

##

ABOUT THE AUTHOR

Lebin Cheng, Vice President of API Security, Imperva

Lebin-Cheng 

Lebin Cheng is a technologist and serial entrepreneur with more than 20 years of experience in cybersecurity. Cheng cofounded Netskope and later cofounded CloudVector, acquired by Imperva. He was awarded 15 patents in areas such as network security, application infrastructure and API inspection. He holds an MBA degree from the Haas School of Business at the University of California Berkeley and a MS in Computer Science from Purdue University.