10
API Security
Most existing APIs are considered insecure. At least, that’s what API security experts agree with. According to Cequence Security, an API security vendor, account takeover (ATO) attacks on APIs increased by about 62% in the second half of 2021. ATO is just one of the most common types of attack vectors that can affect your API. These are usually related to cryptographic failures or the lack of secure storage and transmission of sensitive information. Making sure that your API is designed with security in mind is critical to protect you against attackers.
This chapter will begin by defining what API security is. First, you’ll get to know how to design secure APIs. You’ll then learn that software security is a well-studied area ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access