Loading…
Attending this event?
Thursday, June 27 • 2:15pm - 3:00pm
API Security by Design

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

APIs are now the main attack vector against websites and organizations are growing concerned about how APIs affect their security posture. Sadly, APIs can easily expose vulnerabilities in unexpected ways. For example, unconstrained query parameters can be leveraged for SQL injection and reusing schemas for input and output models opens the door for mass assignment.


The good news is, there’s a lot we can do to improve our API security posture by shifting left on security and tackling vulnerabilities at design time. And that’s the goal of this talk! We’ll begin with a few examples that show how common design and implementation patterns expose major vulnerabilities, and then we’ll proceed to analyse a battery of API design anti-patterns that make our applications vulnerable. I’ll show you how those vulnerabilities relate to the OWASP top 10 API Threats and how we can resolve them by applying security-by-design principles.

We’ll conclude with an overview of the tools we can use to automate the process of discovering and addressing vulnerabilities in our APIs. I’ll show examples of using linters to identify vulnerabilities at design time and fuzzy testers to identify vulnerabilities at runtime.


By the end of this talk, you’ll be aware of the most important threats to our APIs and you’ll know how to discover and address them effectively. You’ll also get familiar with the concepts of API Security by Design, Shift-Left API Security, and Zero Trust APIs.


Speakers
avatar for Jose Haro Peralta

Jose Haro Peralta

API Strategy and Security Advisor, microapis.io
Jose is an API strategy and security advisor. He's the author of Microservice APIs and the creator of fencer, an open-source API security testing tool. He's a regular speaker at international conferences and has taught hundreds of students to build and deliver reliable and secure APIs... Read More →


Thursday June 27, 2024 2:15pm - 3:00pm WEST
Feedback form isn't open yet.

Attendees (5)