Overview
APIs expose application logic and data directly, and they are often built faster than they are documented. The OWASP API Security Top 10 shows that API risk is mostly about authorization and inventory rather than exotic exploits.
A request can be well formed, authenticated and still wrong: a valid user asking for another user's data.
Key concepts
- 01
Object-level authorization
One of the most common API flaws is letting a user reach objects that belong to someone else by changing an identifier.
- 02
Authentication and function access
Weak token handling, and administrative functions exposed to ordinary users, grant access that was never meant to be given.
- 03
Excess data and resource limits
APIs that return more data than the client needs, or accept unlimited requests, leak information and invite abuse.
- 04
Inventory
Forgotten, undocumented or old versions of APIs stay online unprotected. You cannot secure an endpoint you do not know exists.
What good looks like
- Discover and inventory every API, including old versions.
- Enforce a schema so requests are held to what each API accepts.
- Check authorization on every object and function, not only at login.
- Apply rate limits and return only the fields a client needs.
- Monitor for unusual enumeration and volume.
Common pitfalls
- Assuming authentication means authorization.
- Documenting APIs once and never updating them.
- Exposing internal APIs without protection.
How Neonix helps
CybrWAF provides API discovery, schema enforcement, rate limiting and threat inspection, so the API estate is visible and traffic is held to its contract.
This note is an overview of the topic and of how Neonix approaches it. It does not report original incident data.