State of API Security 2024 Report with Imperva’s Lebin Cheng
Lebin Cheng, head of API security at Imperva, reviews highlights and insights from the recent State of API Security 2024 report. With the majority of internet traffic now flowing through APIs, cybercriminals are increasingly targeting these interfaces for direct access to sensitive data. Lebin shares API attack trends Imperva has observed over the past year and the steps organizations can take to protect their APIs. Download load the free report at https://www.imperva.com/resources/resource-library/reports/the-state-of-api-security-in-2024/.
Transcript
This is Textron tv. Well, the great pleasure of being joined by Lebin Cheng. Levin is head of API, security at, um, at Imperva.
Welcome. Good to have you. Great to be here.
Levin, tell us a little bit about your role at Imperva. So, uh, as the, uh, title implies, I am in charge of anything to do with API security. I joined Imperva through acquisitions.
Uh, Imperva acquired my company, a small startup called Cloud Vector that focused on API security. And, um, so what we did is we actually focused our attention to API transactions and talk you security folks in our, um, customer base to actually better have visibility and also deal with new threats to, to the API express the data transfer inside a PII remember that acquisition. I think I was, uh, doing an interview with one of the, one of the SBPs that are very excited about you coming on board.
Well, it's, uh, couldn't, the timing couldn't have been better. I mean, certainly API security is still top of the list. Very, uh, important topic in organizations.
I know that you all do a lot of, uh, you know, as well as work in the area, of course, doing some reporting around what's happening. Mm-Hmm. And you issue a, uh, state of API security report.
I'd love to hear a little bit of sort of what's happening, either what are you seeing, uh, in, in the world of security or even maybe what you're hearing from your customers, what challenges might be out there, what kind of things would be helpful for folks to know? Sure. So, uh, you know, uh, without going into too much detail, all, you know, we actually published this state of now trying accept this cadence for every year.
And, uh, we actually seeing the trends in moving, uh, year over year, where the adoption of APIs by enterprise companies, and actually the data that transmit inside API increasingly being, uh, sensitive, being critical to business because APIs are increasingly being adopted by business critical, uh, uh, applications. And that definitely is a trend that we identified, which pretty much kind of, uh, validates what, you know, I, myself and a couple of us, see when we start the startup, you know, many years back. And when we try to convince people that security will be a thing, and now, you know, the, the state of API make it become a thing.
And, uh, there's a lot of kind of, uh, trends behind, uh, why API adoption would become so per, per, you know, now we actually seeing constantly API consisting of the majority of the enterprise web traffic, you know, more than 70% in some cases, 80%, and depending on what you measure. And, uh, the, the, the, the fourth behind that is really, uh, automation and also cloud options, you know, and, and let's big cloud also, and the need for automation at the end of the day. And because of, you know, the advance of many other, uh, uh, fields including AI that push you, a lot of the customer ex, uh, expected even the business transaction become automated.
And an API is that, you know, lingo power the automation, And of course so much of that automation is relying upon the APIs on two, three, whatever number of services or applications that are involved in that. Also, kind API first design for applications and we see so much more. It's no longer just the outer shell, inner shell access in inside app or a, a data source.
It's really how things are being built. Yeah. Precise.
You know, you, you, you take a kind of hot example like, you know, chat tt, you know, you people, you know, data use and using interface to, you know, loop people into interacting with IT to learn from that. But those are free services in order to monetize, actually they expose APIs. But sure enough, you know, once check GBD become very well known last year, the first active check G BT data leak was reported again, you know, actually one of the chat GBD api.
So when, when it comes to API adoption, then the security issues has started to arise. Yeah. I noticed that even with the, you know, metcha PT cloud is another cloud three, cloud three, um, you know, they're really tailoring their service not just to the end user prompt, but also through API access.
Exactly. Making that easier and easier to iterate. Of course, that, that adds a lot of stickiness of course, to the app too.
Exactly. So that, that's why, you know, that's the attraction of API to developers and to enterprise customers as well, because it's so powerful when you allow them to better search their clients, allow the client to automate the entire process, and it allow them to interact with business partner, you know, much better because they are also API I driven account themselves. So it's almost like a network of facts.
Exactly. Mm-Hmm. Yeah.
So curious, um, any changes or insights into the trends of what's happening with the kinds of threats and also, um, the approaches that people are taking to protect APIs better? Yeah, so, uh, that's a great question. And you know, there's two parts to your question.
You know, I wanna maybe answer them one at a time. The one part is, you know, uh, what is the abuse? What are the attackers?
And then the other part of your question is, you know, do I see anything change in terms of the protection of API? And that's when sometimes the, the values something where I see actually the attackers see the threat landscape actually starting to shift pretty significant. However, uh, unfortunately, you know, uh, a security when it comes to protection mechanism is still a little bit lagging, you know, in, in general when it comes to people's awareness and when it comes to people's, uh, adopting tools, new tools and new ways to protect APIs.
So that maybe go a little bit deeper in the first threat landscape. And one thing about API is such that it is actually, it's API is just interface to application. So it, you know, is the same API is, uh, susceptible to maybe ddo s or the conventional web attack, like injection attacks or cross site tripping and anything like that, you know, or, or conventional bot attacks against APIs.
And that is sufficiently dealt by conventional needs like web application file, et cetera. And, you know, because in perva in general is, is a leader in that. So we actually have the opportunity to cost a lot of customers and somehow, you know, we, we did a good job over the years, you know, for protecting applications from those ice, like it to be, uh, you know, uh, smash and grab kind of attacks.
You kind of, you come in kind of good forward thought. And then there are, uh, uh, uh, increasing trends of threat and abuse, uh, that is actually starting to get smarter. It's is less of a smash and graft, it was more the targeted, uh, a API abuse, and that is targeted against API threats that are API specific.
So for example, we are starting to see, say broken optic authorization type of attacks that only effect of, again, one particular version of the API, but because it's very self and because it's confident, again, that one API, there's no no, uh, signatures or no, you know, this existing tool does not recognize those abuse and that that carry, uh, out what we see is one that was, that vulnerability was found and exploited by the abuser. Usually when, when the abuser was fought, it was way too late. Millions and million directors get extra trade already.
And, and we are seeing actually increasing risk of that has happened, and then we reported it in our report as well. So that is the, uh, the in increase in a specific sophisticated, this logic targeted attacks on in the, on the increase. But because the, um, people are increasingly exposing their services over API mm-Hmm.
And because of that kind of sophisticated nature, the attacks then existing tools becoming, uh, less and less effective against those. Then what we found in terms of protection is there's a lack of awareness, you know, actually in, in the past. And now I think we are seeing some increase in awareness of that, where a lot of, uh, uh, um, organizations sometimes we talk to have a false center of security.
I put my API behind a web application firewall. I enable bot protection, enable prevention, you know, or even I, a gateway check all the authenticated token and done, but I pretty safe. But unfortunately, you know, uh, natural surprise happened with some of the organization where, you know, uh, people comes in, find vulnerability and they actually, you know, drill into those and actually data happen.
I'm curious. That's all extremely interesting because you know, so much more, you know, we, we, we talk about all the different kind of threats, ransomware and all kinds of different things, but it seems increasingly, especially with AI on the forefront of, you know, gen ai access to data is extremely valuable, whether it's encrypting it or doing something, you know, nefarious to exactly, to, uh, you know, to for ransomware kinds of things. But just getting that data, getting that information as well as account count takeovers and compromises of systems, any trends in that way?
Anything new happening in the data front or what people are doing when they are trying to compromise through APIs? Yeah, so, you know, a lot of APIs, they are useful only if they deal with, you know, useful data. So, you know, uh, so what we find is, uh, uh, you know, a a given any organizations, you know, the usually have a good number of API endpoints in the hundreds and the a p endpoint usually, but there's a, uh, there's a significant number of those endpoints are transacting, uh, sensitive data, you know, just, you know, uh, hypothetically let's say, uh, you have a, you know, food ordering services.
Then of course there are a couple of big APIs where full the personal data, you know, whether they your credit card, et cetera, right? You know, let alone, you know, you have open banking APIs and they actually deal with customer data, very tentative financial data and, and those data, you know, exposed to APIs and necessity, you cannot just say, okay, I block everything that exposes sensitive data. But then the, the problem comes in when the developer sometimes, you know, in a rush to develop functionality, maybe there's the bond group between, you know, individual data are not enforced sufficiently enough.
Then that is when you know things, uh, uh, go back because then a bad actor can actually log in as a legitimate user. Like, you know, I can register in free account with from application and I can just try to poke around and if there's a way for me to get to say, you know, Mitch data or Aaron's data or anybody's data, then you know, that become a problem. And, and that was recognized as the number one threat in terms of a p security, right?
Booking level authorization. And, and that kind of, um, abuse is extremely hard to, uh, catch because I lock in as between user or my request actually look rigid, and it's just that I'm crossing that boundary really startling. And, and, and that's, that's when first the most, because no, nobody trigger any alarm.
It's almost like, you know, somebody coming into a bag, but, you know, somehow trick, you know, the bank counter from, you know, giving in somebody else money, but everything looks calm, you know, there's no, nothing a normal you on the surface. And so that's, uh, that that's the thing. We, we are, we are seeing an increase.
And that when we, uh, when we discuss with, you know, customers like, you know, banking in the banking industry or in, you know, other commercial website operators, they all looking for ways to, uh, candidate, you know, not, not even just to say block it, but to say, you know, can, can we get a early alert to actually see if something happened to, to my application? Mm-Hmm. You know, and one of the things from the, uh, report having seen versions of it is, um, business logic attacks against the business logic.
Talk about what, what that is exactly. Yeah. So using the previous example that attributes logic, right?
You know, I log in and then the business logic is, you know, 11 locking and I'm fetching elevens data and using it to render some services to me, right? And that business logic. But if that logic does not enforce the boundary between users sufficiently in certain cases, then, you know, I can get to other people say, so that's one example.
And so those, those are in the rise. And, but when we try to pose this problem in general, right? Trying to help for our customers, uh, one thing that occurs to us is it's not all, it's not all bad news because this kind of business abuse is very, very hard to catch when it occurs.
However, for the bad actors is also for them, is not like very easy to explore because they have to find the same vulnerability also, right? So what we are seeing is actually the bad actors are leveraging some advanced tools, especially makes their bot with a little bit more smart in order to actually look for vulnerability first so that there's a prolonged recognizance phase to many of these significant attacks. And that the phase, uh, as a defender, I want to attack that phase to actually try to make that phase much longer or impossible for the bad bad.
So that's the entry point, becoming trying to solve a problem Problem. It'd be much different if, um, someone was able to compromise an API to transfer funds, let's say, for example. Exactly.
Versus, you know, ordering appliances or something to showing up to some address, right. It might be of interest, 'em, but you know, obviously it's tougher to take advantage of that kind of a, a business logic exploit. Talk a little bit about, um, also you said the automation of, of this when you're, are you talking about automation of work that's happening through APIs, or do you mean automation of the actual attacks themselves?
Absolutely. So, uh, you know, with the of, you know, uh, that is very, uh, trendy call AI and all, I think about AI being able to generate for you and think about your actors and your create, crafting a bot to explore API, but APIs are very specific applications, so different people's APIs are different, but they're more or less the same. So that actually make it very right for ais and something to come in and they reach the API spec of a particular API and generate a bot to try to explore.
And the, the same thing that, uh, kind of empower applications, sa development automation at the same time double edge sword. It also make automation of a bad bot looking for, uh, a tax a little bit easier, right? You know, you automate also the work for, uh, so, uh, the only answer for that is, again, another automations where we wanna automate a security measure and just like, uh, you have a security camera you anchoring and looking for people's behavior for the bank, and you cannot just, you know, uh, throw the camera or if you cannot expect a human, they actually look at the camera 24 7.
But as again, you have some, some kind of automated, uh, pattern recognition, the weapon has normal pattern and then compare to the abnormal pattern. And maybe that's the whole to, uh, to catch, uh, uh, it's almost like arms phrase. You have automation of this logic, and then you have automation of exploit.
And of course security measure need also to be highly automated so that we can, we can catch from related explore. You know, the, one of the things about APIs is the good news is they're relatively easy to create and they have a lot of power and capabilities when you do that. The, I guess the other side of the coin is, you know, you have to manage them, right?
Exactly. They're, you need to manage them as an asset because you may need to deprecate they change over time. Who knows, even the proliferation of APIs, you may have an applications exactly.
That exactly might not be aware of in the security team. Is that, is that something you would rely on, let's say a web application firewall or even an API, um, proxy or a firewall type of solution to help you kind of get your arms around what exactly is coming in and out of your applications? Uh, that's a great, uh, point.
Uh, yeah. When we talk to you organizations, you are looking to solve this problem. Um, they are, uh, a API itself is, is highly specific and highly dynamic.
That's important job. And that make m is alignment because couple with rapid development, IT CI CD process, and we have authorization that no longer have a nine month cycle for the application update. We talk about fraud is also some aggressive, you know, web company.
They talk about daily. Then imagine you have some, you know, old ways of appearing the security problem that you do reviews, you do, you know, posture, you know, you, you say, okay, this, this version of a P is safe, but then the next, next day, next, next month, maybe I changes then, you know? Mm-Hmm.
It's all over again. So you can never, you, you can never play catch up. But the, the good news of that is also if, if you apply, you know, automations to actually, you know, handling the A ts three platform and also with a focus on data and this logic maybe, um, um, maybe that without, and going back to your point about a p gateways and gateways, it, it definitely is a must because, uh, not because they can catch all theological attacks, but because it's kind of future ask all the low hanging fruits for the bad activists, right?
Because we don't want say, oh, you know, physiologic attack, I listened to this talk and you know, I have some, some, some people wanna say, Hey, jump right into, you know, very sophisticated AI driven, you know, API security forget about, you know, but they forgot about the, and we soon give a very good wa you still, you need a very good API gateway because it, it prevent, you know, the obvious, right? Those smash and graph stack like d os, like injection, like, uh, schema violation, you know, obvious similar violation or an authenticated API calls, you have to configure your API data. So those, those be effective against it.
So you, you, you filter that thought out, then you can focus your attention on the kind of the last mile of security, and you apply some, you know, more sophisticated and automated measure, then, then you have a hope of kind of catch them off. But it's a 1, 2, 3, you know, the API gateway and on one and two and the last mile is the number three step, which is the a visibility and trying to solve this logic for It seems also like, um, having the right strategies in place would be critical for incident response, right? Because if you're not, if you don't have your APIs, well-managed, they're not going through some type of a, a, uh, process or proxy or web, web application, fire, all that, you know, it's sort of bare game is all open.
You don't know what's happening across your applications except maybe to dig in through individual applications logs, and that's pretty tough to Right, right. Put back together. It seems like this is a super important resource for you from a incident response and knowing what to do to take corrective measures.
Exactly. And, and, you know, and and least, uh, the, the valve and EPI gateway will, will give you enough locks and also you, you, you will be, when when something happens, you know, that you, even the root cause would not be, say, a injection attack because that would have been solved by, by the web application firewall. It, it should not be an authenticated user coming in because the HVAC gateway should have to stop the bit, so at least it kind of filter out 90% of the noise.
Then, then you can focus on the last, um, last mile and the, and the, and the last batch, because a lot of incident response, you, we talk to the soft people, right? They're overwhelmed by, by the incident that comes in, right? So anything to reduce the number of incidents that come in, it could help.
And so that the attention can focus on things to get the kind of the smartest, you know, bad actors Yeah. And reduce the number of incidents and speed, the resolution of the ones that are validate what really is a, a factor. Yeah.
Any, any other insights? Anything else to kind of jump out? You, you kind of, where we're at now with APIs maybe from, you know, it's been what, about three years or so since you've joined inva?
Yes. And, uh, things have, you know, things have moved rapidly in the world of APIs in that short period of time. Yeah, yeah.
So in general, I, I feel a little bit of, kind of indicate in some way where, you know, API security is becoming more and more a front and center problem and issues. And because API itself is proliferated very rapidly in, in the last few years and also becoming adopted by major organizations, right? It becoming harder than harder to talk to any customer, say, I don't use any a AI at all.
It used to be, you know, uh, uh, we have some of those you say, oh, I don't have security problem, I don't use a P at all. But now it turns out actually a lot of those, when they look back, oh, you know, we actually use a ai, we don't know about it, security don't know about it. Um, and something that, uh, uh, comes out, you know, uh, is the, the, the level automation, especially in, in the evolution of say, traditional bot, uh, is a little bit surprising.
And it actually back that now our most recent report as well is, um, you know, when you think about bot, right? You, you, there was the conventional kind of, uh, scripting box, right? Somebody to come in, you try to buy tickets and buy, uh, Pokemon you, uh, credit or whatever it is, right?
Uh, nothing to do with the active Pokemon, just as example. And, uh, but uh, now we are actually seeing bots are less when, when, when bots are increasingly being used to target APIs. And the one thing about them is that APIs you cannot use capture or, so those, you cannot differentiate a human versus a bot, you know, as a, a major means to prevent bot because APIs are meant for bot.
You have to really have a new way to differentiate good bot and bad bot. And we are actually seeing, uh, bots are increasingly targeting API for, for example, account over attempts because a lot of API registration, user registration, and those are through APIs and even your phone, you know, actually, you know, when the, and trying to validate itself, it's actually leveraging API as well. And some, some, some hacks actually successfully actually happen some video phone by leveraging a p on the back end so that there's, there's, uh, there's a little bit of surprise and we not call it completely surprise, but there's a little bit surprise of the search in bot, uh, kind of, uh, uh, hack itself as a food bot.
It behaving is getting more and more kind of, uh, uh, similar, similar to actually a, a regular fine application would behave. And that makes it very, uh, uh, difficult to differentiate between that actors bot and, and, and so the, the feel of bot and a food is converge actually starting to converge. Very interesting.
Well, thank you so much for sharing with us. So, you know, it's a vast evolving field and you know, of something we're using more and more of every day. Where can folks get a hold of, uh, the information about, uh, the research you've been done?
com and we actually, uh, publish our latest API reports and you know, you have, uh, my information as well. You know, feel free to reach out and, you know, uh, in general, I think, you know, uh, security, you know, uh, vendors or security, uh, folks, you know, we, we all evolving our understanding and, you know, uh, let's just have a conversation and we tested this together and I think it's a solvable problem for, for a, Yeah, that's great. Uh, great section of your site on application security, that's got a lot of resources on it too, so.
Sure. And take advantage of that. We'll put the link into the report in the description as well.
Well, Levi, it's been fascinating talking with you. Appreciate you sharing all the insights that you've gained and continue to develop and, uh, wish you and the team at Imperva the best at, you know, keeping all the bad guys away for all of us. Yeah, thank you, unity.
I really enjoyed the conversation. You Bet. Uh, 11 Chen, who Chang is who with, uh, head of API security with Imperva.
Thanks for joining us and hope we get to talk again soon. Thank.