API Sprawl: Vulnerabilities, Threats and Risks with Lloyd Newton | SecOps Vision 2024
The prevalence of microservices in application architectures has many benefits, but it also has some unintended consequences, including API sprawl. And that sprawl is more than just an inconvenience, there are very real security implications not just for the application itself, but at every step in the software supply chain.
As an example, consider the rise of virtual data centers ushered in by the wave of virtualization. So many virtual machine images were created and abandoned without decommissioning; organizations were then faced with high capex costs and unused storage space. In a similar way, APIs are created by developers without deprecating older versions or maintaining both versions to avoid breaking change. The good news is, API sprawl can be controlled with the correct use of security and assurance controls, including application threat modeling.
In this session, Lloyd Newton from SGN will explore the issue of API sprawl and the risks and vulnerabilities it introduces. Then, Mr. Newton will discuss how to tackle these issues from a security governance and audit perspective and recommend best practices
Transcript
API sprawl, vulnerability, track, and risk. Well, uh, welcome everyone. Basically we want to look at API sprawl today.
Uh, uh, interesting topic, I would say, but, uh, very complicated if you ask me. Uh, introduction of, uh, this particular topic has to do with the fact that, uh, API application programming interface, uh, is seen as an unsung hero of the digital revolution. Many see it as a revenue generator because it's the glue that sticks together, diverse software components in order to create new user experiences, but in providing a direct path to backend databases as well.
So this has become a, an attractive target for threat actors. In, uh, recent, uh, statistics that were churned out by Barracuda, 97% of global IT leaders agree that successful executing an API strategy is vital to future revenue and growth, like I already mentioned. And the fact that there may be tens or even hundreds of thousands of customer and partner facing APIs in large enterprises makes this even more, uh, more a topic to think about.
Question now is, what is the API security? Uh, so putting this into context, and, uh, as you are aware, we basically talking about security and how to secure our APIs in our organizations that, well, API security focuses on strategies, you know, and, uh, it looks at how to mitigate vulnerabilities as in understanding, uh, solutions in, in mitigating these vulnerabilities that exist in our organization. I would quickly go into how, um, APIs, uh, began, uh, but not really bore you much about, uh, the fact that it exists in our organization or in our world today, talking about vehicles and smart, uh, uh, smart, uh, phones and internet of things being, uh, very prone areas where you find APIs.
How did APIs, um, become a sprawl? And if we say something's become a sprawl, we all know, uh, we are talking about the proliferation. Proliferation, sorry, about choice of words, my pronunciation.
Actually, proliferation is the word, actually. And, um, you talk about ammunition, proliferation in the United States where everybody's buying, uh, guns here and there, uh, becomes, is becoming uncontrollable, uh, in just various parts of the world here in the UK as well. Uh, though we do not have any laws to allow free purchases of such.
But, um, you, you, you can picture or have this image in mind when you look at, you talk about sprawl and in the it, uh, or technology, um, area or context, we want to think about VMs. And having worked in the data center for the last, uh, uh, uh, years or so, actually worked for five years in the data center. I'm very much familiar with VM images and hence, uh, how this emerged and became a, a problem instead of a solution for, um, the, for the data center where I work.
And so you have VM images being churned out, and, uh, once they are churned out by virtual, uh, virtual, uh, by, by, by, yeah, administrators of, of these, um, data centers or virtual infrastructures, a, it becomes difficult to decommission these, um, once the, the, you do not have any use for them. So there's a particular purpose for which you would want to, um, greater vm, uh, and its image. However, once you've accomplished that purpose, uh, decommissioning these, um, becomes a daunting task, uh, uncomfortable removing.
What these workloads is, is basically what I'm talking about. APIs have become like such, you know, and, uh, we talk about public facing networks in your organizations and how developers want to use APIs in, uh, yeah, in deploying various applications and softwares. Uh, it's become such, uh, as a problem instead of a solution.
And so these is how these sprawls emerge. You know, the question is, who cares about APIs? We are not here to do a finger pointing.
Uh, however, it's, it's, it's key to find out where this, the, the course or where root cause analysis and point out where these problems are, uh, can easily arise, uh, in terms of, uh, where the threats are. Okay? So you are looking at the, there's a tendency for API to get created without a clear plan, uh, uh, by developers.
Then you're also looking at a situation where developers, after creating these APIs, um, whether through, uh, an HTP get or h TT P posts, uh, or the URL on which it's hosted, it can be difficult to do these things because of the other components that have the API as it dependency. So the developer then realizes that instead of, um, um, yeah, duplicating the old version of the API, uh, which is impossible, then decides to retain both the new and the old APIs. And hence, that causes even the sprawl that we already talked about, uh, the issue of vulnerabilities and, uh, how to identify these vulnerabilities.
A typical example you'd want to consider is the VEB that requires a, a query parameter example is the H TT PS, and you would have noticed that in this particular URL that you see on the screen, you have, uh, a super secret, uh, value, uh, even a username showing. And then a super secret value also showing this is basically hashed in our, um, in our browsers and in our, in the history of these browsers. Uh, basically this, for me, it's more of a, a behavioral, um, risk that is churned out from dev, DevOps and SecOps behaviors, uncontrollable behaviors, uh, discipline and fair, fair, fair to say that education is well, well, uh, provided some of these things will not, will not, um, happen.
But before we even delve into ED education and the mitigation aspect of things, I would want us to look at another area where you'd have, um, ops, which is actually a standard for, uh, yeah, software development and software development. SDLC software development lifecycle and ops, uh, is wellknown for shutting out the various areas where, uh, you have API security, uh, focus, focus and strategies. Uh, one of these areas has to do with a broken object level Authorization.
APIs tend to expose endpoint that handle object identifies, and, uh, you'd want to control the access, uh, surface of object, uh, level access controls you need to put in place access. So control and authorization checks, uh, are key here, uh, in order to get past this particular kind of, uh, uh, risk or, or, or vulnerability. A number of them, uh, is what we see here.
Um, broken authentication, uh, typical one is attack us to compromise authentication tokens, to exploit implementation flaws to assume other users identities temporarily or permanently. So some form of engineering here where user carelessness or of any form may have exposed their passwords or may have exposed their, um, keys or organizations may have exposed their keys, uh, on various, uh, yeah, public, uh, um, sites, uh, public cloud, uh, or better, I want of word and compromises. Okay?
Every now and then, uh, we've heard about various speeches. We would see some of them even in the next, uh, slide where we talk about the impact. You know, uh, I would not want to bore you about the ops, uh, uh, uh, top tens.
Uh, you could always Google these and find them online, but just to let you know that these are setting areas that any organization would want to focus on and understand what the top 10, uh, threats are with regards to APIs they have. So, yeah, so there are about, there are 10 of them, which you'd want to look at. Then I quickly want to talk about the impact, uh, on firms.
Now, if you, you're there and you think that this would not, has, has no, uh, bearing or would not affect you, then you need to look at these figures here, which is pretty, uh, serious. Um, a study showed that 94% of global organizations have experienced API security problems in production over the past year with nearly abit suffering and API related breach. That is not something anybody would want, you know?
Uh, the threats are also far from theoretical this year when we have seen T-Mobile USA admit that 37 million customers come on, 37 million customers who would want their customers to go through this. Uh, you know, come to think about in Europe where you have a lot of, uh, ities turned out to, um, yeah, turned out to organizations. Uh, the, we have the GDPR penalty.
We talk about all these regulations and the penalties that there are, uh, organization in the, in the sector or industry where I work, you have the off jam, uh, penalties to any organization that deals energy and, uh, and there's a leakage or there is a, a compromise of personnel information, account information, or personality identifiable information. Uh, you don't want malicious actors having access to your or taking control over your APIs. And so this is where the impacts are.
com. Yeah, so this is for people who love traveling, and I'm one of them. So you'd want to be careful when you, you are accessing these sites, uh, that you book your travel plan, you making your travel plans and want to book a book, a book a yeah, holidays.
You need to be careful what kinds of APIs, what kinds of URLs, what kinds of vulnerabilities exist, uh, if you're doing that, uh, for your organization and, and the likes. So yeah, basically, these are the impacts that has, uh, there are more actually, but I just wanted to choose this, uh, for, for, for now. Then, uh, quickly want to talk about mitigations because, uh, it's what we want to know how to control or how to remediate these, uh, issues when they crop up.
Governance is key. Governance is key. Why, why, why do I say that?
Governance is basically something to do with, uh, commitment from the top, from the, the, the hierarchy, top hierarchy, um, from the board level, very, yes, the CSO of the organization, for instance, wants to, uh, assign a budget to maybe a software that can, that can have a, uh, an API gateway in place. And all these softwares cost a lot. And if you do not have, uh, yeah, you don't have a board sign off or authorization, then basically where, where, where do you, where do you get to with this?
So you'd want to look at, uh, you'd want to look at a situation where the board, you have, uh, the board supporting you with some of these things, and then you would then want to, uh, have tools in place. So we have tools like swagger, like Red Dock. Uh, these are tools that organizations use to understand where their APIs are.
So a scan, for instance, is done uhit, the number of shadow APIs already in the organization. So this would, uh, help very much in know, in controlling the sprawl, you know, so you'd want to have, um, um, a tool that shadows and make sure that you are not over creating APIs or you're not creating APIs that are not necessary. Uh, those with dependencies are basically, um, identified.
And then once you want to implement any more APIs or develop any more APIs, you would know what to do once you have visibility. A web application firewall, yes, uh, ski, um, there are a number of them out there. One of them moves out there, uh, uh, has a gateway can, can definitely, uh, give you control and access, uh, and block any form of, uh, malicious traffic that could cause exploitation to your APIs, you know?
So, um, yeah, you have, uh, AAWS waf, um, you have, uh, all sorts of WAF firewalls that you could, you could implement in your organization to check this. 2. 3.
So these are things that will help you, uh, avoid money, the middle attacks. Um, then you talk about, oh, or for controlling API access to resources like websites without exposing your credentials. Um, which is also key.
Um, once there's a breach, once your credentials are exposed, there's easily, there's easily going to be a breach apply rates limiting to restrict how often your API can be called. Yes, that's also very important user monitoring tool to log all security events and flag suspicious activities. So yes, uh, these are all things that we could, uh, employ or implo, uh, implement in the organization to control our, uh, APIs from becoming a harmful, um, yeah, tool than rather generating revenue for us.
Zero trust. Many of the organizations I know of today, uh, uh, are at, at at some, have a project going on to implement zero trust. Um, some ha haven't have, have no idea how to go about it.
Uh, it's key that you do this. You put in place zero trust and ensure that, uh, digital trust or, or digital or, or, um, your security is, is, is trusted. You know, 'cause this has to do with behavioral as well, you know, so it, it's important that resources that are being used are, are checked, uh, every, every point or in every, um, you know, point of the cycle of production and the likes, authentication, authorization, the integrity of, of data and the likes, you know?
So, uh, this is basically what we would want to achieve and ensure that, uh, APIs are well secure. Safeguarded wanna give you a of a philosopher, uh, talked and sorry for moving my camera just to give you this one. Uh, not moving it because of the philosophical reasons, but I respect to one of our philosophers would say that, and which comes from this, uh, popular one from metaphysics says the totality is not as it were a mere he, but the whole is something besides the facts, APIs existence and the usefulness cannot be overemphasized, and they actually play a key role in, in, in, in our work as security people.
And hence the need for us to pay attention to them. Thank you.





