Securing the API Economy – The Last Great Cloud Transformation EP10
APIs are driving innovation by enabling seamless integration of cloud services, generative AI, and new digital capabilities—but they’re also expanding the enterprise attack surface. From zero-day exploits to authentication abuse, API security is now a critical concern as breaches can lead to data exposure and fraud.
In this episode of The Last Great Cloud Transformation, hosts Alan Shimel and Mitch Ashley are joined by Cloudflare expert Saikrishna Chavali to discuss the biggest threats to APIs, the limitations of traditional security measures, and how a unified cloud platform can help organizations protect their APIs without adding complexity. Tune in to learn how to secure your API strategy while continuing to innovate.
Transcript
Hey, everyone, I'm Alan Shimmel of Text Drug tv, and welcome to another episode of the Last Great Cloud Transformation. You know, uh, we've been doing this show for months now, and we hope you've caught some of the previous episodes, but if you're not clear on what it is we do here, you know, we're, we're seeing, we call it the last great cloud transformation, but what we're really referring to is that this next wave of cloud migration, if we could call it that, is a little different than what we've seen before for the last almost 20 years, 18 years, something like that. For many people, cloud migration meant moving from a private data center, whether it was a private cloud or, or just a, you know, posted in a private data center up to one of the public clouds, the hyperscale, cloud hyperscale, you know, provider clouds.
And, and a lot of times it was just a shift in lift from, from private to public. Other times there was some transformation, maybe moving to a cloud native microservice architecture, something like that. Um, but what we've seen over the last three years, five years, may, let's say, since covid types, right, is a migration not only from the private data center to the hyperscaler public cloud, but from there to the edge, from the edge to the endpoint, in some cases, from the public hyperscaler cloud, back to the private data data center or private cloud running things like Kubernetes on bare metal and, and so forth, right?
And so, really, our cloud infrastructure is everywhere. And so in many ways, this latest wave is the last great cloud transformation. Our partner for this show is our friend, our friends at CloudFlare Cloud, CloudFlare, which look, I think 22% or something like that of the internet travels over its network, right?
CloudFlare has come up with a solution, a, a aid in this last great cloud transformation, and they call it the connectivity cloud, because what they have found is, look, when you have a little bit of something everywhere, right? You get some assets in the public cloud, I'm in the private cloud, some on the edge, some exist on endpoints. Everywhere you need something that connects all of them.
And, and in connecting all of them, you're dealing with several key issues, latency, security, huge, right? And some sort of intelligence, I'm not going to use the AI word per se, but some sort of intelligence that knows where to go when and what to put, what where, right? Does this is, is the edge the, the right place for this?
Is the core the right place for it? Is the private this, should this be on a, an endpoint? So that's what we're talking about when we talk about the last great cloud transformation.
I hope that makes sense to you. Let me, um, introduce you to our panel today is we're gonna discuss just a, a small slice of this. We're gonna focus in on securing the API economy within the context of this last great cloud transformation.
Joining me today, first of all, from CloudFlare Flair. I went through all that time. I hope I get his name right.
Cy Krishna ChAARI. Am I close? Very close.
I'm s Krishna Chay. Thank you Alan for the introduction. Uh, product marketing at Cloud Flair.
Been in the security space for a decade now. I actually, uh, started off in application security and now back to the API and application economy. So excited to talk to all of you.
Absolutely. And hi, Christian, it's great to have you on here. Joining Side Krishna and myself, though is my co-host of the last great cloud transformation.
Uh, him and I co-host a whole bunch of things and we like to do things together for a long time now, he's a, uh, FU VP for DevOps analyst, Mitch Ashley. Hey, Mitchell. How are you, man?
Good to be there. And I'm glad I'm buttoned down in my cold little bunker here in Colorado. I'm getting some snow this week in cold weather, so you all might see a little bit later on the East Coast, so hang in there.
Absolutely. All right, let's, um, let's turn to the issue at hand, gentlemen, right? Securing the API economy, before we talk about securing the API economy, I think that we probably need to define what we mean by the API economy, right?
Yep. And you know, it's a term that's, I've, I've seen the term used probably for 10 years already, right? Eight years.
And, and really what it is, is so much turns so much of our economy, so much of our e-commerce, so much of our online digital presence turns on API to API communication, right? In fact, I'm actually doing an interview with Grant, is it Baz? Bazookas Berser, yeah.
From CloudFlare, uh, on this, and I've done in the past with him on this, a majority of all the traffic on the internet today is actually API to API traffic. It's a majority of all the traffic on the internet. So when we talk about the API economy, we're talking about a majority of every bit that gets pushed over the internet.
So, I mean, that's, that's the scale of this thing, but peeling that off, what do we, you know, what is this API to API traffic? So, Krishna Mitchell, do you want to expand on that? Sure, sure.
So actually, I, I wanna do a quick overview of, uh, APIs itself, because I think the API economy is a, um, maturation of how we have been using APIs. Uh, and one of the things that APIs compared to web apps or mobile apps, you're touching them every day. You're using them as a consumer, even as a, a business user, et cetera.
But APIs, you don't think about that happen behind the scenes, and they're meant to be behind the scenes. The, the value of APIs is that they can enable one system to talk to another system, exchange data, and do that in an automated fashion. And so all the automation that we talk about in the world out there is happening via APIs that are between applications, whether they are APIs in the, you know, software defined JSON format, or whether they're in older school formats, or whether they're specific to an industry.
It actually, when you think about APIs, they've always existed inside of applications not to the, to the public world, um, when there were service buses. But since then, and especially when we think about the first big push with mobile phones and mobile apps, especially the, when Steve Jobs talked about the App store, um, and then Google, Android store, et cetera, the Play Store, what it meant was all of those apps were being run behind the scenes via APIs. So mo the mobile economy provided a huge boost to APIs.
Second, we saw that, uh, the social and e-commerce space became a huge area whereby when you are just a very active uploading fo photos from your phone to the cloud, um, to back it up or put it on Instagram, et cetera, was all via APIs. And so that provided another second boost, uh, with the consumers coming in to play. And then what we are seeing in today's world, you know, uh, organizations trying to reimagine how their applications are built, uh, as you talked about Alan, with the re-architecting of applications, that was that microservices element behind the scenes to make sure they break down their applications, to talk to each other and talk each service talking to each other using APIs.
And the, the fourth one that we are living in today, that everybody is familiar with, generative ai, I know you didn't want to use that word, but I brought it in. Um, it is being run while a lot of us are using it via web apps, behind the scenes. It is all being run via APIs.
And that is how this API economy is continuing to explode, um, whereby organizations are now making money just like open ais and the other AI models, um, making money based on how much their API is being used and being integrated into other systems. So when you talk about the API economy, it has many tentacles, and it is continuing to grow, uh, in importance. You know, side Krishna, uh, excellent, uh, description, I think of how the ation of AI have taken place.
So I'll just, I'll just add to what you said and, uh, kind of build from it. One is, as APIs have gone from sort of the exception to being the rule, the exception was those are the few things we exposed to other applications outside the organization, outside the firewall. Um, maybe you mentioned message bus, but boy, I had a, I had a flashback there for a moment, going back to so architectures and things.
Um, but, um, but it's evolved even even beyond that to the point where we now think of, uh, AI a IS products. Many services on the net only are offered via API, that that's how you use it. You consume it, you might stick a front end to it, a web interface or mobile phone, but, uh, the service may be only APIs.
So you think about that as your storefront for your service is other pieces of code talking to your services through APIs. Another, another aspect that's changed, which is kinda how it's manifest, which you talk about in that, that fourth wave is, is what's called API first, where essentially applications are built around the fact that everything is an API, and it will all talk to each, each component, whether it's the user interface or some backend service, front end microservice, whatever it is, everything will talk via APIs. And what's interesting about that from a networking perspective is, you know, sometimes software and software architecture is a bit of a head scratcher for a network security person, or maybe even a network person that's really a network inside the application that's talking to itself over TCP, ip, whatever we're using, whatever GraphQL or restful interfaces, fancy words for different kinds of APIs.
Um, so it's, it's, we've really gone from it being the exception to being how everything works. And that's the, that's why you see all this traffic, whether it's over the internet and the cloud providers or inside your own networks. That's why it's all happening over APIs.
Agreed. I'm sorry, um, Mitch, it is, when we talk about that last great, uh, cloud transformation, it's again, back to the fact that the, at the app layer, you're exposing all of these APIs, but coordinating them, mm-hmm. Gaining them, making sure the performance is optimal, is all part of the cloud transformation that is so critical, even before you get to security.
And obviously security is a critical portion. Good point. Very good point.
Yeah. I want to turn to security and, and specifically around securing all this, but before we do, you know, so Krishna, you opened up the, the, the, the Pandora's box with the AI stuff, we warned you, right? It's gonna happen at some point in every cover.
Yeah, yeah. So look, this, this, this is a whole different ballgame, quite frankly right now, especially with the onset of, of a Gentech ai, right? Who do you think these, all of these AI agents are gonna be talking to people?
No, they're gonna talk to APIs. So if we think that a majority of the internet traffic now is API to API, how much of it is gonna be agen AI to API? Some may say that really what is, you know, a good chunk of very essence of what an AI agent is, is some sort of AI bridge, API bridge, right?
It, it, it's an API that lets you plug into everything, or that plugs into other things. So I think, you know, we're just at the beginning of the API economy and, and how much of it, or how much of the total digital world is gonna be riding on that, right? But let's, as I said, let's turn to security.
Well, before review, I just wanna mention this. Go ahead. This is so pervasive that my granddaughter told me she wants to dress up as an API for her Halloween costume this year.
That's how pervasive this is. Really? I'm kidding.
Of course. Oh, okay. You she's wired, dude.
Um, I'm the security, not just security though. So look, if something's this important, you know, it's the law of why we can't have nice things, it becomes a target. There's a bull bullseye on its back, so to speak, right?
Of, of how can that be disruptive? How can you know, how can it be disrupted? Excuse me.
How can people exploit it, hack it, make something out of it? And therein lies the problem. Therein lies the issue, right?
How do we, how do we secure this gigantic monster of API to API or API to agent communication? So, Christian, I know CloudFlare, I mean, you guys have put a lot of resources into this very issue. Let, let's talk about some of the things, you know, some of the ways and things that you guys have come up with.
Yeah. So we've done a bit of research into what are we seeing in terms of threats. So, we'll, we break this down into what are the threats we are seeing live, and then what are the problems around API security to do API security well in an organization.
Um, so in terms of threats, let's just kind of break it down. The, the actually most common threat that you see on, in, uh, kind of realtime traffic is business logic or d di distributed Nile of service attacks that are just hitting their APIs to try and either exhaust resources or to try and get into a service and then figure out what is a, what is behind that service at the end of the day, you know, an API is mostly a communication mechanism, and therefore they're trying to figure out what is that API talking to in the backend. Um, and that's something that we are seeing a lot of constant traffic, uh, around that.
Beyond that, when we think about actual data breaches, what's unfortunately very clear is that we hadn't fully thought through what needs to be behind a authentication mechanism. And then, you know, we are still, we're still trying to figure out what is the authorization mechanisms and methods that we go through. But even authentication, putting basic authentication is not something that was, uh, has been very common.
And therefore we have seen a lot of public major data, uh, breaches that have an API that's just openly accessible. So that's the second part. Now on that, when you're talking about leakage, you're essentially leaking data.
And the most important, uh, types of data that what we are seeing is attackers using that to do reconnaissance, to then use that in other attacks that are a bit more targeted in nature, um, because they found all these public APIs just spewing a lot and lot of data, um, that can be used in other places. So it may not be necessarily sensitive on its own, but it's a piece in the larger, uh, targeted attacks that we are seeing. And then lastly, what we also see is just like with, uh, applications, APIs at the end of the day are also code.
And so they can be vulnerabilities in that zero day attacks that we zero day exploits that we are seeing, just like with applications, they can happen with APIs as well. Just because an API does not have a front end does not mean that it will not have the, the code level vulnerabilities, um, given they may be written in similar languages to, um, the, the, uh, web application, uh, code that is, or the, uh, the, uh, code behind the web applications, uh, that we all use. And so being able to protect against that helps you protect against, as we think about, as Mesh has talked about the economy and Alan talking about how the economy will continue to grow, so will fraud, and we're gonna see fraudster trying to go after the APIs to get access to money, to get access to, um, credentials, et cetera.
And so that's the next area that we're, we're really seeing growth in, unfortunately. Yeah. Mitch, thoughts?
You know, I was just thinking about, um, not to bring AI back into the conversation, there's a lot of discussion about how did deep seek train its models, and it's done through something called reinforcement learning. And of course, um, the other aspect of it was as trained on open AI's models or other people's models kind of ing models models, that that's a great example of where automation comes in, where something you couldn't do on a large scale through any other way other than through automated API calls, uh, into applications or models or whatever it might be. So it's, it'd probably be shocking to, to just the average user or maybe us that has a little more technical background of how much of what's happening inside an app or looks like it's inside an app, actually taring through API calls and how our apps wouldn't function at all without it.
I mean, some of 'em wouldn't even start up, right. Couldn't present a user interface to you. So I'm, I'm curious, uh, as like, Christian, as, as you think about from a cloud perspective, when so much of the traffic is APIs rather than, you know, HT B calls over web browsers and, and email types of things, protocols, you know, the old, the old internet protocols, right?
That, that built the internet. Uh, how, how does that make you think about the cloud differently? Especially because customers like myself, we are a customer of CloudFlare, by the way, um, wanna put parts of our apps in the cloud, not only at at the Edge, but also in multiple places across your cloud instead of us trying to figure out how to deploy it to some point past the cloud?
Yeah, I think this gets to some of the, uh, big problems with trying to secure your APIs. So there is two parts to this broadly. One is, at the end of the day, APIs are written as code, just like web applications are.
And there is a portion of it, which is the typical vulnerabilities that, um, the s or open web application security, uh, project has, uh, kind of outlined as the top 10, uh, kind of risks are very similar between web applications and, um, APIs. So being able to protect against those so that they don't even reach your API servers, um, wherever they may be, is going to be super critical. The second is making sure that when you are, when you are looking at, uh, APIs, the unique part about APIs is they should have some sort of authentication and authorization on them.
And exceptions should be those that are un authenticated, that should be the exception. Whereas with web applications, a vast majority of the traffic maybe are not because they're just looking at, um, and reading data. But with, with, um, with APIs, that should be an exception.
And so being able to put that in place and then be able to enforce it function that developers don't have to come up with it, come up with authentication mechanism every single time they're creating a new API, which, which is just so very common in organizations, which, which just as an aside, that forces developers to become security experts. And why we want developers to know something about security, security expertise is not gonna be the first thing on that plate. Um, and therefore being able to standardize that and push that to, to the edge is gonna be so very critical.
Um, on, on the authentication side, and the last part is, as a security team, you're constantly thinking about governance. What is happening in, in my estate of APIs, applications, other assets that might be there? What are, how are they being configured?
Because once you have, you know, coded an application or an API, and then you have, um, put it into a release cycle and it's out there, there're gonna be multiple ways that it's being deployed, run, configured for different, uh, use cases. And so all of those can have misconfigurations. And we see that all the time today.
In fact, one of the things that we see is the, uh, problem of APIs leaking sensitive data, because once they, when they were first, um, released, they were very pristine, well done over time. You keep adding a bit of fun functionality. And over time that leads to things where just for that one use case, you will, you are, uh, uh, you know, able to kind of expose a bit of data, but now in another context, it is leaking sensitive data.
So, um, that is something that you need to be able to constantly be able to monitor and where appropriate without having to burden the development teams be able to put in place, uh, protections in real time at the edge so that, again, there's much less burden on developers and those that malicious traffic is not reaching your, um, your, your, um, a p servers themselves. And the way that connectivity cloud really helps in this context is to make sure that all of those protections, you don't have to put them in place at each of your data centers on each of your APIs separately. You can push, you know, rules into a, uh, common engine and then make sure that they're propagated at all locations that you are, that you are serving, uh, from which you're serving your applications on, in what we call an edge or a connectivity cloud edge.
Excellent. Excellent. You know, Mitch, I, I was listening to what you said and then what, like Krishna came with, I, I think one of the things I said earlier really is, I mean, it complicates thing, but it's so true of what, what, what applications look like today, right?
Our applications are dispersed, they're microservice based applications. And you know, when people think of APIs, they may think of, I'm a user of an application and I, and that's the A PII interface with that internal to external or external to internal, if you will. But in the microservice cloud native kind of world that we live in now, right?
Something like 70% of greenfield applications are built in a cloud native, uh, architecture, much more than that. External to internal. API is the internal to internal API, it's one container talking to another container.
It's one function of an application going out to a SaaS based API coming back in talking to another piece of the internal, right? Internally an API to API thing. As you know, our applications are sort of little Frankenstein's, if you will, right?
We're all stitched, they're all stitched together, stitch together. And what's, and what is the thread? What is those stitches?
It's, it's APIs. And so I, I'm going to guess that there's probably four x five x internal API calls for every internal or external API call, and they have their own security requirements. And that's, those security requirements have to be orchestrated, governed.
What have you managed, you know, whether it's at that COBE level, the orchestrator level, or the mesh level, right? Of how these things are, are talking to each other. But that's a, you know, and, and they're all, you know, let me add one more little complicator in there.
They're all over the place. They're in the edge, they're in the core, they're in the data center, they're on the endpoint. Mm-hmm.
It's enough to make you go crazy, right? Because that, now that's a job, right? If you could secure all that, that's a job.
I don't know if it a good analogy, but it, it's kinda like an air traffic control system of multiple. Yeah, it really is. Whether international travel, continental, you know, local, et cetera, it's 3D 360 degrees, right?
You mentioned cobe, Kubernetes, you know, and then the cluster has an API gateway and it does security for APIs. What can talk to what within that and other, other Kubernetes clusters. And of course things go outside of that.
And then service providers have API gateways and firewalls and things that control, uh, both security and authentication, uh, as well as traffic of those APIs. So it, it is, it's, it's kind of a cellular system almost, if you want to think with that way of multiple layers of, uh, how APIs work. And, and the good thing is the APIs give you a lot of autonomy in code and in design.
'cause I can create a, a microservice that just specialize in pulling data from Salesforce because I need these customer records from my application to process an order or to go get, uh, background information from, you know, say a science database that's got, uh, medical information in what I'm gonna occlude in some deliverable to a end user, some product I'm producing, but that can be specialized. So lets us build autonomous pieces of code, not, maybe it's a gen AI agents at some point not too far down the road that can go do, do its thing and not worry about the rest of the world of all the software and the APIs happening. It also lets developers go, eh, nail, okay, I, I know, I know where those API calls happen, or I know how to trace it down using observability tools and things like that around tracing.
Um, but it, it, it's a different world. It's a very different world than the days of I will talk over a solo bus, um, or a model if application. Um, but it's like everything, it's, it's just a different mindset has advantages, brings with it other challenges and, but the advantages outweigh the negatives.
And I think, Mitch, you, you mentioned, um, something around, uh, agenda AI agents, but that touches back to Alan's point, which is, you know, Alan, you were talking about there'll be one, um, a one API call between the, or many fewer API calls between external and internal boundaries. Um, and there'll be a lot on the internal side, totally agree on the internal side, but the unique part now is there's an even more blurring with gentech AI agents of what is internal and external when you are calling AI models to do things as a step in your application. And so you are, uh, a service may actually be calling, not the application, the application that everybody's touching, but a service that is trying to do some data analysis, trying to pull the latest information so that it can be passed to a user may actually just call on its own and AI model of, of some sort that has to do some data analysis and then be brought back to the application.
And now what is happening is when in the old world you had an understanding of, okay, here are things that are exposed to the internet, everything that the developers are doing behind the scenes, uh, I don't have to really care about that. Now you need to be thinking about all of those services as well, because those could be exposed. And when you are talking to another, um, AI models that are open source, you know, by third party commercial one, or whether it is sitting in some other location that you, you own, you are building your own, um, it just makes the, that world of API traffic even more complicated.
And one of the things that we are finding is, um, in the past, even just pre pre covid, think the pre covid days when APIs were still, uh, quite common, um, not as common as today. One of the thing, one of the things that customers struggled with was identifying what are all the APIs that my organizations have exposed? Because the security team is not everywhere.
And talking to every development team, now this problem has multiplied. Now it is not just what are the APIs, but developers, what are the AI models you're u using? 'cause almost always those are being discussed or, or that's being communicated with through APIs.
And we need to think about what is the data not just coming out of the API, but what is the data I'm putting into the, uh, into the API that is going into an AI model, whether it could be PO for poisoning purposes or leaking your organization's sensitive information. So I think those two things, especially with the world of agent AI, have become a lot more critical, uh, for organizations to deal with. That is the cutting edge of what we think of API security today.
You know, there's another dimension to this too, and that is, um, what, what goes hand in hand with API first software architecture is also stateless, which means, you know, we used to make calls, meaning I open a connection to this, whatever it is, on the other side, I do things across, you know, whatever that connection, the socket or whatever it was back then. Um, and then close the connection. It's kind of the difference between TP and Unity DP, right?
You know, am I doing a connection or open and a close or am I just sending it and it will happen? That's a lot of how software in order to scale and, and have that independence of microservices or whatever that function is that is providing or requesting the service, that's a lot of what scales this up. So that also increases not only the security, but also the manageability of those applications, because I can't take like freeze point time of the state of the machine and I can go see where everything is at.
No, you know, that that same process that requested that might've been updated two minutes ago or might've scaled from one to 53 instances of that microservice across the network that's distributed. So that's why we're able to get such high performance out of systems because we can distribute 'em through that stateless architecture as well as APIs and networks. I, I think that, I just wanna mention one thing on that, on the stateless point, because it's so very critical in, and it, it applies to cybersecurity in the sense that the CIA triad one part, one leg of that tool is availability and the importance of a stateless architecture, um, that can be ideally based, uh, edge, uh, you know, pushed out to the edge.
Um, especially some things that are, can be provided by a connectivity cloud. Enable coal starts to be diminished because you can be waiting when you're thinking about being very dynamic providing data. And this is of data we're talking about, especially with AI models and AI agents, that difference between a bit of latency is very significant to the user, uh, at the end of the day.
And so minimizing cold starts, and that is something that, you know, only in a, a, a provider and a that has been thinking about stateless architecture at the edge can, can really provide. Um, and that's something that we have definitely been, uh, seeing with a lot of customers, um, that they need, that those cold starts to be reduced so that whenever they call a function and it is on up, the instances on up, they're ready to take, uh, workloads. You had to mention cold starts.
It was 11 degrees when I woke up here this morning. So thanks for that reminder there. Like, Christian, oh, all right guys, we're about outta time.
Like Krishna, for people wanna get more information about connectivity cloud, securing their APIs and so forth on CloudFlare, where, where's the best place for them to go? com has very in-depth technical analysis on the latest cybersecurity threats and API performance and security conversations. Thank you.
Thanks Krishna. Thank you for coming on here today. What a great conversation, man.
Mitchell. Good work. I, I enjoyed, I learned a little too, which is always a good thing.
It's gonna wrap up though this episode of the last great Cloud transformation. Stay tuned. I think our next one might be a live round table again.
So if you watching this, you enjoyed it, you want to be involved in the next one, it's live. You could come in and chat your questions and comments and we will incorporate those into the show. But until then, on behalf of CloudFlare Text Strong Mitchell Ashley, Cy Krishna, help me shival Val Ali.
I always think give it a little French there at the end. Shival and myself, I hope you've enjoyed this episode. Take care.
We're out.


