API Security's James Webb Moment
The James Webb Telescope reveals emerging stellar nurseries and individual stars in the Carina Nebula that were previously obscured. Credits: NASA, ESA, CSA, and STScI.

API Security's James Webb Moment

it's not what you don’t know that gets you into trouble. It’s what you know for sure that just ain’t so. We have been largely unaware of the totality of our attack surface, trusting legacy security tooling to provide us with a false sense of security. Today, APIs make up the vast majority of traffic, but they go largely undetected because our proverbial telescope is unable to spot them. If it does "see", it lacks the context to understand how to interpret their behavior.

If we look at the Hubble photo below showing the star forming region in the Carina Nebula in optical light, it is very difficult to see what is going on inside these collapsing pockets, because of all the surrounding space dust. Dust acts like a thick curtain to regular telescopes.

No alt text provided for this image

We therefore need a strong telescope that can pick up this infrared light from the star forming pockets, and the JWST can do exactly that, in addition to spectacular resolution.

No alt text provided for this image

It is clear that the extra detail is not only due to the increased sensitivity, but also to the extra information that is simply not retrieved with the Hubble telescope. Take a look at the dark regions on the Hubble photo. These regions are not empty or passive. They are simply opaque to Hubble’s camera, and hence the telescope does not see what goes on in these pockets. But in the JWST photo, you see a plethora of activity in these otherwise dark and hidden regions.

Similary, relying on your WAF (Hubble Telescope) to provide API security will lead to blind spots and false negatives. As APIs mostly use HTTP protocol and HTTP methods to communicate and exchange data between systems, it is no wonder we started with a familiar tool (WAF), but it is now clear (weekly public API breaches) that this is not the way forward.

No alt text provided for this image

The API security platform provides the "extra" information, or context if you will, to understand how the APIs are being used, what their security posture looks like, and how to spot misuse. The information from the WAF is still useful, but can be extended to look deeper into the API transaction (JWST), as opposed to only the HTTP transaction (Hubble).?

Karanvir Singh Attwal

Senior Solutions Engineer @ Akamai Technologies | Pre-Sales

1 年

I love this! ??

Curtis A.

Enterprise Sales @ Akamai API Security

1 年

Great comparison!

要查看或添加评论,请登录

Filip Verloy的更多文章

  • Rubrik Cloud Resilience Summit Recap

    Rubrik Cloud Resilience Summit Recap

    Last week Rubrik held it's Cloud Resilience Summit, which is available on-demand in full and I highly recommend you…

    1 条评论
  • The Problem Is Not That You Don't Know What to Do, The Problem Is That You Haven't Been Doing What You Know You Should.

    The Problem Is Not That You Don't Know What to Do, The Problem Is That You Haven't Been Doing What You Know You Should.

    We've all been there. Another major data breach hits the headlines.

    4 条评论
  • A reMarkable 2 Review

    A reMarkable 2 Review

    Since I and many others have started looking at the reMarkable tablet for work, I thought the review would not be out…

    30 条评论
  • NIS2 has failed already!

    NIS2 has failed already!

    An often heard, maybe slightly denigratory, question when it comes to Belgium is “Oh yeah? Name a famous Belgian… “ But…

    8 条评论
  • The Cybersecurity Paradigm Shift

    The Cybersecurity Paradigm Shift

    An often heard concern from customers is that they need to manage too many security point solutions, depending on the…

    4 条评论
  • Sharks vs Cigarettes

    Sharks vs Cigarettes

    A plastic shark in the movies will keep people from swimming in the ocean, but a warning label on a packet of…

    1 条评论
  • Embrace the power of boredom

    Embrace the power of boredom

    We have ignored the power of boredom, because the world keeps distracting us. Seasonal changes drive us to think…

    2 条评论
  • Doing more with less sometimes takes a little investment.

    Doing more with less sometimes takes a little investment.

    In times of economic uncertainty, businesses need to be mindful of their technology investments and how they can be…

  • Lukewarm is no good, the Power of Intrinsic Motivation.

    Lukewarm is no good, the Power of Intrinsic Motivation.

    British author Roald Dahl wrote in his book My Uncle Oswald; "Lukewarm is no good. Hot is no good either.

    1 条评论
  • Beating Bill Gates at Wordle!

    Beating Bill Gates at Wordle!

    Bill Gates is famously a New York Times Wordle addict. As he wrote on his blog Gates Note' in August of last year, he…

    1 条评论

社区洞察

其他会员也浏览了