4 tips to help keep your APIs safe

Security analysts say multifactor authentication is an absolute must for any company running multiple interfaces.
So many of the biggest breaches these days involve APIs, which help power almost all of your favorite apps and platforms.
APIs have made all of our lives easier by giving companies an easy way to share information and data with one another. The best examples are rideshare apps like Uber and Lyft.
Dozens of APIs are required to give you the experience you demand as a customer, including tools that bring up your profile, connect the app to your bank account, identify your location, find the location of nearby drivers and determine routes.
“Any online service or mobile app where you have to put in your credit card number can be affected by API abuse. The most common things you see now are credential stuffing and abuse of the business logic of the application, like verifying email addresses, credit card numbers or gift cards,” said Zane Lackey, co-founder and CTO of the cybersecurity company Signal Sciences.
Gartner has already released worrying predictions for the future of API security, writing in a recent report that by 2022, API abuse will become the most common attack seen by security teams.
Gartner added in another study that in 2019, 40% of web-enabled applications will have more surface area for attack in the form of exposed APIs rather than the user interface. That number will reach 90% by 2021 according to its predictions.
With all of these different APIs sending and receiving so much valuable information, there is risk. Some of the world’s biggest companies now manage hundreds of APIs and rely on small third-party enterprises to provide critical functions for their online business.
Etay Maor, chief security officer at IntSights, said that when you dig deeper into many breaches, the root cause often points back to APIs being abused or accessed by malicious actors.
“There was a famous breach last year at the IRS, where attackers used a database and were downloading taxpayer information. One of the new systems launched in 2014 where end-users could download all their information and so that’s exactly what the criminals did through the API,” Maor said.
“700,000 taxpayers information was downloaded. Some of the attacks you read about, if you go deeper, you find out that it was an abuse of the API, a combination of vulnerable APIs and somebody who obtained a database of users and then started to attack that API.”
TechRepublic spoke to security experts and researchers about four steps enterprises can take to protect their APIs.
Beyond the basic security measures every organization should have, a key to protecting APIs is making sure you know who is using what and who has access to what.
One of the biggest problems enterprises face is credential stuffing, where crybercriminals use databases of stolen emails and passwords to bombard APIs with thousands of bogus requests.
Lackey said as more companies move to web apps as their main mode of interaction with customers, criminals are pivoting toward attacking the APIs that power mobile apps.
“Attackers are now buying big stolen lists of credentials and retrying those against every service they can think of,” Lackey said. “Once they discover the accounts, they’ll then attack the business logic of the application. Their objective is ‘I want to log into the account and update the mailing address for the customer account that I just stole so that all the goods get delivered to my mailing address.'”
To protect against this kind of credential stuffing, enterprises should use stringent multifactor authentication, according to Ben Waugh, chief security officer at the healthcare web app company Redox.
Redox helps healthcare institutions use technology, like APIs, to improve systems and share information.


