Hi, I'm Tom Field senior vice president of editorial with information security media group I'm talking today about API security making sense of the confusing market and it's my privilege to be speaking with Shrayon's meta He's the co-founder and CTO of sequence security Shrayon's. Thank you so much for taking time to speak with me today Thank you, Tom. Thank you for having me on the show Shrayon's let's start by setting some context here talk about your perspective on how API's have really grown in the marketplace and they're used and really in their exploitation Yeah, so what we see in the new world today is close to 80% of internet is actually driven through API's Your web application that is talking to the the back end using API your mobile app with your Business or partner applications that that are exposed to the outside world and what we see is this this explosion is actually driven through a Transition from monolithic app to microservices based architectures where each microservice is exposing its own API to interact with the application There are hundreds of API's that are being exposed to interact with the customers the partners and the applications So Shrayon's API security means different things to different people. What's it mean in your context?
Yeah, so API security to some people it might mean simply authentication and encryption It might mean simple right cycle management. How do you actually enable applications and API's to interact with the customers and partners? For us it is going one level above what that means to us is once you are exposing these applications They are prone to attacks ranging from automated attacks from scanning to credential stuffing People have access to billions of usernames and passwords And they are they are using these API's to quickly try them out on your like login applications It also means in certain cases the bad guys are trying out different variations of parameters on these APIs to run something like a SQL injection type attacks, but primarily on API's and some of the well-known use cases around this was the harbor Attach that happened a few months ago or something that happened on Twitter where people actually exposed telephone numbers for Twitter users in other cases It's simply about just the lack of visibility and oversight on the number of API's that are actually exposed out there in the DevOps world New apps are coming out pretty much on a daily if not hourly basis and they are exposing new APIs that are prone to attacks There's just a simple lack of visibility on on your attacks of this today So you've already given us a good context in how APIs have exploded in use Is it fair to say that these security concerns have grown proportionately with this explosion? Definitely so in our customer base today, we are seeing more attacks for over APIs than on the traditional web channels This is primarily because it's just simply easier to attack these channels There is a lack of controls on on these channels that are lack of tools that are available that can actually protect these channels And the part for the bad guys what we see is they don't choose the doors with bigger locks In fact, they're looking for doors that are literally have either no locks or or some basic protections in place It's very easy for them to automate These APIs as well, but they can interact using JSON and XML instead of heavy lifting and parsing of HTML and JavaScript that goes Goes over the traditional web chats Sure, let's dive a little bit deeper into this At sequence, how do you commonly see APIs being taken advantage of today?
So there are various different ways that we see our customers are being backed by the bad guys One simple example around this is what we call as credentials staffing a cache where the bad guys have access to Billings of using in passwords and they're using these API's to to verify or check these credentials And then once these credentials are verified They can actually use them for for fraud in other cases the bad guys are actually scraping content From competitors and using them to their advantage. It could be about getting the pricing information It could be about getting doing fake comments or fake likes and all these APIs are actually into that available to the outside world for the bad guys to abuse in other cases We see attacks like parameter exploitation where the bad guys are simply trying out different ways They can actually overcome the system or overtake the system these APIs and applications by exfiltrating the entire database or Individual records out of the system without authentication or without proper checks in place So Shran's talk to me more about sequence security in your approach to API security. What do you find is unique in how you tackle this? So at sequence we have been in business in protecting web mobile and APIs for the past five years and our approach to Application security has been more about protecting all channels the exact same way.
It could be your web channel It could be your mobile apps interacting using APIs or it would be APIs directly interacting to partners Because we do not require any instrumentation into the app. We are perfect solution to protect your APIs The way our solution actually works. It's a continuous cycle of discover Detect and defend where we are constantly discovering new apps and new APIs that are getting exposed So your devops as it's rolling out new applications your psychops can keep up to date with those with protecting those applications as well Then in an out-of-bound fashion without adding any risk to that application itself We are applying machine learning and behavior analysis to bubble up attacks on to these these APIs And then you can defend these APIs using various mechanism ranging from simple blocking to rate limiting to providing fake responses that significantly slows down these backpacks Very good Shran's. I appreciate your time and insight today.
Thank you so much Yeah, thank you for having me Tom Again, the topic has been API security that was speaking with Shran's meta co-founder and CTO of sequence security For information security media group, I'm Tom Field. Thank you very much