The Cyber Security Review | Friday, December 02, 2022
API attacks will become the most-frequent attack vector in 2022.
FREMONT, CA: According to Gartner, in 2022, API attacks overtook other attack types as the most common. While it is yet unknown whether this is the case, it is obvious that they are incredibly effective when considering that the exploitation of Twitter's API vulnerability exposed the data of 5.4 million users.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Cybersecurity company Wib announced the release of what it calls the industry's first API PenTesting-as-a-service (PTaaS), which is intended to test for application security, API, and business logic vulnerabilities to assist security teams in addressing these threats.
Wib, which offers consumers the ability to create a comprehensive inventory of APIs, generate documentation, and improve visibility over the attack surface, recently disclosed obtaining USD 16 million in fundraising. In this case, penetration testing gives security professionals a more realistic picture of the API security posture of their firm so they can find and close any potential entry gaps before hackers can take advantage of them.
The announcement comes at a time when assaults on APIs are rising; according to data, 94 per cent of firms have encountered security issues with production APIs. To take matters worse, 61 per cent of security teams lack any API security strategy or just have a basic plan, leaving many of them unsure how to counter these risks. The truth is that after adopting cloud computing and microservices, many enterprises are still catching up with API security.
As businesses adopt an API-first approach and switch to a microservices-based architecture, which alters their attack surfaces, most of these blind spots become apparent.
However, their defences weren't created for this structure and haven't yet evolved to cover it.
Security is always outpaced by adoption, and this situation is no exception. This time, however, is different because API traffic already accounts for 91 per cent of all online traffic, and most defenders are unaware of APIs as an attack vector.
Wib gives businesses access to the knowledge and tools required to spot risks at the API level by providing a service designed specifically for penetration testing.
Security teams receive a comprehensive assessment report of discovered vulnerabilities, a risk severity score derived from the NIST's cyber matrix calculator, and a remediation road map plan with suggestions for mitigating vulnerabilities after each test. Wib is only one of several suppliers in the global API security market, which analysts estimate to be worth USD 783.9 million in 2021 and USD 984.1 million in 2022.
The company is up against a wide range of rivals in the market, including Salt Security, which earlier this year raised USD 140 million in series D funding and provides an artificial intelligence (AI) and machine learning (ML)-driven platform for inventorying APIs and exposed data with OAS analysis capabilities.
NoName Security, an API security platform that finds flaws and incorrect configurations while giving security teams automatic detection and response capabilities, is another prominent rival. In December 2021, NoName Security received USD 135 million as part of a series C investment round.
Herrin contends that what sets WIB apart from these current tools is its adaptable approach to penetration testing and disregarding API traffic when looking for risks.
Both of these unicorns concentrate on a production traffic-based view, which Herrin claimed was important but insufficient to uncover blind spots such as zombie APIs (which are exposed but receive no typical traffic) or APIs that don't communicate across expected traffic pathways.
More in News