SlideShare a Scribd company logo
API Security with Postman
and Qualys
Security Solution Architect, Application Security
Qualys, Inc.
2
APIs Are
Everywhere Highly exposed
Greater likelihood of attack
Constantly being probed
Internet-facing APIs
Custom / domain-specific
For employees or contractors
Often built without security
considered
Internal APIs
Unknown risk posture
No access to source code
Often process critical data
Vendor APIs
Cloud provider not
responsible for security of
your apps and APIs
APIs in public clouds
3
https://owasp.org/www-project-api-sec
urity/
OWASP API
Security Top 10
API1 Broken Object Level Authorization
API2 Broken User Authentication
API3 Excessive Data Exposure
API4 Lack of Resources & Rate Limiting
API5 Broken Function Level Authorization
API6 Mass Assignment
API7 Security Misconfiguration
API8 Injection
API9 Improper Assets Management
API10 Insufficient Logging & Monitoring
OWASP API
Security Top 10 -
Highlights
API1 Broken Object Level Authorization
API2 Broken User Authentication
API5 Broken Function Level Authorization
API1 Broken Object Level Authorization
API1 Broken
Object Level
Authorization
(BOLA)
API5 Broken Function Level Authorization
API5 Broken
Function Level
Authorization
API2 Broken
User
Authentication
API2 Broken User Authentication
SolarWinds CVE-2020-10148
Administration bypass
Lack of authentication
Request processed before authentication
is verified
API6 Mass Assignment
API6 Mass Assignment
Note on API8
Injection
Frequently, practitioners feel that XSS
attacks are not valid for APIs due to
JSON responses
If JSON is written into an application
with a UI, the attack may execute
Microservices - Be aware of all areas
the responses are used
Qualys Web
Application
Scanning
Qualys WAS Highlights
Unlimited scans
Unlimited users
Cloud based
Not a point solution
Massive scalability
Flexible licensing
Scheduled scans
Ad-hoc, targeted
scans
Multi-site scanning
Scanner pooling
API scanning
Out-of-Band
detections
Comprehensive API
Splunk TA
Integrations with:
- Qualys WAF
- CI/CD tools
- Burp Suite
- Bugcrowd
RBAC
Tagging
Detection history
Scheduled reports
Customizable reports
Retest findings
Ignore findings
Low TCO Scanning
Flexibility
Integrations
Features
Postman Support
API Security - Coming Soon
Demo
Wrap-up
Qualys can utilize existing Postman collections
Quickly scan APIs for vulnerabilities
API Security is important
The OWASP API Security Top 10 is an
excellent resource
Thank You!
earnold@qualys.com
Security Solution Architect, Application Security
Qualys, Inc.

More Related Content

PDF
OWASP API Security Top 10 - API World
PDF
OWASP Top 10 API Security Risks
PPTX
API Management in Digital Transformation
PDF
REST API Authentication Methods.pdf
PPTX
PPTX
OAuth - Don’t Throw the Baby Out with the Bathwater
ODP
OAuth2 - Introduction
PPTX
OWASP Top 10 2021 What's New
OWASP API Security Top 10 - API World
OWASP Top 10 API Security Risks
API Management in Digital Transformation
REST API Authentication Methods.pdf
OAuth - Don’t Throw the Baby Out with the Bathwater
OAuth2 - Introduction
OWASP Top 10 2021 What's New

What's hot (20)

PDF
OWASP Top 10 Web Application Vulnerabilities
PDF
API Security Best Practices & Guidelines
PPTX
What's New in API Connect & DataPower Gateway in 1H 2018
PPTX
Pentesting ReST API
PDF
OAuth 2.0 with IBM WebSphere DataPower
PDF
Owasp top 10
PDF
Deploying Privileged Access Workstations (PAWs)
PPTX
OWASP Top 10 2021 Presentation (Jul 2022)
PPT
Introduction To OWASP
PDF
DataPower API Gateway Performance Benchmarks
PDF
Insecure direct object reference (null delhi meet)
PDF
Attacking AWS: the full cyber kill chain
PDF
Api security-testing
PPTX
DataPower Restful API Security
PDF
How to migrate an application in IBM APIc, and preserve its client credential
PDF
OWASP API Security Top 10 Examples
PPTX
What is an API Gateway?
PDF
OAuth 2.0
PPTX
API Governance in the Enterprise
PDF
API Gateway How-To: The Many Ways to Apply the Gateway Pattern
OWASP Top 10 Web Application Vulnerabilities
API Security Best Practices & Guidelines
What's New in API Connect & DataPower Gateway in 1H 2018
Pentesting ReST API
OAuth 2.0 with IBM WebSphere DataPower
Owasp top 10
Deploying Privileged Access Workstations (PAWs)
OWASP Top 10 2021 Presentation (Jul 2022)
Introduction To OWASP
DataPower API Gateway Performance Benchmarks
Insecure direct object reference (null delhi meet)
Attacking AWS: the full cyber kill chain
Api security-testing
DataPower Restful API Security
How to migrate an application in IBM APIc, and preserve its client credential
OWASP API Security Top 10 Examples
What is an API Gateway?
OAuth 2.0
API Governance in the Enterprise
API Gateway How-To: The Many Ways to Apply the Gateway Pattern
Ad

Similar to API Security with Postman and Qualys (20)

PDF
Checkmarx meetup API Security - API Security top 10 - Erez Yalon
PDF
Common Security API Issues and How to Mitigate Them Using Postman
PPTX
Bas Dijkstra: Are you sure your APIs are secure?
PDF
apidays Hong Kong - Attack API Architecture, Alvin Tam, Hong Kong Computer So...
PDF
APIsecure 2023 - API First Hacking, Corey Ball, Author of Hacking APIs
PPTX
Outpost24 webinar - Api security
PDF
apidays London 2023 - APIs: The Attack Surface That Connects Us All, Stefan M...
PDF
API Hijacking.pdf
PDF
API Hijacking.pdf
PDF
API Hijacking (1).pdf
PDF
2022 APIsecure_Shift Left API Security - The Right Way
PPTX
Safeguarding Digital Assets_ Uncovering Security Risks in APIs - Automation G...
PDF
API Testing and Hacking.pdf
PDF
API Testing and Hacking.pdf
PDF
API Testing and Hacking (1).pdf
PDF
apidays Australia 2023 - API Security Breach Analysis & Empowering Devs to M...
PPTX
Deep-Dive: Secure API Management
PDF
OWASPAPISecurity
PDF
5 step plan to securing your APIs
PDF
How Secure Are Your APIs?
Checkmarx meetup API Security - API Security top 10 - Erez Yalon
Common Security API Issues and How to Mitigate Them Using Postman
Bas Dijkstra: Are you sure your APIs are secure?
apidays Hong Kong - Attack API Architecture, Alvin Tam, Hong Kong Computer So...
APIsecure 2023 - API First Hacking, Corey Ball, Author of Hacking APIs
Outpost24 webinar - Api security
apidays London 2023 - APIs: The Attack Surface That Connects Us All, Stefan M...
API Hijacking.pdf
API Hijacking.pdf
API Hijacking (1).pdf
2022 APIsecure_Shift Left API Security - The Right Way
Safeguarding Digital Assets_ Uncovering Security Risks in APIs - Automation G...
API Testing and Hacking.pdf
API Testing and Hacking.pdf
API Testing and Hacking (1).pdf
apidays Australia 2023 - API Security Breach Analysis & Empowering Devs to M...
Deep-Dive: Secure API Management
OWASPAPISecurity
5 step plan to securing your APIs
How Secure Are Your APIs?
Ad

More from Postman (20)

PDF
Advanced AI and Documentation Techniques
PDF
WeTestAthens: Postman's AI & Automation Techniques
PDF
Elevating Developer Experiences with AI-Powered API Testing & Documentation
PDF
Discovering Public APIs and Public API Network with Postman
PDF
Optimizing Teamwork: Harnessing Collections & Workspaces for Collaboration
PDF
API testing Beyond the Basics AI & Automation Techniques
PDF
Not Your Grandma’s Rate Limiting (slides)
PDF
Five Ways to Automate API Testing with Postman
PDF
How to Scale APIs-as-Product for Future Success
PPTX
Revolutionizing API Development: Collaborative Workflows with Postman
PDF
Everything You Always Wanted to Know About AsyncAPI
PDF
Elevating Event-Driven World: A Deep Dive into AsyncAPI v3
PDF
Five Things You SHOULD Know About Postman
PDF
Integration-, Snapshot- and Performance-Testing APIs
PDF
How ChatGPT led OpenAPI's Recent Spike in Popularity
PDF
Exploring Postman’s VS Code Extension
PDF
2023 State of the API Report: Key Findings and Trends
PDF
Nordic- APIOps is here What will you build in an API First World
PDF
Testing and Developing gRPC APIs
PDF
Testing and Developing GraphQL APIs
Advanced AI and Documentation Techniques
WeTestAthens: Postman's AI & Automation Techniques
Elevating Developer Experiences with AI-Powered API Testing & Documentation
Discovering Public APIs and Public API Network with Postman
Optimizing Teamwork: Harnessing Collections & Workspaces for Collaboration
API testing Beyond the Basics AI & Automation Techniques
Not Your Grandma’s Rate Limiting (slides)
Five Ways to Automate API Testing with Postman
How to Scale APIs-as-Product for Future Success
Revolutionizing API Development: Collaborative Workflows with Postman
Everything You Always Wanted to Know About AsyncAPI
Elevating Event-Driven World: A Deep Dive into AsyncAPI v3
Five Things You SHOULD Know About Postman
Integration-, Snapshot- and Performance-Testing APIs
How ChatGPT led OpenAPI's Recent Spike in Popularity
Exploring Postman’s VS Code Extension
2023 State of the API Report: Key Findings and Trends
Nordic- APIOps is here What will you build in an API First World
Testing and Developing gRPC APIs
Testing and Developing GraphQL APIs

Recently uploaded (20)

PDF
Why TechBuilder is the Future of Pickup and Delivery App Development (1).pdf
PDF
medical staffing services at VALiNTRY
PPTX
ISO 45001 Occupational Health and Safety Management System
PDF
Nekopoi APK 2025 free lastest update
PPTX
Operating system designcfffgfgggggggvggggggggg
PPTX
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
PDF
Navsoft: AI-Powered Business Solutions & Custom Software Development
PDF
How to Choose the Right IT Partner for Your Business in Malaysia
PDF
Upgrade and Innovation Strategies for SAP ERP Customers
PDF
Odoo Companies in India – Driving Business Transformation.pdf
PDF
Which alternative to Crystal Reports is best for small or large businesses.pdf
PDF
Wondershare Filmora 15 Crack With Activation Key [2025
PPTX
Online Work Permit System for Fast Permit Processing
PPT
Introduction Database Management System for Course Database
PPTX
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
PDF
Digital Strategies for Manufacturing Companies
PPTX
VVF-Customer-Presentation2025-Ver1.9.pptx
PDF
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
PDF
top salesforce developer skills in 2025.pdf
PDF
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf
Why TechBuilder is the Future of Pickup and Delivery App Development (1).pdf
medical staffing services at VALiNTRY
ISO 45001 Occupational Health and Safety Management System
Nekopoi APK 2025 free lastest update
Operating system designcfffgfgggggggvggggggggg
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
Navsoft: AI-Powered Business Solutions & Custom Software Development
How to Choose the Right IT Partner for Your Business in Malaysia
Upgrade and Innovation Strategies for SAP ERP Customers
Odoo Companies in India – Driving Business Transformation.pdf
Which alternative to Crystal Reports is best for small or large businesses.pdf
Wondershare Filmora 15 Crack With Activation Key [2025
Online Work Permit System for Fast Permit Processing
Introduction Database Management System for Course Database
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
Digital Strategies for Manufacturing Companies
VVF-Customer-Presentation2025-Ver1.9.pptx
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
top salesforce developer skills in 2025.pdf
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf

API Security with Postman and Qualys

  • 1. API Security with Postman and Qualys Security Solution Architect, Application Security Qualys, Inc.
  • 2. 2 APIs Are Everywhere Highly exposed Greater likelihood of attack Constantly being probed Internet-facing APIs Custom / domain-specific For employees or contractors Often built without security considered Internal APIs Unknown risk posture No access to source code Often process critical data Vendor APIs Cloud provider not responsible for security of your apps and APIs APIs in public clouds
  • 3. 3 https://owasp.org/www-project-api-sec urity/ OWASP API Security Top 10 API1 Broken Object Level Authorization API2 Broken User Authentication API3 Excessive Data Exposure API4 Lack of Resources & Rate Limiting API5 Broken Function Level Authorization API6 Mass Assignment API7 Security Misconfiguration API8 Injection API9 Improper Assets Management API10 Insufficient Logging & Monitoring
  • 4. OWASP API Security Top 10 - Highlights API1 Broken Object Level Authorization API2 Broken User Authentication API5 Broken Function Level Authorization
  • 5. API1 Broken Object Level Authorization API1 Broken Object Level Authorization (BOLA)
  • 6. API5 Broken Function Level Authorization API5 Broken Function Level Authorization
  • 7. API2 Broken User Authentication API2 Broken User Authentication SolarWinds CVE-2020-10148 Administration bypass Lack of authentication Request processed before authentication is verified
  • 10. Note on API8 Injection Frequently, practitioners feel that XSS attacks are not valid for APIs due to JSON responses If JSON is written into an application with a UI, the attack may execute Microservices - Be aware of all areas the responses are used
  • 12. Qualys WAS Highlights Unlimited scans Unlimited users Cloud based Not a point solution Massive scalability Flexible licensing Scheduled scans Ad-hoc, targeted scans Multi-site scanning Scanner pooling API scanning Out-of-Band detections Comprehensive API Splunk TA Integrations with: - Qualys WAF - CI/CD tools - Burp Suite - Bugcrowd RBAC Tagging Detection history Scheduled reports Customizable reports Retest findings Ignore findings Low TCO Scanning Flexibility Integrations Features
  • 14. API Security - Coming Soon
  • 15. Demo
  • 16. Wrap-up Qualys can utilize existing Postman collections Quickly scan APIs for vulnerabilities API Security is important The OWASP API Security Top 10 is an excellent resource
  • 17. Thank You! earnold@qualys.com Security Solution Architect, Application Security Qualys, Inc.