SlideShare a Scribd company logo
Cloud External APIs with ChatGPT 4-Turbo
and Attack Path Visualization
AI Innovations bring new attacks to Enterprise APIs
Agenda
• Playground has changed for APIs…
• AI innovation makes it easier to find new data insights
• Barriers (costs) are dropping for API experimentation
• Data is AI fuel. APIs are the new charging stations.
• GenAI proliferation accelerates 2024+
• API data consumption will explode alongside AI assistants
• API Security & App, Data, SCS Discovery must evolve.
• Context becomes necessary for API and data safety
• “Attack Path Visualization” helps with security & privacy
Playground has changed…
Sam Altman - Nov 7, 2023 at DevDay, OpenAPI’s first conf
“Assistants API will make everything easier.”
“[API] retrieval… and
using your own
functions” makes
better Assistants
Ramon Huet, OpenAI’s head of developer experience
ChatGPT 3.0 or earlier = no external APIs (Nov 2022)
gpt-3.0
Enterprise API Security & Data Classification
API target: https://retoolapi.dev/rv0soy/sensitivedata
API key: sensitivetH16uqkjUPiTX9T6y8S1E0d8myj39f2j1co0w0EzdKF3RfYmtIymyKJ
Data Theorem (API Secure) Teleskope.ai (Cloud Data Security Platform)
Other Security Tools
OpenAI: Nov 7 (Functions & Retrieval)
gpt-4.0-turbo
After analyzing the provided API response, I found a total of 42 instances of PII. These instances include credit
card numbers, social security numbers, and zip codes. If you have any further questions or need assistance with
anything else, please let me know.
API Key, OAuth 2.0, Azure AD
ChatGPT 4.0 Turbo = yes to External APIs (Nov 2023)
Cost = $0.25-$0.35
2-3X lower cost
with Chat GPT-4
Data is AI fuel.
APIs are the charging stations.
Elon Musk - Nov 23,2023 at NYT DealBook summit
“Data is probably more valuable than gold.”
Growth of OpenAI
AI concepts Generative AI (GenAI)
Foundation
Models
LLM (Large
Language
Models)
ChatGPT
(AI app)
AGI
(Artificial General Intelligence)
Today
Not yet… [process more data]
“[Not-for-profit Open AI that I named and help start] should be
renamed Super Closed Source for Maximum Profit AI.”
AGI defined as "smarter than the smartest human at anything…
less than three years away.” said on Nov 23, 2023
How far is AGI from reality?
API security and data discovery must evolve.
Satya Nadella, Microsoft - Nov 2023 at Ignite 2023
“We are making the age of AI real for
people and businesses everywhere.”
Genie
locked in
a bottle
Apidays Paris 2023 - Cloud APIs, ChatGPT 4-Turbo, and Attack Path Visualization, Doug Dooley, Data Theorem
Defending Enterprise APIs and apps…
API exploits and vulnerabilities… so what?
Visualize the API connective tissue
Transparency can improve security
VISUAL
CONTEXT
What?
● Vulnerabilities
● Priority Level
● Data Types
Who?
● Owner
● IAM
● CIEM
When?
● Last Changed
● Last accessed
● Alert Time
How?
● Attack Path
● Public/Private
● Exploit Details
MRI for APIs
Attack Path Visualization
MRI for APIs
Highlight: API Security Leaders
#1 Pure Play
#3 Overall
Comprehensive analyst report
on the broadening landscape
of API Security & Management
New Research: API Security & Mgmt
Alexei Balaganski, Analyst
Come see us - Booth #5

More Related Content

PDF
apidays Helsinki & North 2023 - API Security in the era of Generative AI, Mat...
PDF
APIsecure 2023 - Exploring Advanced API Security Techniques and Technologies,...
PDF
Want to integrate your business phone system or contact center with your CRM?
PDF
A Look At API Economy Trends In 2024 - by Bill Doerrfeld, Nordic APIs
PPTX
Research Reveals: Current Threats to APIs and Possible Mitigations - Eli Arku...
PDF
Are API Services Taking Over All the Interesting Data Science Problems?
PPTX
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
PDF
FireTail at API Days Australia 2024 - The Double-edge sword of AI for API Sec...
apidays Helsinki & North 2023 - API Security in the era of Generative AI, Mat...
APIsecure 2023 - Exploring Advanced API Security Techniques and Technologies,...
Want to integrate your business phone system or contact center with your CRM?
A Look At API Economy Trends In 2024 - by Bill Doerrfeld, Nordic APIs
Research Reveals: Current Threats to APIs and Possible Mitigations - Eli Arku...
Are API Services Taking Over All the Interesting Data Science Problems?
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
FireTail at API Days Australia 2024 - The Double-edge sword of AI for API Sec...

Similar to Apidays Paris 2023 - Cloud APIs, ChatGPT 4-Turbo, and Attack Path Visualization, Doug Dooley, Data Theorem (20)

PDF
apidays LIVE Paris - The Business of APIs by Jed Ng
PDF
Supporting the digital transformation of the society with APIs (@Polimi)
PPTX
API Design: Women Who Code (WWCode) DFW
PDF
Open / Public APIs - From Implementation to Digital Business Model
PDF
Microsoft + OpenAI: Recent Updates (Machine Learning 15minutes! Broadcast #74)
PDF
APIsecure 2023 - AI in API Security, Carolina Ruiz (Brier & Thorn)
PDF
How would AI shape Future Integrations?
PPTX
BusinessGPT - Security and Governance for Generative AI.pptx
PDF
OWASP API Security Top 10 Examples
PPTX
DevSecCon London 2019 - Achieve AI-Powered API Privacy Using Open Source
PPTX
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
PDF
apidays LIVE Hong Kong - The Business of APIs by Jed Ng
PDF
Open APIs - concepts. applications. visualizations.
PPTX
2022 APIsecure_Securing APIs with Open Standards
PPTX
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
PDF
Akamai_ API Security Best Practices - Real-world attacks and breaches
PDF
Hacking and Defending APIs - Red and Blue make Purple.pdf
PDF
apidays Australia 2023 - API Strategy In The Era Of Generative AI,Shreshta Sh...
PDF
APIdays London 2019 - Value in the API Economy: Insights from the world’s lar...
PDF
Apidays Singapore 2024 - APIs in the world of Generative AI by Claudio Tag, IBM
apidays LIVE Paris - The Business of APIs by Jed Ng
Supporting the digital transformation of the society with APIs (@Polimi)
API Design: Women Who Code (WWCode) DFW
Open / Public APIs - From Implementation to Digital Business Model
Microsoft + OpenAI: Recent Updates (Machine Learning 15minutes! Broadcast #74)
APIsecure 2023 - AI in API Security, Carolina Ruiz (Brier & Thorn)
How would AI shape Future Integrations?
BusinessGPT - Security and Governance for Generative AI.pptx
OWASP API Security Top 10 Examples
DevSecCon London 2019 - Achieve AI-Powered API Privacy Using Open Source
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
apidays LIVE Hong Kong - The Business of APIs by Jed Ng
Open APIs - concepts. applications. visualizations.
2022 APIsecure_Securing APIs with Open Standards
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Akamai_ API Security Best Practices - Real-world attacks and breaches
Hacking and Defending APIs - Red and Blue make Purple.pdf
apidays Australia 2023 - API Strategy In The Era Of Generative AI,Shreshta Sh...
APIdays London 2019 - Value in the API Economy: Insights from the world’s lar...
Apidays Singapore 2024 - APIs in the world of Generative AI by Claudio Tag, IBM
Ad

More from apidays (20)

PDF
apidays Munich 2025 - The Physics of Requirement Sciences Through Application...
PDF
apidays Munich 2025 - Developer Portals, API Catalogs, and Marketplaces, Miri...
PDF
apidays Munich 2025 - Making Sense of AI-Ready APIs in a Buzzword World, Andr...
PDF
apidays Munich 2025 - Integrate Your APIs into the New AI Marketplace, Senthi...
PDF
apidays Munich 2025 - The Double Life of the API Product Manager, Emmanuel Pa...
PDF
apidays Munich 2025 - Let’s build, debug and test a magic MCP server in Postm...
PDF
apidays Munich 2025 - The life-changing magic of great API docs, Jens Fischer...
PDF
apidays Munich 2025 - Automating Operations Without Reinventing the Wheel, Ma...
PDF
apidays Munich 2025 - Geospatial Artificial Intelligence (GeoAI) with OGC API...
PPTX
apidays Munich 2025 - GraphQL 101: I won't REST, until you GraphQL, Surbhi Si...
PPTX
apidays Munich 2025 - Effectively incorporating API Security into the overall...
PPTX
apidays Munich 2025 - Federated API Management and Governance, Vince Baker (D...
PPTX
apidays Munich 2025 - Agentic AI: A Friend or Foe?, Merja Kajava (Aavista Oy)
PPTX
apidays Munich 2025 - Streamline & Secure LLM Traffic with APISIX AI Gateway ...
PPTX
apidays Munich 2025 - Building Telco-Aware Apps with Open Gateway APIs, Subhr...
PPTX
apidays Munich 2025 - Building an AWS Serverless Application with Terraform, ...
PDF
apidays Helsinki & North 2025 - REST in Peace? Hunting the Dominant Design fo...
PDF
apidays Helsinki & North 2025 - Monetizing AI APIs: The New API Economy, Alla...
PDF
apidays Helsinki & North 2025 - How (not) to run a Graphql Stewardship Group,...
PDF
apidays Helsinki & North 2025 - APIs in the healthcare sector: hospitals inte...
apidays Munich 2025 - The Physics of Requirement Sciences Through Application...
apidays Munich 2025 - Developer Portals, API Catalogs, and Marketplaces, Miri...
apidays Munich 2025 - Making Sense of AI-Ready APIs in a Buzzword World, Andr...
apidays Munich 2025 - Integrate Your APIs into the New AI Marketplace, Senthi...
apidays Munich 2025 - The Double Life of the API Product Manager, Emmanuel Pa...
apidays Munich 2025 - Let’s build, debug and test a magic MCP server in Postm...
apidays Munich 2025 - The life-changing magic of great API docs, Jens Fischer...
apidays Munich 2025 - Automating Operations Without Reinventing the Wheel, Ma...
apidays Munich 2025 - Geospatial Artificial Intelligence (GeoAI) with OGC API...
apidays Munich 2025 - GraphQL 101: I won't REST, until you GraphQL, Surbhi Si...
apidays Munich 2025 - Effectively incorporating API Security into the overall...
apidays Munich 2025 - Federated API Management and Governance, Vince Baker (D...
apidays Munich 2025 - Agentic AI: A Friend or Foe?, Merja Kajava (Aavista Oy)
apidays Munich 2025 - Streamline & Secure LLM Traffic with APISIX AI Gateway ...
apidays Munich 2025 - Building Telco-Aware Apps with Open Gateway APIs, Subhr...
apidays Munich 2025 - Building an AWS Serverless Application with Terraform, ...
apidays Helsinki & North 2025 - REST in Peace? Hunting the Dominant Design fo...
apidays Helsinki & North 2025 - Monetizing AI APIs: The New API Economy, Alla...
apidays Helsinki & North 2025 - How (not) to run a Graphql Stewardship Group,...
apidays Helsinki & North 2025 - APIs in the healthcare sector: hospitals inte...
Ad

Recently uploaded (20)

PDF
Galatica Smart Energy Infrastructure Startup Pitch Deck
PPTX
Introduction-to-Cloud-ComputingFinal.pptx
PPTX
1_Introduction to advance data techniques.pptx
PPTX
Microsoft-Fabric-Unifying-Analytics-for-the-Modern-Enterprise Solution.pptx
PPT
ISS -ESG Data flows What is ESG and HowHow
PPTX
IB Computer Science - Internal Assessment.pptx
PPTX
climate analysis of Dhaka ,Banglades.pptx
PPTX
IBA_Chapter_11_Slides_Final_Accessible.pptx
PPT
Miokarditis (Inflamasi pada Otot Jantung)
PDF
Fluorescence-microscope_Botany_detailed content
PPTX
Business Ppt On Nestle.pptx huunnnhhgfvu
PPTX
iec ppt-1 pptx icmr ppt on rehabilitation.pptx
PDF
Introduction to the R Programming Language
PPTX
MODULE 8 - DISASTER risk PREPAREDNESS.pptx
PDF
[EN] Industrial Machine Downtime Prediction
PPTX
STUDY DESIGN details- Lt Col Maksud (21).pptx
PPTX
oil_refinery_comprehensive_20250804084928 (1).pptx
PPTX
AI Strategy room jwfjksfksfjsjsjsjsjfsjfsj
PPTX
STERILIZATION AND DISINFECTION-1.ppthhhbx
PDF
168300704-gasification-ppt.pdfhghhhsjsjhsuxush
Galatica Smart Energy Infrastructure Startup Pitch Deck
Introduction-to-Cloud-ComputingFinal.pptx
1_Introduction to advance data techniques.pptx
Microsoft-Fabric-Unifying-Analytics-for-the-Modern-Enterprise Solution.pptx
ISS -ESG Data flows What is ESG and HowHow
IB Computer Science - Internal Assessment.pptx
climate analysis of Dhaka ,Banglades.pptx
IBA_Chapter_11_Slides_Final_Accessible.pptx
Miokarditis (Inflamasi pada Otot Jantung)
Fluorescence-microscope_Botany_detailed content
Business Ppt On Nestle.pptx huunnnhhgfvu
iec ppt-1 pptx icmr ppt on rehabilitation.pptx
Introduction to the R Programming Language
MODULE 8 - DISASTER risk PREPAREDNESS.pptx
[EN] Industrial Machine Downtime Prediction
STUDY DESIGN details- Lt Col Maksud (21).pptx
oil_refinery_comprehensive_20250804084928 (1).pptx
AI Strategy room jwfjksfksfjsjsjsjsjfsjfsj
STERILIZATION AND DISINFECTION-1.ppthhhbx
168300704-gasification-ppt.pdfhghhhsjsjhsuxush

Apidays Paris 2023 - Cloud APIs, ChatGPT 4-Turbo, and Attack Path Visualization, Doug Dooley, Data Theorem

  • 1. Cloud External APIs with ChatGPT 4-Turbo and Attack Path Visualization AI Innovations bring new attacks to Enterprise APIs
  • 2. Agenda • Playground has changed for APIs… • AI innovation makes it easier to find new data insights • Barriers (costs) are dropping for API experimentation • Data is AI fuel. APIs are the new charging stations. • GenAI proliferation accelerates 2024+ • API data consumption will explode alongside AI assistants • API Security & App, Data, SCS Discovery must evolve. • Context becomes necessary for API and data safety • “Attack Path Visualization” helps with security & privacy
  • 3. Playground has changed… Sam Altman - Nov 7, 2023 at DevDay, OpenAPI’s first conf “Assistants API will make everything easier.” “[API] retrieval… and using your own functions” makes better Assistants Ramon Huet, OpenAI’s head of developer experience
  • 4. ChatGPT 3.0 or earlier = no external APIs (Nov 2022) gpt-3.0
  • 5. Enterprise API Security & Data Classification API target: https://retoolapi.dev/rv0soy/sensitivedata API key: sensitivetH16uqkjUPiTX9T6y8S1E0d8myj39f2j1co0w0EzdKF3RfYmtIymyKJ Data Theorem (API Secure) Teleskope.ai (Cloud Data Security Platform) Other Security Tools
  • 6. OpenAI: Nov 7 (Functions & Retrieval)
  • 7. gpt-4.0-turbo After analyzing the provided API response, I found a total of 42 instances of PII. These instances include credit card numbers, social security numbers, and zip codes. If you have any further questions or need assistance with anything else, please let me know. API Key, OAuth 2.0, Azure AD ChatGPT 4.0 Turbo = yes to External APIs (Nov 2023)
  • 8. Cost = $0.25-$0.35 2-3X lower cost with Chat GPT-4
  • 9. Data is AI fuel. APIs are the charging stations. Elon Musk - Nov 23,2023 at NYT DealBook summit “Data is probably more valuable than gold.”
  • 11. AI concepts Generative AI (GenAI) Foundation Models LLM (Large Language Models) ChatGPT (AI app) AGI (Artificial General Intelligence) Today Not yet… [process more data]
  • 12. “[Not-for-profit Open AI that I named and help start] should be renamed Super Closed Source for Maximum Profit AI.” AGI defined as "smarter than the smartest human at anything… less than three years away.” said on Nov 23, 2023 How far is AGI from reality?
  • 13. API security and data discovery must evolve. Satya Nadella, Microsoft - Nov 2023 at Ignite 2023 “We are making the age of AI real for people and businesses everywhere.”
  • 17. API exploits and vulnerabilities… so what?
  • 18. Visualize the API connective tissue
  • 19. Transparency can improve security VISUAL CONTEXT What? ● Vulnerabilities ● Priority Level ● Data Types Who? ● Owner ● IAM ● CIEM When? ● Last Changed ● Last accessed ● Alert Time How? ● Attack Path ● Public/Private ● Exploit Details MRI for APIs
  • 21. Highlight: API Security Leaders #1 Pure Play #3 Overall
  • 22. Comprehensive analyst report on the broadening landscape of API Security & Management New Research: API Security & Mgmt Alexei Balaganski, Analyst
  • 23. Come see us - Booth #5