SlideShare a Scribd company logo
Is Your API Being Abused?
And Would You Even Know If It Was?
NordicAPIs Platform Summit 2018
(AT&T Business: https://www.corp.att.com/edu/cybersecurity/managing-risks
EY: https://www.slideshare.net/dynamiccio/cybersecurity-mock-cyberwar-gamehtml)
(AT&T Business: https://www.corp.att.com/edu/cybersecurity/managing-risks
EY: https://www.slideshare.net/dynamiccio/cybersecurity-mock-cyberwar-gamehtml)
“By 2022, API abuses will be the most-frequent
attack vector resulting in data breaches for
enterprise web applications.”
(Gartner: How To Build An Effective API Security Strategy | 8 Dec 2017 | ID:G00342236)
Is Your API Being Abused – And Would You Even Notice If It Was?
Is Your API Being Abused – And Would You Even Notice If It Was?
Is Your API Being Abused – And Would You Even Notice If It Was?
Is Your API Being Abused – And Would You Even Notice If It Was?
Source: XMLdation – API/JSON Competitive Assets to meet PSD2
Your Business, On Line
• Your target users to interact via mobile devices and apps.
• They are consumers, customers, staff and suppliers.
• Need quick, functionally rich, safe and convenient services.
• Services could be online bookings, payment systems, CRM,
HR Systems, etc.
“On average, 18 SDKs are integrated into an
app… In an SDK there are 1 or more APIs...”.”
Source: SafeDK, 2017
“Over 80% of major corporations have 10 or
more mobile applications…”
Source: ThreatMetrix, 2018
https://developer.twitter.com/en/docs/basics/authentication/guides/securing-keys-and-tokens
“You should treat your API keys as you do
your username and password. As mentioned
above, API keys should not be hard-coded in
source code repositories--just as usernames
and passwords shouldn’t be.”
Dynamic Mobile App Legitimacy Solution
• Dynamic: threat is always shifting. Approov is ahead of it.
• Mobile App: any and every app you publish and all the 3rd
party apps and services they access.
• Legitimacy: uses forensic integrity technologies to identify
if a user and device is real or not. Stops bots. Stops hackers.
Stops imitators.
• Solution: our software, deployed as a service.
“The anti-bot solution for mobile”
Approov recognizes and stops unidentified
user access to your mobile apps, and only
allows access to the users you want
https://approov.io
(Image: byJcomp – Freepik.com
https://www.freepik.com/free-photo/white-notebook-black-data-firewall_1150276.htm)
API
Requests
Using Valid
User
Credentials
Case study: https://approov.io/case-studies/racing-post.html
Racing
Spreadsheet
Analysis
Data Scraping
Bot / Script
Reverse
API
Requests
Racing
Post
Backend
API
Requests
CSV
Scrapers’
Cloned
App Wireshark:
Scrapers’
Automated
Code
Is Your API Being Abused – And Would You Even Notice If It Was?
Faked
Play
Fake
Account
Creation
Account
Details
More examples: https://hackerbot.net/
Fake
Account
Factory
Fake
Play
Web App
IP Address
Spoofing
Saved Game
Editing
User
Access
Reward
Benefits
Game
Application
Backend
SignUp/Play
Rewards
Is Your API Being Abused – And Would You Even Notice If It Was?
Aggregator
App
Aggregator
Backend
Device
Farm
Cloud
Proxy
Mobility
Provider
APIs
Launch Provider App
for unsupported
operations
Unlock &
start car
Takeaways
• API abuse is a clear and present danger.
• If someone can game your system, they will.
• Your mobile channel is your Achilles Heel.
• API abusers may be your customers.
• You need to know what is communicating with you, not just who.
• Solutions don’t need to be complex.
Thank You!
And Enjoy Your APIs!
david.stewart@criticalblue.com
@critblue
https://approov.io

More Related Content

PDF
apidays LIVE Paris - Driving innovation through External APIs without putting...
PPTX
API Abuse - The Anatomy of An Attack
PDF
Contract {Collaboration} Driven Development - APIdays Interface 2020
PPTX
Adapt or Die Sydney - API Security
PDF
apidays LIVE Paris - Potential of API integrations, common traps and advices ...
PPTX
APIs for... Your Mom
PDF
apidays LIVE Hong Kong 2021 - Event-driven APIs & Schema governance for Apach...
PPTX
Kondo-ing API Authorization
apidays LIVE Paris - Driving innovation through External APIs without putting...
API Abuse - The Anatomy of An Attack
Contract {Collaboration} Driven Development - APIdays Interface 2020
Adapt or Die Sydney - API Security
apidays LIVE Paris - Potential of API integrations, common traps and advices ...
APIs for... Your Mom
apidays LIVE Hong Kong 2021 - Event-driven APIs & Schema governance for Apach...
Kondo-ing API Authorization

What's hot (20)

PPTX
Executing on API Developer Experience
PDF
Building an API Security Strategy
PDF
apidays LIVE LONDON - Protecting financial-grade APIs - Getting the right API...
PDF
How Apigee Api Management Platform Helps with Digital Excellence
PPTX
API Management Workshop (at Startupbootcamp Berlin)
PDF
apidays LIVE Jakarta - E5 ways to make your integration more resilient by Je...
PDF
apidays LIVE Hong Kong - The Business of APIs by Jed Ng
PDF
How Secure Are Your APIs?
PDF
apidays LIVE Paris 2021 - Addressing OWASP API Security Top 10 by Isabelle Ma...
PPTX
apidays LIVE India - 10 steps to secure your API by Pabitra Kumar Sahoo, Qual...
PDF
apidays LIVE London 2021 - API Security challenges and solutions by Wadii Tah...
PDF
apidays LIVE Paris - Succeeding with API Programs by Kiran Nadgir
PPTX
Test and Protect Your API
PPTX
apidays LIVE Paris - Principles for API security by Alan Glickenhouse
PDF
Apigee and Accenture Webcast - Accenture Technology Vision 2013 - An API Cent...
PPTX
Microservices Done Right: Key Ingredients for Microservices Success
PDF
Mobile - Your API Security Blindspot by David Stewart, Approov
PPTX
Mining API Traffic Metadata
PPTX
London Adapt or Die: Securing your APIs the Right Way!
PDF
API as a Growth Tool
Executing on API Developer Experience
Building an API Security Strategy
apidays LIVE LONDON - Protecting financial-grade APIs - Getting the right API...
How Apigee Api Management Platform Helps with Digital Excellence
API Management Workshop (at Startupbootcamp Berlin)
apidays LIVE Jakarta - E5 ways to make your integration more resilient by Je...
apidays LIVE Hong Kong - The Business of APIs by Jed Ng
How Secure Are Your APIs?
apidays LIVE Paris 2021 - Addressing OWASP API Security Top 10 by Isabelle Ma...
apidays LIVE India - 10 steps to secure your API by Pabitra Kumar Sahoo, Qual...
apidays LIVE London 2021 - API Security challenges and solutions by Wadii Tah...
apidays LIVE Paris - Succeeding with API Programs by Kiran Nadgir
Test and Protect Your API
apidays LIVE Paris - Principles for API security by Alan Glickenhouse
Apigee and Accenture Webcast - Accenture Technology Vision 2013 - An API Cent...
Microservices Done Right: Key Ingredients for Microservices Success
Mobile - Your API Security Blindspot by David Stewart, Approov
Mining API Traffic Metadata
London Adapt or Die: Securing your APIs the Right Way!
API as a Growth Tool
Ad

Similar to Is Your API Being Abused – And Would You Even Notice If It Was? (20)

PDF
apidays LIVE Hong Kong - API Abuse - Comprehension and Prevention by David St...
PDF
apidays LIVE Singapore 2021 - Why verifying user identity Is not enough In 20...
PDF
Enhancing your Security APIs
PPTX
apidays LIVE New York 2021 - Playing with FHIR without getting burned by Dav...
PDF
apidays LIVE LONDON - API Abuse - Comprehension and Prevention by David Stewart
PDF
apidays New York 2023 - A decade of API breaches, courtesy of application fla...
PDF
Checkmarx meetup API Security - API Security top 10 - Erez Yalon
PPTX
APIs: The New Security Layer
PDF
OWASP API Security Top 10 - API World
PDF
apidays Australia 2023 - API Security Breach Analysis & Empowering Devs to M...
PDF
APIsecure 2023 - AI in API Security, Carolina Ruiz (Brier & Thorn)
PDF
Takeaways from API Security Breaches Webinar
PDF
The API Primer (OWASP AppSec Europe, May 2015)
PDF
LF_APIStrat17_OWASP’s Latest Category: API Underprotection
PPTX
apidays Paris 2024 - Layered Approach of API Security Strategies and its Busi...
PDF
HowYourAPIBeMyAPI
PDF
APIDays Paris Security Workshop
PDF
What Is API Security? Threats, Tools, and Best Practices in 2025 | USCSI®
PDF
Hacking and Defending APIs - Red and Blue make Purple.pdf
PDF
Black and Blue APIs: Attacker's and Defender's View of API Vulnerabilities
apidays LIVE Hong Kong - API Abuse - Comprehension and Prevention by David St...
apidays LIVE Singapore 2021 - Why verifying user identity Is not enough In 20...
Enhancing your Security APIs
apidays LIVE New York 2021 - Playing with FHIR without getting burned by Dav...
apidays LIVE LONDON - API Abuse - Comprehension and Prevention by David Stewart
apidays New York 2023 - A decade of API breaches, courtesy of application fla...
Checkmarx meetup API Security - API Security top 10 - Erez Yalon
APIs: The New Security Layer
OWASP API Security Top 10 - API World
apidays Australia 2023 - API Security Breach Analysis & Empowering Devs to M...
APIsecure 2023 - AI in API Security, Carolina Ruiz (Brier & Thorn)
Takeaways from API Security Breaches Webinar
The API Primer (OWASP AppSec Europe, May 2015)
LF_APIStrat17_OWASP’s Latest Category: API Underprotection
apidays Paris 2024 - Layered Approach of API Security Strategies and its Busi...
HowYourAPIBeMyAPI
APIDays Paris Security Workshop
What Is API Security? Threats, Tools, and Best Practices in 2025 | USCSI®
Hacking and Defending APIs - Red and Blue make Purple.pdf
Black and Blue APIs: Attacker's and Defender's View of API Vulnerabilities
Ad

More from Nordic APIs (20)

PPTX
How to Choose the Right API Platform - We Have the Tool You Need! - Mikkel Iv...
PPTX
Bulletproof Backend Architecture: Building Adaptive Services with Self-Descri...
PDF
Implementing Zero Trust Security in API Gateway with Cilium - Pubudu Gunatila...
PPTX
Event-Driven Architecture the Cloud-Native Way - Manuel Ottlik, HDI Global SE
PPTX
Navigating the Post-OpenAPI Era with Innovative API Design Frameworks - Danie...
PDF
Using Typespec for Open Finance Standards - Chris Wood, Ozone API
PPTX
Schema-first API Design Using Typespec - Cailin Smith, Microsoft
PPTX
Avoiding APIpocalypse; API Resiliency Testing FTW! - Naresh Jain, Xnsio
PPTX
How to Build an Integration Platform with Open Source - Magnus Hedner, Benify
PPTX
API Design First in Practise – An Experience Report - Hari Krishnan, Specmatic
PPTX
The Right Kind of API – How To Choose Appropriate API Protocols and Data Form...
PPTX
Why Frequent API Hackathons Are Key to Product Market Feedback and Go-to-Mark...
PPTX
Maximizing API Management Efficiency: The Power of Shifting Down with APIOps ...
PPTX
APIs Vs Events - Bala Bairapaka, Sandvik AB
PPTX
GraphQL in the Post-Hype Era - Daniel Hervas, Reckon Digital
PPTX
From Good API Design to Secure Design - Axel Grosse, 42Crunch
PPTX
API Revolution in IoT: How Platform Engineering Streamlines API Development -...
PPTX
Unlocking the ROI of API Platforms: What Success Actually Looks Like - Budhad...
PDF
Increase Your Productivity with No-Code GraphQL Mocking - Hugo Guerrero, Red Hat
PPTX
Securely Boosting Any Product with Generative AI APIs - Ruben Sitbon, Theodo ...
How to Choose the Right API Platform - We Have the Tool You Need! - Mikkel Iv...
Bulletproof Backend Architecture: Building Adaptive Services with Self-Descri...
Implementing Zero Trust Security in API Gateway with Cilium - Pubudu Gunatila...
Event-Driven Architecture the Cloud-Native Way - Manuel Ottlik, HDI Global SE
Navigating the Post-OpenAPI Era with Innovative API Design Frameworks - Danie...
Using Typespec for Open Finance Standards - Chris Wood, Ozone API
Schema-first API Design Using Typespec - Cailin Smith, Microsoft
Avoiding APIpocalypse; API Resiliency Testing FTW! - Naresh Jain, Xnsio
How to Build an Integration Platform with Open Source - Magnus Hedner, Benify
API Design First in Practise – An Experience Report - Hari Krishnan, Specmatic
The Right Kind of API – How To Choose Appropriate API Protocols and Data Form...
Why Frequent API Hackathons Are Key to Product Market Feedback and Go-to-Mark...
Maximizing API Management Efficiency: The Power of Shifting Down with APIOps ...
APIs Vs Events - Bala Bairapaka, Sandvik AB
GraphQL in the Post-Hype Era - Daniel Hervas, Reckon Digital
From Good API Design to Secure Design - Axel Grosse, 42Crunch
API Revolution in IoT: How Platform Engineering Streamlines API Development -...
Unlocking the ROI of API Platforms: What Success Actually Looks Like - Budhad...
Increase Your Productivity with No-Code GraphQL Mocking - Hugo Guerrero, Red Hat
Securely Boosting Any Product with Generative AI APIs - Ruben Sitbon, Theodo ...

Recently uploaded (20)

PDF
How Creative Agencies Leverage Project Management Software.pdf
PDF
medical staffing services at VALiNTRY
PDF
Odoo Companies in India – Driving Business Transformation.pdf
PDF
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
PDF
Which alternative to Crystal Reports is best for small or large businesses.pdf
PDF
Audit Checklist Design Aligning with ISO, IATF, and Industry Standards — Omne...
PDF
Nekopoi APK 2025 free lastest update
PDF
System and Network Administration Chapter 2
PDF
wealthsignaloriginal-com-DS-text-... (1).pdf
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 41
PDF
2025 Textile ERP Trends: SAP, Odoo & Oracle
PDF
Understanding Forklifts - TECH EHS Solution
PDF
top salesforce developer skills in 2025.pdf
PDF
AI in Product Development-omnex systems
PPTX
Operating system designcfffgfgggggggvggggggggg
PDF
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf
PDF
Design an Analysis of Algorithms I-SECS-1021-03
PPTX
CHAPTER 2 - PM Management and IT Context
PDF
Upgrade and Innovation Strategies for SAP ERP Customers
PPTX
Essential Infomation Tech presentation.pptx
How Creative Agencies Leverage Project Management Software.pdf
medical staffing services at VALiNTRY
Odoo Companies in India – Driving Business Transformation.pdf
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
Which alternative to Crystal Reports is best for small or large businesses.pdf
Audit Checklist Design Aligning with ISO, IATF, and Industry Standards — Omne...
Nekopoi APK 2025 free lastest update
System and Network Administration Chapter 2
wealthsignaloriginal-com-DS-text-... (1).pdf
Internet Downloader Manager (IDM) Crack 6.42 Build 41
2025 Textile ERP Trends: SAP, Odoo & Oracle
Understanding Forklifts - TECH EHS Solution
top salesforce developer skills in 2025.pdf
AI in Product Development-omnex systems
Operating system designcfffgfgggggggvggggggggg
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf
Design an Analysis of Algorithms I-SECS-1021-03
CHAPTER 2 - PM Management and IT Context
Upgrade and Innovation Strategies for SAP ERP Customers
Essential Infomation Tech presentation.pptx

Is Your API Being Abused – And Would You Even Notice If It Was?