Akamai is expanding its software security capabilities with the launch this week of its new API Security offering.
APIs are at the foundation of most modern applications, enabling services from different locations to be integrated into a platform. APIs are increasingly being targeted by attackers in recent years. Akamai's State of the Internet report, found that API attacks spiked in 2022 reaching record highs.
The risks associated with APIs motivated Akamai to acquire privately held API security vendor Neosec in April, which is now the foundation of Akamai's new API product. Akamai is also extending the Neosec technology, adding in a series of additional capabilities. Among the features that Akamai has added is an edge connector to integrate API security scanning with the Akamai network. The Akamai Shadow Hunt service is also being integrated with API Security, enabling security analysts to use the API data for threat hunting.
"API Security is innovative because it brings detection and response (XDR) techniques to protecting APIs," Rupesh Chokshi, GM of Application Security at Akamai told SDxCentral. "By storing historical data in the API Security data lake and using behavioral analytics to understand normal and abnormal usage of APIs over time, Akamai sees API threats that other solutions might miss.”
Protecting APIs is not a new thing for Akamai
The new API Security product isn't the only service in the Akamai portfolio designed to help protect APIs.
The company already has its App & API Protector (AAP) solution, which has been in the market since 2021. Chokshi said that AAP and API Security protect against different threats in different ways.
Chokshi explained that AAP protects websites, applications and APIs on the Akamai network by blocking incoming malicious traffic in real-time. Within AAP-accepted traffic and anywhere across the enterprise, API Security discovers all APIs, uses behavioral analytics to detect abnormal activity, and automatically responds to threats and abuse.
"Together, AAP and API Security deliver the most comprehensive global protection by combining enterprise-wide visibility, behavioral analysis of API activity, and prevention of attacks and abuse," he said.
The challenges of APIs and the road ahead
Chokshi noted that in recent years thanks to digital transformation, the growth of API adoption and usage is exponential. Subsequently, the API attack surface continues to grow dramatically.
Given the importance of APIs to enable modern platforms, Chokshi said that protecting APIs will become a core requirement for modern businesses.
"Today, most organizations have no understanding of how many APIs they use, let alone have an inventory," Chokshi said. "Without knowing what APIs they have, it is unfortunately common that APIs are also unprotected.“
Comments