CISOs take note: if you rely on web application firewalls (WAFs) to secure your web and mobile applications built on APIs, Alissa Valentina Knight can breach your APIs. In fact, she may have already done so.
In a new white paper sponsored by Traceable, Knight says she’s done dozens of penetration tests against APIs. With some bank targets, she changed customers’ PINs, which allowed her to transfer money between accounts she didn’t own. In health care she logged in to her account and accessed other patients’ electronic health records. She successfully breached automotive APIs and remotely controlled the vehicles.
“It definitely underscores how much of the plumbing in financial services, health care, automotive — the internet of everything is done with APIs,” she said in an interview with SDxCentral.
Knight cited an Akamai study that found API calls represent 83% of all web traffic. “That means that more than half of the traffic on the internet is no longer human-to-application traffic,” she said. “It’s app to app or device to app or device to device, all powered by APIs.”
Of course, securing these APIs is critically important and failing to do so has very real, and in some cases life and death, consequences. And the biggest mistake most organizations make in securing these APIs is using ineffective tools like WAFs, according to Knight and Traceable CTO Sanjay Nagaraj.
“If you are serious about API security, WAFs are not going to cut it,” Nagaraj said.
Traceable Takes On WAFsNagaraj co-founded the application security startup with Jyoti Bansal, who serves as Traceable’s CEO. The two men worked together at AppDynamics: Bansal was also its CEO and Nagaraj was a former VP of engineering before Cisco bought the application performance management company for $3.7 billion in 2017.
They launched their new security venture, Traceable, in July 2020 with $20 million in funding and a platform that uses distributed tracing technology to monitor end-to-end application activity — from the user and session through the application code — and artificial intelligence to distinguishing between valid and malicious use of an application’s APIs.
WAFs do an OK job protecting legacy monolithic applications behind a single perimeter from a set of known attacks, Nagaraj said. “But when it comes to APIs, the game totally changes,” he added.
WAFs don’t understand context, and they don’t detect logic-based attacks like authentication and authorization vulnerabilities, mass assignment, excessive data exposure, and other novel threats that target APIs, he explained. “That’s where you’re going to be disappointed as a company. If you say, ‘I have my WAFs and they protect me against API attacks,’ forget it. It’s not gonna happen.”
‘No Security Without Context’Knight, who is also a bank CISO, says she’s speaking from the adversary’s perspective when she blames CISOs. “There really is this false sense of security being created by chief information security officers whose go-to, historically, is to secure anything that speaks HTTP with a WAF,” she said, adding that so many of the APIs she hacked were secured by WAFs.
“The problem is that WAFs work off of a rules-based detection engine, meaning that it’s looking for known patterns of bad,” she continued. “But the attacks that I'm running aren’t carrying the traditional indicators of compromise. I’m exploiting logic flaws and issues.”
The most common problem Knight found in API breaches is broken object level authorization vulnerabilities. This means her account was properly authenticated, however she was allowed to access data that she wasn’t authorized to see.
For example, a health-care app legitimately authenticated Knight because she has a legitimate username and password. But she shouldn’t be able to request another patient’s records. “A WAF isn’t going to understand that,” Knight said. “It’s not going to have that context in security that is really required to be an effective security solution. There is no security without context.”
WAFs Can’t Keep UpAPI security requires context, but it also has to be autonomous and happen in real time to keep up with the pace of innovation, Nagaraj said. “On Amazon, for example, there is code shipping every seven seconds,” he said. “If these APIs are coming online every X number of days, or X number of minutes in a lot of cases, how do you keep up with that? There’s no way you can continue to keep [WAF] rules up to date to manage protecting all of these new APIs.”
Additionally, organizations use internal APIs, and developers can inadvertently expose them and create vulnerabilities while deploying web services. “This is where we believe you first have to have visibility,” Nagaraj said. “You need to be able to discover all of your APIs, understand the risk associated with these APIs, because you can’t protect what is not visible. And then you need to protect against these attacks on next-generation APIs.”
While discovery is the first step in API security, risk assessment should be step No. 2, Nagaraj added. “There could be 10,000 APIs in an organization, so which ones to prioritize and which ones to actually focus on?” This is where AI and machine learning come into play to help security teams understand APIs’ business context and logic.
Knight likens it to the antivirus evolution over the past 20 years. Two decades ago, endpoint security was antivirus software, and every time a new virus was discovered, vendors like McAfee and Symantec had to update their antivirus software to account for new malware variants. “Now, legacy antivirus has left the scene, and we’re in a new era of endpoint detection and response solutions that use machine learning,” she said. “We’ve gotten away from this legacy form of rules-based or patten-based detection with antivirus and other areas of security, yet we’re still doing this with web application firewalls.”
Comments