Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Erez Yalon — The OWASP API Security Project

37 min3 januari 2020

Om avsnittet

Why did APIs need a security Top 10 of their own? Erez Yalon joins Chris and Robert to explain the gaps that led to the OWASP API Security project and walk through its original 2019 list. He contrasts traditional web applications with APIs serving many kinds of clients, where authorization decisions and exposed data can become especially difficult to control. The conversation distinguishes broken object-level authorization from broken function-level authorization, then examines excessive data exposure, mass assignment, resource limits, and forgotten API versions. Erez also discusses the project's plans for practical learning materials and ways the community can contribute. This is a guided introduction to the original API Security Top 10, with concrete explanations of the design assumptions behind common failures.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Erez Yalon:
LinkedIn
OWASP API Security project

Mentioned in this episode:
OWASP API Security Top 10 — 2019
OWASP API Security repository
OWASP crAPI

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Introduction
01:35 What an API is
05:50 Why API security differs from web security
09:25 Rapid change and the API attack surface
11:43 Why OWASP started the API Security project
14:52 Broken object-level authorization
17:22 Broken authentication
19:03 Excessive data exposure
20:42 Resource and rate limits
21:21 Broken function-level authorization
23:16 Mass assignment
24:55 Injection
26:34 Improper assets management
27:59 Logging and monitoring
30:05 Learning resources and the project roadmap
33:30 Contributing to API security

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.